Unplanned IT and telecoms outage, cyber attack and data breach – these were the three main threats to organisations according to the Business Continuity Institute's Horizon Scan 2014 report, but other threats are on the rise such as adverse weather, human illness and transport network disruption. Of course it varies depending on what sector you’re in, where you're geographically located and how big your organization is.
The annual Horizon Scan report, sponsored by BSI, is one of the main pieces of research conducted by the Institute as it provides an insight that those working in the profession can use to inform their own business continuity programme. The Horizon Scan report continues to receive great feedback from those who use it, but it only provides value if people take the time to complete the survey.
The BCI is now asking business continuity professionals and those working in the wider field of organizational resilience to take just a few minutes to complete the Horizon Scan 2015 survey and share your thoughts on what you think the biggest threats are that organizations face.
To complete the survey, click here. You can read the Horizon Scan 2014 report by clicking here.
Showing posts with label Thought Leadership. Show all posts
Showing posts with label Thought Leadership. Show all posts
Wednesday, 3 December 2014
Wednesday, 30 October 2013
Cyber threat opportunity
Ken Simpson
The VR Group
Only a week to go until the BCM World Conference!
What if we took a different approach to our reflective learning this time?
Instead of waiting until after the conference to reflect and integrate what we have learned, what if we took a proactive approach and spent some time ahead of the conference reflecting on what aspects of our current practice we need to change.
What if that reflection also included reframing the problem – not just how can I fine tune my practices within current frameworks and constraints, but how would I want to transform my practice going forward and remove some of those constraints.
To achieve that outcome perhaps we may take a different mindset into the conference.
If we can try that exercise in critical reflection and recalibrate our mindsets, then perhaps new, or at least different, learning could emerge from the way we interact with the ideas presented and with other conference delegates.
That is the core of what my session at the conference is about, thinking differently about a problem and the way we practice our craft. I hope to encourage discussion around emerging threats and how we might use these to improve our engagement with Executives and the wider organization.
Specifically the session will present my experiences of using cyber-attacks as the focus for Executive exercises and engagement. Cyber is used as an example, and as a metaphor for emerging threats/risks, not as a vehicle to talk about a lot of IT technical stuff. Come and hear how (and why) Executives are more engaged when we use confidentiality and integrity as the disruption risk - rather than the more common approach of using availability.
As befits a 'holistic management discipline' the discussions will most likely touch on a number of issues also discussed in other sessions including:
The VR Group
Only a week to go until the BCM World Conference!
What if we took a different approach to our reflective learning this time?
Instead of waiting until after the conference to reflect and integrate what we have learned, what if we took a proactive approach and spent some time ahead of the conference reflecting on what aspects of our current practice we need to change.
What if that reflection also included reframing the problem – not just how can I fine tune my practices within current frameworks and constraints, but how would I want to transform my practice going forward and remove some of those constraints.
To achieve that outcome perhaps we may take a different mindset into the conference.
If we can try that exercise in critical reflection and recalibrate our mindsets, then perhaps new, or at least different, learning could emerge from the way we interact with the ideas presented and with other conference delegates.
That is the core of what my session at the conference is about, thinking differently about a problem and the way we practice our craft. I hope to encourage discussion around emerging threats and how we might use these to improve our engagement with Executives and the wider organization.
Specifically the session will present my experiences of using cyber-attacks as the focus for Executive exercises and engagement. Cyber is used as an example, and as a metaphor for emerging threats/risks, not as a vehicle to talk about a lot of IT technical stuff. Come and hear how (and why) Executives are more engaged when we use confidentiality and integrity as the disruption risk - rather than the more common approach of using availability.
As befits a 'holistic management discipline' the discussions will most likely touch on a number of issues also discussed in other sessions including:
- the critical nature of cross discipline engagement,
- thinking more like management,
- taking a strategic rather than compliance approach, and
- the concept of resilience
Some pre-reading on Mindset:
Ken will be discussing this and the issue of influencing key decision makers within the 'Thought Leadership' stream at the BCM World Conference on Thursday 7th November, starting at 14:50.
