Showing posts with label Thought Leadership. Show all posts
Showing posts with label Thought Leadership. Show all posts

Wednesday, 3 December 2014

Horizon Scan 2015

Unplanned IT and telecoms outage, cyber attack and data breach – these were the three main threats to organisations according to the Business Continuity Institute's Horizon Scan 2014 report, but other threats are on the rise such as adverse weather, human illness and transport network disruption. Of course it varies depending on what sector you’re in, where you're geographically located and how big your organization is.

The annual Horizon Scan report, sponsored by BSI, is one of the main pieces of research conducted by the Institute as it provides an insight that those working in the profession can use to inform their own business continuity programme. The Horizon Scan report continues to receive great feedback from those who use it, but it only provides value if people take the time to complete the survey.

The BCI is now asking business continuity professionals and those working in the wider field of organizational resilience to take just a few minutes to complete the Horizon Scan 2015 survey and share your thoughts on what you think the biggest threats are that organizations face.

To complete the survey, click here. You can read the Horizon Scan 2014 report by clicking here.

Wednesday, 30 October 2013

Cyber threat opportunity

Ken Simpson
The VR Group

Only a week to go until the BCM World Conference!

What if we took a different approach to our reflective learning this time?

Instead of waiting until after the conference to reflect and integrate what we have learned, what if we took a proactive approach and spent some time ahead of the conference reflecting on what aspects of our current practice we need to change.

What if that reflection also included reframing the problem – not just how can I fine tune my practices within current frameworks and constraints, but how would I want to transform my practice going forward and remove some of those constraints.

To achieve that outcome perhaps we may take a different mindset into the conference.
If we can try that exercise in critical reflection and recalibrate our mindsets, then perhaps new, or at least different, learning could emerge from the way we interact with the ideas presented and with other conference delegates.

That is the core of what my session at the conference is about, thinking differently about a problem and the way we practice our craft. I hope to encourage discussion around emerging threats and how we might use these to improve our engagement with Executives and the wider organization.

Specifically the session will present my experiences of using cyber-attacks as the focus for Executive exercises and engagement. Cyber is used as an example, and as a metaphor for emerging threats/risks, not as a vehicle to talk about a lot of IT technical stuff. Come and hear how (and why) Executives are more engaged when we use confidentiality and integrity as the disruption risk - rather than the more common approach of using availability.

As befits a 'holistic management discipline' the discussions will most likely touch on a number of issues also discussed in other sessions including:

  • the critical nature of cross discipline engagement,
  • thinking more like management,
  • taking  a strategic rather than compliance approach, and
  • the concept of resilience
 
Some pre-reading on Mindset:
 
 
 
 
Ken will be discussing this and the issue of influencing key decision makers within the 'Thought Leadership' stream at the BCM World Conference on Thursday 7th November, starting at 14:50.

Monday, 22 April 2013

Debate Unlimited – A glimpse into the Executive Forum

With this year’s Executive Forum running on 12th and 13th June in Brussels, it seems a good


Lee Glendon CBCI
Head of Research & Advocacy
time to look back at the two earlier Forums.  What does happen when 600+ years of BC experience converges on Brussels each year for two days?

 
As a recap, the purpose of the Forum is to generate informed debate among experienced BC professionals wrestling with ideas about the strategic direction of business continuity, while keeping a firm eye on what is achievable within a real organisation.
 