Monday, 22 April 2013
Debate Unlimited – A glimpse into the Executive Forum
With this year’s Executive Forum running on 12th
and 13th June in Brussels, it seems a good
![]() |
| Lee Glendon CBCI Head of Research & Advocacy |
As a recap, the purpose of the Forum is to generate informed
debate among experienced BC professionals wrestling with ideas about the
strategic direction of business continuity, while keeping a firm eye on what is
achievable within a real organisation.
Perhaps, the two most memorable ideas that emerged from the
2011 Forum, was that ‘business continuity is not about compliance, it is about
embedding resilience through silent running’ and secondly that a key benefit of
BC was to identify and prevent ‘sideways bleeding’.
The debate on compliance started with an academic view that
BCM was about compliance: BCM had become
a discussion, which assumed that you can stop things happening if only people
followed the rules; BCM lacked emotional intelligence and was seen as a tax on
people’s jobs in some organisations; and standards weren’t helping either as
they were based on bad organisations and stifled creativity. With the gauntlet firmly thrown down, an
electrifying discussion ensued which ultimately led to the conclusion that BC should actually free-up minds, as it
actually assumes that things do go wrong!
While it was acknowledged that ‘tick-box’ might be the starting point for
BC, it is not the final destination. There is a need to develop a roadmap and
engage and sustain the interest of top management to realise the full potential
that BC can bring.
As part of the debate on compliance, there had been
extensive discussion around whether BC should look for value add, let alone
articulate the next step of what the value would be. Some asserted that BC was not about helping
the financials and in the short term it was a cost, and others argued that
adding value is not the same as stopping failures from bringing down the
business. Some questioned whether
raising the ability of the organisation to respond to incidents before a major
disruption occurred was adding value or capability. In a sign of conversations to come, one
delegate felt that the value add of BC was to be found in facilitating the
mission of the organisation and its contribution to the sustainability of the
organisation.
The ‘sideways bleeding’ idea came out of a workshop
discussion where one participant articulated that external strategy consultants
had been retained by their top management to bring about significant cost
reductions. The consultants advocated a
vertical approach to securing the costs savings in IT. The BC team could see the consequences of
this initiative as the savings secured in one area of the organisation were
effectively nullified by increasing costs and productivity losses in other
areas. This generated a healthy debate
about the service that BC professionals should be offering their organisation –
while the operational level BC service may be well established in many firms, what
would a strategic level service look like?
The 2012 Forum picked up the challenge of defining the
strategic level service and identified its key components from developing a
centre of excellence in contingency and continuity to engaging top management
through crisis response and focusing on the risks that concern them through
exercising and scenario analysis. Value
measurement became a hot topic of debate with a very blunt statement from one
delegate that reporting to executives that you were doing the job they pay you
to do was not ‘adding value’ and BC professionals should take advantage of
reporting structures to articulate the value that BC could bring beyond what
was expected i.e. compliance to regulations.
Two areas dominated subsequent discussions: supply chain resilience and horizon scanning.
The academic re-framing of supply chain complexity in terms
of layers and networks rather than supply chains was brought to life over the
two days with examples ranging from overlooking single points of failure beyond
tier one suppliers to unforeseen cascading risks at the logistics level. One organisation highlighted how its ability
to maintain its supply chain during the Arab Spring - through preparedness and
enhanced security - secured increased market share. Supply chain risk was confirmed by all as
one risk that can raise the profile and relevancy of BC. But where should you start? The advice was to use your analytical skills
and look for single points of failure and examine outsource deals; from here
you can offer to run an exercise and see what you learn – you may well
highlight unknown vulnerabilities and win the mandate to bring in BC.
Horizon Scanning was seen as both a technique to change the
conversation with executives from general loss scenarios to a more engaging
discussion of specific threats and their strategic consequences. It was seen as an essential source of
developing a situational picture to improve not just the response to events but
anticipation of events as well. The ‘BC
radar’ was introduced as an accessible model to set requirements for capability
development and ensure readiness in the right areas.
Finally, in 2012 the Open Forum sessions were brought into
the programme. Here delegates proposed
and prioritised seven topics of their own choosing to take advantage of the
collective experience and expertise of fellow delegates. Topics included the establishment and
composition of ‘resilience councils’, the synergies between BCM and Security
disciplines, and Eurozone contingency planning.
For those who take a look at the 2013 programme they will see that some
of these topics are going to be developed further this year.
The Executive Forum is a rather unique event: it seeks to bring together best practice from
within the profession while drawing on inspiration from outside. Participants leave refreshed and invigorated,
ready to march towards the sound of gunfire!
Notes:
The Reports from the 2011 and 2012 Forums will be available
to purchase from the BCI Shop in May 2013.
To find out more about this year’s Forum please visit the
BCI website: http://www.thebci.org/index.php?option=com_content&view=article&id=379&Itemid=293
Monday, 1 April 2013
Vision Therapy - helping you to see more risks
![]() |
| Ken Simpson, Director The VR Group Pty Ltd |
Thank you all who joined my BCAW webinar, Vision Therapy - helping
you to see more risks. I try to make my webinars as interactive as
possible, using polls and other techniques, and following up with a post such
as this to share any interesting results of the polls and pose some additional
questions for people to reflect upon.
In keeping with the theme for BCAW 2013 my
presentation argued that there are those risks we see, those we don't see
(because we are not looking or because we refuse to recognise them) and then
there are those that you cannot see - which are the Black Swan events. My argument
was that there are perhaps less Black Swans than we think and more of the
events we don't see because we don't look and recognize the threats and
vulnerabilities.
The concept of the 'Black Swan event' has
become part of the language of BC. If we want to understand this concept we
should at some point read how it was originally proposed, rather than rely on
how somebody else filtered those words. I posed this question to the audience;
Monday, 25 March 2013
What’s driving supply chain complexity? Part One
![]() |
| Lee Glendon CBCI Head of Research and Advocacy |
In the BCI’s report Horizon Scan 2013, one of the key trends
of concern identified by Business Continuity professionals was “increasing
supply chain complexity”. So on Tuesday 19th March, the BCI
and the Chartered Institute of Purchasing & Supply (CIPS) convened a
roundtable of senior supply chain, risk and business continuity practitioners
from sectors as diverse as retail, manufacturing, energy, housing, construction
and telecommunications to share experiences and discuss how they were dealing
with the challenge.
If folk were hoping that complexity is something that will
stop or slowly unwind, then they would not have got much comfort from the
discussion.
Perhaps, the most important driver of complexity is the
customer and the desire of businesses to develop the right supply chain to meet
the needs of the customer. For example, the supply chain required to be
able to sell a product as “made in Italy” sets its own restrictions and risks
that need to be managed.
| BCAW Roundtable Discussion 2013 |
Many of the drivers of complexity have come about through
conscious business decisions. A number of organisations had decided to
consolidate their tier one suppliers – while this simplifies the number of
interfaces at tier one, what is has done has created many more tiers below the
immediate supplier, reducing visibility. Participants noted that they
were now experiencing disruption originating at tiers five and even six!
Another issue raised by a number of people was around the
illusion of diversity that dual-sourcing can bring. While many had
introduced dual-sourcing in terms of immediate suppliers, some had found to
their cost that at tier two or three they were reliant on a single supplier
again. This point opened up a wider discussion about how difficult it was
to understand interdependencies between suppliers and that the term supply
chain should perhaps be replaced by ‘supply chain networks’.
Some sectors were suffering from lack of communication
around changes in their extended supply chain. More than one participant
commented that their suppliers would change the location of production or the
people providing a service without informing them, so organisations would be
caught out in finding that an event, for example industrial action, in one
country affected them, even though they didn’t think they had any exposure to
the event.