Perhaps, the two most memorable ideas that emerged from the 2011 Forum, was that ‘business continuity is not about compliance, it is about embedding resilience through silent running’ and secondly that a key benefit of BC was to identify and prevent ‘sideways bleeding’.   
The debate on compliance started with an academic view that BCM was about compliance:  BCM had become a discussion, which assumed that you can stop things happening if only people followed the rules; BCM lacked emotional intelligence and was seen as a tax on people’s jobs in some organisations; and standards weren’t helping either as they were based on bad organisations and stifled creativity.  With the gauntlet firmly thrown down, an electrifying discussion ensued which ultimately led to the conclusion that BC should actually free-up minds, as it actually assumes that things do go wrong!  While it was acknowledged that ‘tick-box’ might be the starting point for BC, it is not the final destination. There is a need to develop a roadmap and engage and sustain the interest of top management to realise the full potential that BC can bring.
As part of the debate on compliance, there had been extensive discussion around whether BC should look for value add, let alone articulate the next step of what the value would be.  Some asserted that BC was not about helping the financials and in the short term it was a cost, and others argued that adding value is not the same as stopping failures from bringing down the business.  Some questioned whether raising the ability of the organisation to respond to incidents before a major disruption occurred was adding value or capability.   In a sign of conversations to come, one delegate felt that the value add of BC was to be found in facilitating the mission of the organisation and its contribution to the sustainability of the organisation.
The ‘sideways bleeding’ idea came out of a workshop discussion where one participant articulated that external strategy consultants had been retained by their top management to bring about significant cost reductions.  The consultants advocated a vertical approach to securing the costs savings in IT.  The BC team could see the consequences of this initiative as the savings secured in one area of the organisation were effectively nullified by increasing costs and productivity losses in other areas.  This generated a healthy debate about the service that BC professionals should be offering their organisation – while the operational level BC service may be well established in many firms, what would a strategic level service look like?
The 2012 Forum picked up the challenge of defining the strategic level service and identified its key components from developing a centre of excellence in contingency and continuity to engaging top management through crisis response and focusing on the risks that concern them through exercising and scenario analysis.  Value measurement became a hot topic of debate with a very blunt statement from one delegate that reporting to executives that you were doing the job they pay you to do was not ‘adding value’ and BC professionals should take advantage of reporting structures to articulate the value that BC could bring beyond what was expected i.e. compliance to regulations.   Two areas dominated subsequent discussions:  supply chain resilience and horizon scanning.
The academic re-framing of supply chain complexity in terms of layers and networks rather than supply chains was brought to life over the two days with examples ranging from overlooking single points of failure beyond tier one suppliers to unforeseen cascading risks at the logistics level.   One organisation highlighted how its ability to maintain its supply chain during the Arab Spring - through preparedness and enhanced security - secured increased market share.    Supply chain risk was confirmed by all as one risk that can raise the profile and relevancy of BC.  But where should you start?   The advice was to use your analytical skills and look for single points of failure and examine outsource deals; from here you can offer to run an exercise and see what you learn – you may well highlight unknown vulnerabilities and win the mandate to bring in BC.
Horizon Scanning was seen as both a technique to change the conversation with executives from general loss scenarios to a more engaging discussion of specific threats and their strategic consequences.  It was seen as an essential source of developing a situational picture to improve not just the response to events but anticipation of events as well.  The ‘BC radar’ was introduced as an accessible model to set requirements for capability development and ensure readiness in the right areas.
Finally, in 2012 the Open Forum sessions were brought into the programme.  Here delegates proposed and prioritised seven topics of their own choosing to take advantage of the collective experience and expertise of fellow delegates.  Topics included the establishment and composition of ‘resilience councils’, the synergies between BCM and Security disciplines, and Eurozone contingency planning.  For those who take a look at the 2013 programme they will see that some of these topics are going to be developed further this year.
The Executive Forum is a rather unique event:  it seeks to bring together best practice from within the profession while drawing on inspiration from outside.  Participants leave refreshed and invigorated, ready to march towards the sound of gunfire!
Notes:
The Reports from the 2011 and 2012 Forums will be available to purchase from the BCI Shop in May 2013.
To find out more about this year’s Forum please visit the BCI website: http://www.thebci.org/index.php?option=com_content&view=article&id=379&Itemid=293
 
 

Monday, 1 April 2013

Vision Therapy - helping you to see more risks

Ken Simpson, Director
The VR Group Pty Ltd
Thank you all who joined my BCAW webinar, Vision Therapy - helping you to see more risks. I try to make my webinars as interactive as possible, using polls and other techniques, and following up with a post such as this to share any interesting results of the polls and pose some additional questions for people to reflect upon. 
 
In keeping with the theme for BCAW 2013 my presentation argued that there are those risks we see, those we don't see (because we are not looking or because we refuse to recognise them) and then there are those that you cannot see - which are the Black Swan events. My argument was that there are perhaps less Black Swans than we think and more of the events we don't see because we don't look and recognize the threats and vulnerabilities. 
 