Representatives from the public sector provided an
interesting contrast to their colleagues in the private sector. Their
driver of complexity was government policy which was requiring not supplier
consolidation but increasing their spend with small and medium sized
businesses, while this was sometimes managed through a large tier one supplier,
there was a need to monitor the success of this policy and provide extensive
training and development support for small businesses to work with government
entities.
The consequences of redrawing the boundaries of
organisations over many years through outsourcing were also flagged as creating
challenges in that the suppliers often had more knowledge and expertise than
the client. Some felt that too much intellectual power had been outsourced and
one organisation stated that they were now bringing back in-house some of the
higher skilled activities.
In concluding this part of the roundtable discussion, it’s
much clearer why complexity is such a taxing trend for Business Continuity
professionals and why it is so important to find an approach to manage it
effectively.
In Part 2 of this roundtable report, we’ll look at some of
the techniques that are being used to manage complexity.
Thursday, 21 March 2013
A Winning Combination with great odds
![]() |
| Your BC Eye Donna Monkhouse |
Once again your BC Eye tuned into yet another excellent webinar – just
one of the many free webinars that are being run as part of this year’s BCAW
activities to raise awareness around the value of Business Continuity.
This one discussed the rise (and not fall) of contingency planning
(widely used and known in the financial sector as the way to deal with threats)
and its continued rise to become an integral part of good Business Continuity
practice.
Based on the recently released BCI Research Report: The Winning Combination – the 3 Cs of Business Continuity: Contingency Planning, Continuity Capability and Crisis Response and hosted by our very own Lee Glendon, who heads up our
Research and Advocacy activities, this webinar showed us that by bringing the 3
Cs together we can accomplish good Business Continuity practice and ultimately
achieve the one true goal, which is organizational resilience.
![]() |
| Lee Glendon CBCI |
Lee talked about the specific role of the BC professional in Contingency
Planning, which he neatly defined as the individual who makes an action plan
actionable and the challenges a BC Manager faces as a non-financial
professional of being deemed capable of assuming responsibility for supporting
the development of a Contingency Plan.
The key thing this presentation drove home to me was that fact that
Contingency Planning, Continuity Capability and Crisis response should not be
dealt with in isolation but that they all support each other. Continuity Planning is all about the pre-plan
response for things that can be reasonably planned for; Contingency Planning is
all about dealing with specific threats or scenarios; and Crisis Response is
required when an event goes beyond reasonable planning and poses a high degree
of threat to the existence of an organization.
Together they form, as Lee stated, “a three-line defence” mechanism,
which works!
Putting this concept into a context that we can all relate to, Lee took
us through a case study that demonstrated the successful application of the
3Cs, namely, Cheltenham Races, which are organised by the British Horseracing
Authority.
He explained that the Continuity Capability was in this instance about
‘keeping the show on the road’, which meant making sure the event could happen,
like for example identifying an alternative location for the same date (not
easy to change a race date). This
included the recognition of the fact that things can go wrong and that there
will inevitably be disruptions, after all, it is the winter race programme in
the UK that we are talking about here!
Then he talked about the Contingency Planning element, which in this
case was essentially having plans at local level (i.e. for the racecourse
itself) in the event that it snowed, or there was a hard frost or security
issues. And finally he talked about the
Crisis Response, for the bigger things like injuries to the horses, cruelty to
animal campaigns that might damage the good reputation of the British
Horseracing Authority as well as our beloved (and I can say that as a Brit)
Cheltenham Races or cause a major disruption to the event.
The success of this wonderful example of the practical application of the
3 Cs was evidenced through an enhanced reputation and wide public recognition
according to the British Horseracing Association. There were lots of contributory factors
including good communications; making sure the needs of all the race
stakeholders were met; bending the rules a bit where necessary (or as Lee
referred to it, flexible policy); not having a fixed plan but having the
capability to deal with threats and incidents; as well as the continuity of
staff.