The concept of the 'Black Swan event' has become part of the language of BC. If we want to understand this concept we should at some point read how it was originally proposed, rather than rely on how somebody else filtered those words. I posed this question to the audience;

Monday, 25 March 2013

What’s driving supply chain complexity? Part One

Lee Glendon CBCI
Head of Research and Advocacy
In the BCI’s report Horizon Scan 2013, one of the key trends of concern identified by Business Continuity professionals was “increasing supply chain complexity”.  So on Tuesday 19th March, the BCI and the Chartered Institute of Purchasing & Supply (CIPS) convened a roundtable of senior supply chain, risk and business continuity practitioners from sectors as diverse as retail, manufacturing, energy, housing, construction and telecommunications to share experiences and discuss how they were dealing with the challenge.
 
If folk were hoping that complexity is something that will stop or slowly unwind, then they would not have got much comfort from the discussion.  
 

BCAW Roundtable Discussion 2013
Perhaps, the most important driver of complexity is the customer and the desire of businesses to develop the right supply chain to meet the needs of the customer.  For example, the supply chain required to be able to sell a product as “made in Italy” sets its own restrictions and risks that need to be managed.  
 
Many of the drivers of complexity have come about through conscious business decisions.  A number of organisations had decided to consolidate their tier one suppliers – while this simplifies the number of interfaces at tier one, what is has done has created many more tiers below the immediate supplier, reducing visibility.  Participants noted that they were now experiencing disruption originating at tiers five and even six!  
 
Another issue raised by a number of people was around the illusion of diversity that dual-sourcing can bring.  While many had introduced dual-sourcing in terms of immediate suppliers, some had found to their cost that at tier two or three they were reliant on a single supplier again.  This point opened up a wider discussion about how difficult it was to understand interdependencies between suppliers and that the term supply chain should perhaps be replaced by ‘supply chain networks’.
 
Some sectors were suffering from lack of communication around changes in their extended supply chain.  More than one participant commented that their suppliers would change the location of production or the people providing a service without informing them, so organisations would be caught out in finding that an event, for example industrial action, in one country affected them, even though they didn’t think they had any exposure to the event.
 
Representatives from the public sector provided an interesting contrast to their colleagues in the private sector.  Their driver of complexity was government policy which was requiring not supplier consolidation but increasing their spend with small and medium sized businesses, while this was sometimes managed through a large tier one supplier, there was a need to monitor the success of this policy and provide extensive training and development support for small businesses to work with government entities.
 
The consequences of redrawing the boundaries of organisations over many years through outsourcing were also flagged as creating challenges in that the suppliers often had more knowledge and expertise than the client. Some felt that too much intellectual power had been outsourced and one organisation stated that they were now bringing back in-house some of the higher skilled activities.
 
In concluding this part of the roundtable discussion, it’s much clearer why complexity is such a taxing trend for Business Continuity professionals and why it is so important to find an approach to manage it effectively. 
 
In Part 2 of this roundtable report, we’ll look at some of the techniques that are being used to manage complexity.
 

Thursday, 21 March 2013

A Winning Combination with great odds

Your BC Eye
Donna Monkhouse
Once again your BC Eye tuned into yet another excellent webinar – just one of the many free webinars that are being run as part of this year’s BCAW activities to raise awareness around the value of Business Continuity.
 
This one discussed the rise (and not fall) of contingency planning (widely used and known in the financial sector as the way to deal with threats) and its continued rise to become an integral part of good Business Continuity practice.   
 
Based on the recently released BCI Research Report: The Winning Combination – the 3 Cs of Business Continuity: Contingency Planning, Continuity Capability and Crisis Response and hosted by our very own Lee Glendon, who heads up our Research and Advocacy activities, this webinar showed us that by bringing the 3 Cs together we can accomplish good Business Continuity practice and ultimately achieve the one true goal, which is organizational resilience. 
 
Lee Glendon CBCI
Lee talked about the specific role of the BC professional in Contingency Planning, which he neatly defined as the individual who makes an action plan actionable and the challenges a BC Manager faces as a non-financial professional of being deemed capable of assuming responsibility for supporting the development of a Contingency Plan. 
 
The key thing this presentation drove home to me was that fact that Contingency Planning, Continuity Capability and Crisis response should not be dealt with in isolation but that they all support each other.   Continuity Planning is all about the pre-plan response for things that can be reasonably planned for; Contingency Planning is all about dealing with specific threats or scenarios; and Crisis Response is required when an event goes beyond reasonable planning and poses a high degree of threat to the existence of an organization.   Together they form, as Lee stated, “a three-line defence” mechanism, which works!
 