The next phase of this truly insightful webinar was about the application
of the 3 Cs to threats and risks or rather the question of how this could be
done. This is where the black swans of
this year’s BCAW 2013 theme appeared on the horizon. (Remember the main banner on the BCAW website?) Lee defined the
characteristics of these infamous black swans as: unexpected; more consequential than your white
swan (the ones you do see coming); relative in terms of knowledge (i.e. the
more knowledge, the less black the swan (!); and ones where we have a clear
understanding of what the consequences could be even if we don’t know what that
event will be exactly or how likely it is.
Here, Lee brought into play the famous “Known, Knowns” concept of
Donald Rumsfeld (2002) and linked them to the 3 Cs as follows:
Known Knowns i.e. things we know we know, which can be
dealt with using Contingency Planning;
Known Unknowns i.e. the things we know we don’t know, which
require us to build Continuity Capability;
Unknown Knowns i.e. the things we know about but don’t know
when they will happen, which if they do, will require a Crisis Response;
Unknown Unknowns i.e. the things we don’t know about nor do we
know when they will happen, which also fall under the remit of a Crisis
Response.
In conclusion, Lee brought us back to the opening topic of the webinar,
namely, Contingency Planning, which he concluded, is known, particularly in the
Financial Sector to work across strategic, financial and operational risks. What this webinar proved was that the 3 Cs
would work just as well and actually when we talk about Contingency Planning,
in essence, we are talking about the application of the 3 Cs; all we are doing
essentially is using different elements of the same structure. Which elements we ultimately use, will simply
depend on the level of our knowledge.
So Contingency Planning really is on the rise; on the rise to become an
integral part of Business Continuity and the application of the 3 Cs will help
us to build resilience.
Tuesday, 12 February 2013
BC Predictions for 2013 - 7 to 10
This blog brings to an end
my review of BCI predictions for 2013 – mainly because as we have now reached
February, they are beginning to look more like news comment than forecasts.
Predictions 7 through 10
were about business failures, sustainability, increased outsourcing problems
and social media respectively.
Tuesday, 29 January 2013
BC Predictions for 2013 - Numbers 5 and 6
Today I will look at our
predictions 5 and 6, which have some degree of overlap.
Firstly we predicted
that “ISO 22301 will start to take off, with certificates issued in more than
one country”. Hardly a difficult prediction I know, but still an opportunity to
test the often argued premise that many companies had delayed certification to
BS25999 because they were waiting for an ISO standard.
Whether this is true or
not, we will start to find out in 2013, but indications from our research is
that the vast majority of organizations will still opt for the nebulous concept
of alignment, rather than full certification.
Wednesday, 23 January 2013
BC Predictions for 2013: Number 4 - Contingency Planning will become fashionable again
![]() |
| Lyndon Bird FBCI |
Without stealing the thunder
of my colleague Lee Glendon who is researching this proposition and will issue a
discussion paper on the topic later during BCAW 2013, I think it is becoming obvious
that conventional BCM as defined by a management system does not cover the full
range of BC thinking. British Standards are working on a Crisis Management
Standard (BS11200) and an Organizational Resilience Standard (BS45000) so we
can only assume that they agree with us.
Thursday, 17 January 2013
BC Predictions for 2013 - Number Three: IT will still dominate BC thinking but will be refreshed under the issues raised by cyber threat, big data, cloud and mobility services and social media
Continuing our review of our predictions for
2013, most people believe that IT will still dominate BC thinking but will be refreshed
under the issues raised by cyber threat, big data, cloud and mobility services
and social media. Worries about a myriad of cyber fears will start
to move on from its hype phase to a more sophisticated, nuanced understanding
of the main issues, threats and vulnerabilities.
Strangely, however, the biggest concern many
organizations still worry about is the oldest of all business continuity issues
- IT or Telecom disruption. This has had a considerable revival in the past
year, perhaps highlighted by the surprisingly long outages being experienced by
a major bank and more than one mobile telecom network provider.
Monday, 14 January 2013
Big picture – long picture: the value of horizon scanning
![]() |
| Lee Glendon CBCI |
Big picture – long
picture1: the value of horizon scanning
How can you ensure
that your BCM programme and resources are allocated in a way proportionate to
the current and potential threats that the company is and will be facing?
That’s a real question one of our members faced last year
from her senior management team. While
some folk will be frustrated at the threat-oriented starting point of the
question, it is not an uncommon one as many practitioners will confirm. While ‘risk
assessment through threat evaluation’ may provide some assistance with the
question posed above, horizon scanning potentially provides a framework to
build out the situational picture. It
also provides an opportunity for a proactive stance by practitioners.
Tuesday, 8 January 2013
10 Business Continuity Predictions for 2013 - getting to grips with Business Reslience
![]() |
| Lyndon Bird FBCI |
At
the start of the year it is always tempting to forward and make some
predictions. Like New Year resolutions, however, they are generally much
modified as soon as they come into contact with reality. Nevertheless at the
BCI we asked our experts what they thought might be important Business
Continuity trends in 2013 and got some interesting responses, from which we
listed our top ten, and here they are:
10 Business
Continuity Predictions for 2013
Wednesday, 12 December 2012
Black Swans – something for senior managers to hide behind or to action?
![]() |
| Lyndon Bird FBCI |
Some
business continuity practitioners have argued that Risk Management techniques
provide a tried and tested approach to dealing with conventional threats, but
have limited effectiveness in identifying or evaluating rare but potentially
catastrophic issues.
There
has even been a host of terms that have entered our common lexicon simply to
try and define these types of high impact situations. The former US Defence Secretary Donald Rumsfeld
was much satirised when he talked about “known, unknowns” and “unknown,
unknowns” etc. but it is proving to be a useful way of distinguishing types of
threat.
The
idea of “Black Swans” to define things that are outside of personal experience,
and therefore missed when trying to register potential risks has also been much
debated. Many have treated “Black Swans”
as if they are the same as “unknown, unknowns”, but in most circumstances they
are more akin to “unknown, knowns” -
perhaps unknown to key decision makers but certainly not unknown to everyone.
For
example the volcano ash cloud which closed European airspace is often called a
“Black Swan” event – but every aspect of that drama was well-known by some
people - the volcano might erupt (meteorologists); there is a level of ash that
airplanes were not allowed to fly through (aviation authorities); and there is
a relatively high tolerance to ash levels in more recently designed jet engines
(aerospace engineers). So the problem
was less to do with lack of knowledge but the failure to share and assimilate
the significance of that knowledge.
This
is at the heart of the debates we have about apparent failures of risk
management; the Libor rate scandal; the sub-prime mortgage crisis that bankrupted
many banks; the collapse of the once impregnable Arthur Anderson global
business empire. All came as a great
shock at the time, not only to outsiders, but apparently also to the Board and
C-Suite executives of the organizations concerned.
Lack
of available knowledge was not the problem; lack of knowledge by those who had
the power to stop dangerous things happening was. Claiming such things as “Black Swans” helps
deflect blame on the premise that “how can we have done anything about it if it
was an inconceivable incident?” This excuse might work if a meteorite hits the
earth, but not if we simply have failed to look at signs, talk to people who
know what is happening and adjusted our behaviour accordingly.
I
wonder if there is now a risk that we are headed towards another problem which
is not being properly confronted at the right level. The Business Continuity
Institute and the Chartered Institute of Purchasing and Supply conduct an annual survey into how
well Business Continuity is being handled within the Supply Chain. As a basic question, we collect data about the
main causes of operational disruptions across the world. One item has been steadily rising up the list
until today this year it finished 3rd – after the perennial top-two
of Adverse Weather and IT/Telecoms failure. That factor is “failure or serious disruption
to services provided by an outsourcer”. In
the world of globalization, low cost manufacturing and just-in-time delivery,
we have treated outsourcing (and its close cousin off-shoring) as
self-evidently good things. It allows
management to concentrate on core business; it manages external costs better through
competitive bidding processes and it buys in a higher level of specialist
expertise than might be affordable in-house.