Putting this concept into a context that we can all relate to, Lee took us through a case study that demonstrated the successful application of the 3Cs, namely, Cheltenham Races, which are organised by the British Horseracing Authority. 
 
He explained that the Continuity Capability was in this instance about ‘keeping the show on the road’, which meant making sure the event could happen, like for example identifying an alternative location for the same date (not easy to change a race date).  This included the recognition of the fact that things can go wrong and that there will inevitably be disruptions, after all, it is the winter race programme in the UK that we are talking about here!   Then he talked about the Contingency Planning element, which in this case was essentially having plans at local level (i.e. for the racecourse itself) in the event that it snowed, or there was a hard frost or security issues.  And finally he talked about the Crisis Response, for the bigger things like injuries to the horses, cruelty to animal campaigns that might damage the good reputation of the British Horseracing Authority as well as our beloved (and I can say that as a Brit) Cheltenham Races or cause a major disruption to the event. 
 
The success of this wonderful example of the practical application of the 3 Cs was evidenced through an enhanced reputation and wide public recognition according to the British Horseracing Association.   There were lots of contributory factors including good communications; making sure the needs of all the race stakeholders were met; bending the rules a bit where necessary (or as Lee referred to it, flexible policy); not having a fixed plan but having the capability to deal with threats and incidents; as well as the continuity of staff.
 
The next phase of this truly insightful webinar was about the application of the 3 Cs to threats and risks or rather the question of how this could be done.   This is where the black swans of this year’s BCAW 2013 theme appeared on the horizon.  (Remember the main banner on the BCAW website?)  Lee defined the characteristics of these infamous black swans as:  unexpected; more consequential than your white swan (the ones you do see coming); relative in terms of knowledge (i.e. the more knowledge, the less black the swan (!); and ones where we have a clear understanding of what the consequences could be even if we don’t know what that event will be exactly or how likely it is.
 
Here, Lee brought into play the famous “Known, Knowns” concept of Donald Rumsfeld (2002) and linked them to the 3 Cs as follows:
 
Known Knowns i.e. things we know we know, which can be dealt with using Contingency Planning;
 
Known Unknowns i.e. the things we know we don’t know, which require us to build Continuity Capability;
 
Unknown Knowns i.e. the things we know about but don’t know when they will happen, which if they do, will require a Crisis Response;
 
Unknown Unknowns i.e. the things we don’t know about nor do we know when they will happen, which also fall under the remit of a Crisis Response.
 
In conclusion, Lee brought us back to the opening topic of the webinar, namely, Contingency Planning, which he concluded, is known, particularly in the Financial Sector to work across strategic, financial and operational risks.  What this webinar proved was that the 3 Cs would work just as well and actually when we talk about Contingency Planning, in essence, we are talking about the application of the 3 Cs; all we are doing essentially is using different elements of the same structure.  Which elements we ultimately use, will simply depend on the level of our knowledge. 
 
So Contingency Planning really is on the rise; on the rise to become an integral part of Business Continuity and the application of the 3 Cs will help us to build resilience.
 
 
 
 

Tuesday, 12 February 2013

BC Predictions for 2013 - 7 to 10

Lyndon Bird FBCI
This blog brings to an end my review of BCI predictions for 2013 – mainly because as we have now reached February, they are beginning to look more like news comment than forecasts.
 
Predictions 7 through 10 were about business failures, sustainability, increased outsourcing problems and social media respectively.

Tuesday, 29 January 2013

BC Predictions for 2013 - Numbers 5 and 6

Lyndon Bird FBCI
Today I will look at our predictions 5 and 6, which have some degree of overlap.
 
Firstly we predicted that “ISO 22301 will start to take off, with certificates issued in more than one country”. Hardly a difficult prediction I know, but still an opportunity to test the often argued premise that many companies had delayed certification to BS25999 because they were waiting for an ISO standard.
 
Whether this is true or not, we will start to find out in 2013, but indications from our research is that the vast majority of organizations will still opt for the nebulous concept of alignment, rather than full certification.

Wednesday, 23 January 2013

BC Predictions for 2013: Number 4 - Contingency Planning will become fashionable again

Lyndon Bird FBCI
There has been some puzzled faces questioning our BC prediction number 4 – “Contingency Planning will become fashionable again as a part of a broader understanding of Business Continuity which includes Continuity Capability and Crisis Response”.