The
problem is that some of this accepted wisdom is being questioned by supply
chain and BCM professionals in organizations, but this message is not being
heard by those who could change it.
As
the global economy continues to stagnate, more and more pressure is placed on
cost-saving and often this leads to excessive price pressure on those
organizations bidding to gain or even retain their accounts. It also leads to more single source suppliers in
return for lower prices and service provision from more geographically,
politically and culturally unstable regions. This seems to be a trade-off between cost and
reliability, and some feel the balance has gone too far with significantly more
disruptions ensuing - which are then causing higher levels of dissatisfied
customers and eventual loss of business.
There
is always a need to make a judgment and a sensible balance between “no risk at
any costs” and “any risk at lowest cost” has to be taken – but for those who
favour the higher risk end of that scale do they really know what consequences
they might be facing. Is this perhaps
another “unknown, known” that top management might try to pass of as a “black
swan” if all goes wrong?
Monday, 24 September 2012
A couple of months can make all the difference.
![]() |
| Lyndon Bird FBCI |
After years of preparation and
much scepticism in some quarters, London 2012 is now over. Both the Olympic and Paralympic Games have
been hailed globally as great achievements. Oddly, I have received congratulations from
colleagues and friends in all parts of the world as if the success of the Games
had had something to do with me. However, reflected glory is always welcome and
I am not complaining that the UK is being viewed in such a positive light.
It is strange that just a few
weeks ago the main media interest was in the failure of G4S to provide adequate
security personnel; the possibility of an immigration officer strike; and doom
and destruction predictions on almost everything from transport to infrastructure. We constantly heard of a grid-locked London,
wide-scale traffic chaos, business disruptions and 1970’s style industrial
action. Even Mitt Romney, the
Republican candidate for the US presidency, publicly expressed his worries on
the eve of the Games based upon little more than arbitrary scare stories.
Some commentators predicted massive
criminality and public disorder although evidence from previous Games suggested
the exact opposite. Others saw it as
inevitable that we would face terrorist attacks, resulting in possible carnage.
Those less dramatic in their
predictions did all seem to agree that London itself would be over-flowing with
people and that businesses would be unable to operate due to the congestion and
staff absenteeism. When pointed out that
tourist numbers were down, the same opinion leaders then changed their
complaint to the fact that the events were scaring normal tourists away such that
hotels, restaurants, theatres and the stores on Oxford Street would soon be
going bankrupt.
To my knowledge little of this
happened. Sensible organizations and individuals arranged their working
practices appropriately. Maybe the
short-term financial boom envisaged by some London leisure businesses failed to
materialise, but the enormous gain to the reputation of London will make people
who never dreamed of visiting London before put it at the top of their list as
a place to see.
The leading UK retailer “The John
Lewis Partnership” reported a major increase in sales and no problem with
“foot-fall” at their central London shops as well as great success at their new
store adjacent to the Olympic Park. Large
organizations like BT, BA and Sainsbury’s have contributed much to the overall
success but it will enhance and benefit their reputation in ways almost nothing
else could. Overall the negative impact
on business has been much exaggerated.
Well did this happen by luck?
Perhaps it is pertinent to quote
golfing legend Gary Player who (when opponents claimed he was fortunate)
famously said “it is odd but the more I practice the luckier I get”. It
seems clear to me that major problems usually occur only when unexpected things
happen, at unpredictable times and when no-one is trained to deal with
them. Fear of the Olympics was like
other potential catastrophes that failed to ignite – think of the millennium
bug or two flu pandemics (avian and swine varieties). All captured the attention of the media but
caused limited or no direct impact because we knew about them and had prepared
accordingly. Where we face real problems is when the threat
is impossible to foresee such as the tsunami triggered by the earthquake
causing a nuclear melt-down; a political extremist running riot in peaceful
Norway; or a corporate scandal getting out of control as we saw a few years ago
with Enron and Arthur Anderson.