Without stealing the thunder of my colleague Lee Glendon who is researching this proposition and will issue a discussion paper on the topic later during BCAW 2013, I think it is becoming obvious that conventional BCM as defined by a management system does not cover the full range of BC thinking. British Standards are working on a Crisis Management Standard (BS11200) and an Organizational Resilience Standard (BS45000) so we can only assume that they agree with us.

Thursday, 17 January 2013

BC Predictions for 2013 - Number Three: IT will still dominate BC thinking but will be refreshed under the issues raised by cyber threat, big data, cloud and mobility services and social media

Lyndon Bird FBCI
Continuing our review of our predictions for 2013, most people believe that IT will still dominate BC thinking but will be refreshed under the issues raised by cyber threat, big data, cloud and mobility services and social media.  Worries about a myriad of cyber fears will start to move on from its hype phase to a more sophisticated, nuanced understanding of the main issues, threats and vulnerabilities.
Strangely, however, the biggest concern many organizations still worry about is the oldest of all business continuity issues - IT or Telecom disruption. This has had a considerable revival in the past year, perhaps highlighted by the surprisingly long outages being experienced by a major bank and more than one mobile telecom network provider.

Monday, 14 January 2013

Big picture – long picture: the value of horizon scanning

Lee Glendon CBCI
Big picture – long picture1: the value of horizon scanning
 
How can you ensure that your BCM programme and resources are allocated in a way proportionate to the current and potential threats that the company is and will be facing?
 
That’s a real question one of our members faced last year from her senior management team.  While some folk will be frustrated at the threat-oriented starting point of the question, it is not an uncommon one as many practitioners will confirm.   While ‘risk assessment through threat evaluation’ may provide some assistance with the question posed above, horizon scanning potentially provides a framework to build out the situational picture.  It also provides an opportunity for a proactive stance by practitioners.

Tuesday, 8 January 2013

10 Business Continuity Predictions for 2013 - getting to grips with Business Reslience


Lyndon Bird FBCI

At the start of the year it is always tempting to forward and make some predictions. Like New Year resolutions, however, they are generally much modified as soon as they come into contact with reality. Nevertheless at the BCI we asked our experts what they thought might be important Business Continuity trends in 2013 and got some interesting responses, from which we listed our top ten, and here they are:
10 Business Continuity Predictions for 2013

Wednesday, 12 December 2012

Black Swans – something for senior managers to hide behind or to action?

Lyndon Bird FBCI
Some business continuity practitioners have argued that Risk Management techniques provide a tried and tested approach to dealing with conventional threats, but have limited effectiveness in identifying or evaluating rare but potentially catastrophic issues.  
 
There has even been a host of terms that have entered our common lexicon simply to try and define these types of high impact situations.  The former US Defence Secretary Donald Rumsfeld was much satirised when he talked about “known, unknowns” and “unknown, unknowns” etc. but it is proving to be a useful way of distinguishing types of threat.   
 
The idea of “Black Swans” to define things that are outside of personal experience, and therefore missed when trying to register potential risks has also been much debated.  Many have treated “Black Swans” as if they are the same as “unknown, unknowns”, but in most circumstances they are more akin to “unknown, knowns”  - perhaps unknown to key decision makers but certainly not unknown to everyone.  
 
For example the volcano ash cloud which closed European airspace is often called a “Black Swan” event – but every aspect of that drama was well-known by some people - the volcano might erupt (meteorologists); there is a level of ash that airplanes were not allowed to fly through (aviation authorities); and there is a relatively high tolerance to ash levels in more recently designed jet engines (aerospace engineers).  So the problem was less to do with lack of knowledge but the failure to share and assimilate the significance of that knowledge.
 
This is at the heart of the debates we have about apparent failures of risk management; the Libor rate scandal; the sub-prime mortgage crisis that bankrupted many banks; the collapse of the once impregnable Arthur Anderson global business empire.  All came as a great shock at the time, not only to outsiders, but apparently also to the Board and C-Suite executives of the organizations concerned.  
 
Lack of available knowledge was not the problem; lack of knowledge by those who had the power to stop dangerous things happening was.  Claiming such things as “Black Swans” helps deflect blame on the premise that “how can we have done anything about it if it was an inconceivable incident?” This excuse might work if a meteorite hits the earth, but not if we simply have failed to look at signs, talk to people who know what is happening and adjusted our behaviour accordingly.
 
I wonder if there is now a risk that we are headed towards another problem which is not being properly confronted at the right level. The Business Continuity Institute and the Chartered Institute of Purchasing and Supply conduct an annual survey into how well Business Continuity is being handled within the Supply Chain.  As a basic question, we collect data about the main causes of operational disruptions across the world.  One item has been steadily rising up the list until today this year it finished 3rd – after the perennial top-two of Adverse Weather and IT/Telecoms failure.  That factor is “failure or serious disruption to services provided by an outsourcer”.  In the world of globalization, low cost manufacturing and just-in-time delivery, we have treated outsourcing (and its close cousin off-shoring) as self-evidently good things.  It allows management to concentrate on core business; it manages external costs better through competitive bidding processes and it buys in a higher level of specialist expertise than might be affordable in-house.
 
The problem is that some of this accepted wisdom is being questioned by supply chain and BCM professionals in organizations, but this message is not being heard by those who could change it.  
 
As the global economy continues to stagnate, more and more pressure is placed on cost-saving and often this leads to excessive price pressure on those organizations bidding to gain or even retain their accounts.  It also leads to more single source suppliers in return for lower prices and service provision from more geographically, politically and culturally unstable regions.  This seems to be a trade-off between cost and reliability, and some feel the balance has gone too far with significantly more disruptions ensuing - which are then causing higher levels of dissatisfied customers and eventual loss of business.  
 
There is always a need to make a judgment and a sensible balance between “no risk at any costs” and “any risk at lowest cost” has to be taken – but for those who favour the higher risk end of that scale do they really know what consequences they might be facing.  Is this perhaps another “unknown, known” that top management might try to pass of as a “black swan” if all goes wrong?
 

Monday, 24 September 2012

A couple of months can make all the difference.

Lyndon Bird FBCI
After years of preparation and much scepticism in some quarters, London 2012 is now over.  Both the Olympic and Paralympic Games have been hailed globally as great achievements.   Oddly, I have received congratulations from colleagues and friends in all parts of the world as if the success of the Games had had something to do with me.   However, reflected glory is always welcome and I am not complaining that the UK is being viewed in such a positive light.
It is strange that just a few weeks ago the main media interest was in the failure of G4S to provide adequate security personnel; the possibility of an immigration officer strike; and doom and destruction predictions on almost everything from transport to infrastructure.   We constantly heard of a grid-locked London, wide-scale traffic chaos, business disruptions and 1970’s style industrial action.   Even Mitt Romney, the Republican candidate for the US presidency, publicly expressed his worries on the eve of the Games based upon little more than arbitrary scare stories.
Some commentators predicted massive criminality and public disorder although evidence from previous Games suggested the exact opposite.   Others saw it as inevitable that we would face terrorist attacks, resulting in possible carnage.   Those less dramatic in their predictions did all seem to agree that London itself would be over-flowing with people and that businesses would be unable to operate due to the congestion and staff absenteeism.   When pointed out that tourist numbers were down, the same opinion leaders then changed their complaint to the fact that the events were scaring normal tourists away such that hotels, restaurants, theatres and the stores on Oxford Street would soon be going bankrupt.
To my knowledge little of this happened. Sensible organizations and individuals arranged their working practices appropriately.   Maybe the short-term financial boom envisaged by some London leisure businesses failed to materialise, but the enormous gain to the reputation of London will make people who never dreamed of visiting London before put it at the top of their list as a place to see.  
The leading UK retailer “The John Lewis Partnership” reported a major increase in sales and no problem with “foot-fall” at their central London shops as well as great success at their new store adjacent to the Olympic Park.  Large organizations like BT, BA and Sainsbury’s have contributed much to the overall success but it will enhance and benefit their reputation in ways almost nothing else could.   Overall the negative impact on business has been much exaggerated.
Well did this happen by luck?  
Perhaps it is pertinent to quote golfing legend Gary Player who (when opponents claimed he was fortunate) famously said “it is odd but the more I practice the luckier I get”.   It seems clear to me that major problems usually occur only when unexpected things happen, at unpredictable times and when no-one is trained to deal with them.  Fear of the Olympics was like other potential catastrophes that failed to ignite – think of the millennium bug or two flu pandemics (avian and swine varieties).   All captured the attention of the media but caused limited or no direct impact because we knew about them and had prepared accordingly.   Where we face real problems is when the threat is impossible to foresee such as the tsunami triggered by the earthquake causing a nuclear melt-down; a political extremist running riot in peaceful Norway; or a corporate scandal getting out of control as we saw a few years ago with Enron and Arthur Anderson.
For “known, knowns”, the Olympics is a great example of integrated Business Continuity Management.   It shows that however complicated or frightening a threat is perceived to be, it can be mitigated effectively by good planning, good organisation and plenty of practice.   The Games did not just happen at random, the organisers knew the dates and schedules in detail for many years.   They had the capability and expertise of leading experts from around the world to call on, and they had time to test and rehearse everything over and over again until it was perfect.   Some things went wrong, of course, but they were managed not by panic or “off the cuff” decision-making but by fully trained and committed people using tried and tested processes.
I hope you all enjoyed summer 2012 as much as I did.   It was good for the morale of the country, great for Risk Managers in showing that risks can be managed not just avoided and brilliant for those Business Continuity professionals who contributed their time, efforts, skills and passion to making it work for everyone.

Friday, 21 September 2012

Business continuity – a culture, not a plan


Dr Cliff Ferguson Ph.D. AMBCI
Business continuity is not just about disaster recovery – it should be a corporate culture.

This is the view of Clifford Ferguson, chairperson of the South African BCI Forum and Government Pensions Administration Agency (GPAA) BC Committee, who says that when business continuity is top of mind, companies can deal with any eventuality.

“The problem – particularly in government departments and parastatals – is that business continuity is seen as disaster recovery. But disaster recovery is only a component of business continuity. So organisations may know how to evacuate a building or locate the disaster recovery site, but they don't necessarily know how to keep their business in full operation in the event of a problem,” he says.

Ferguson says most organisations tend to draft a business continuity plan and shelve it until they face a disaster. “Most companies don't implement their business continuity strategies properly,” he says.

“A comprehensive programme needs to be put into place and be made a business culture. You need a top-down, bottom-up approach, with awareness at lower level and implementation from the top.”

Ferguson highlights his agency's experience in changing its corporate culture to focus on business continuity.

“In line with the requirements of our two major customers – the National Treasury and the Government Pensions Fund (GEPF), we had to implement a comprehensive business continuity plan. We engaged an international consultant and began training and implementation around two years ago.” 

The strategy included training and BCI international certification for representative senior management, the appointment of a business continuity committee, including three Exco members, followed by the training of other practitioners. Some staff volunteers also trained as practitioners. The programme did not end with training, however. It is an ongoing project, which includes fortnightly review meetings, desktop exercises, training and awareness days, and live evacuation drills at least once every quarter.

Ferguson says, as a work in progress, the plan is constantly tweaked and revised on the feedback of emergency services and staff.
 
“For example, we physically move staff to our disaster recovery centre during a drill, and then ask them to report back on possible improvements after the exercise. During an evacuation drill, the emergency services will give us feedback on any problem areas.

“This is unusual – organisations or companies could have a disaster site, but not everyone moves people to test their plan on the site. We make the people own the business continuity plan. We are doing more now and cascading the plan down so every single business unit has its own plan and its own emergency box, too,” he says.

Even though the business continuity programme is relatively new, Ferguson feels the heightened awareness has already benefited the agency.

Unforeseen incidents, such as the mail server going down or the water supply being cut off for days, could previously have caused problems. However, with the new staff mindset, these problems arose recently but caused no disruptions in the agency's work, says Ferguson.

“For example, we had no water and the sanitation facilities became clogged. In a building with hundreds of staff, this was a problem. But we were well prepared, made alternative arrangements and business continued as normal – albeit with some complaints. On another occasion, we experienced power cuts, but it was business as usual. So the training paid off.”

Ferguson concludes: “Business continuity planning is critical – unexpected things can happen to anybody. All the incidents we had could have happened to anybody and we didn't know they were coming. However, just having a plan and heightened staff awareness allowed us to continue operations without a hitch when problems occurred. If something big should happen tomorrow, we would probably be prepared, and as business continuity culture improves, so will our preparedness.”

Ferguson will address the upcoming ITWeb Business Continuity 2012 Conference, at The Forum in Bryanston, on 13 November. For more information about this event, click here.