For “known, knowns”, the Olympics
is a great example of integrated Business Continuity Management. It shows that however complicated or
frightening a threat is perceived to be, it can be mitigated effectively by
good planning, good organisation and plenty of practice. The Games did not just happen at random, the
organisers knew the dates and schedules in detail for many years. They had the capability and expertise of
leading experts from around the world to call on, and they had time to test and
rehearse everything over and over again until it was perfect. Some
things went wrong, of course, but they were managed not by panic or “off the
cuff” decision-making but by fully trained and committed people using tried and
tested processes.
I hope you all enjoyed summer
2012 as much as I did. It was good for
the morale of the country, great for Risk Managers in showing that risks can be
managed not just avoided and brilliant for those Business Continuity
professionals who contributed their time, efforts, skills and passion to making
it work for everyone.
Friday, 21 September 2012
Business continuity – a culture, not a plan
![]() |
|
Dr Cliff Ferguson Ph.D. AMBCI
|
Business continuity is not just about disaster recovery – it should be a
corporate culture.
This is the view of Clifford Ferguson, chairperson of the South African BCI Forum and Government
Pensions Administration Agency (GPAA) BC Committee, who says that when business
continuity is top of mind, companies can deal with any eventuality.
“The problem – particularly in government departments and parastatals – is that business continuity is seen as disaster recovery. But disaster recovery is only a component of business continuity. So organisations may know how to evacuate a building or locate the disaster recovery site, but they don't necessarily know how to keep their business in full operation in the event of a problem,” he says.
Ferguson says most organisations tend to draft a business continuity plan and shelve it until they face a disaster. “Most companies don't implement their business continuity strategies properly,” he says.
“A comprehensive programme needs to be put into place and be made a business culture. You need a top-down, bottom-up approach, with awareness at lower level and implementation from the top.”
Ferguson highlights his agency's experience in changing its corporate culture to focus on business continuity.
“In line with the requirements of our two major customers – the National Treasury and the Government Pensions Fund (GEPF), we had to implement a comprehensive business continuity plan. We engaged an international consultant and began training and implementation around two years ago.”
The strategy included training and BCI international certification for representative senior management, the appointment of a business continuity committee, including three Exco members, followed by the training of other practitioners. Some staff volunteers also trained as practitioners. The programme did not end with training, however. It is an ongoing project, which includes fortnightly review meetings, desktop exercises, training and awareness days, and live evacuation drills at least once every quarter.
Ferguson says, as a work in progress, the plan is constantly tweaked and revised on the feedback of emergency services and staff.
“For example, we physically move staff to our disaster recovery centre during a drill, and then ask them to report back on possible improvements after the exercise. During an evacuation drill, the emergency services will give us feedback on any problem areas.
“This is unusual – organisations or companies could have a disaster site, but not everyone moves people to test their plan on the site. We make the people own the business continuity plan. We are doing more now and cascading the plan down so every single business unit has its own plan and its own emergency box, too,” he says.
Even though the business continuity programme is relatively new, Ferguson feels the heightened awareness has already benefited the agency.
Unforeseen incidents, such as the mail server going down or the water supply being cut off for days, could previously have caused problems. However, with the new staff mindset, these problems arose recently but caused no disruptions in the agency's work, says Ferguson.
“For example, we had no water and the sanitation facilities became clogged. In a building with hundreds of staff, this was a problem. But we were well prepared, made alternative arrangements and business continued as normal – albeit with some complaints. On another occasion, we experienced power cuts, but it was business as usual. So the training paid off.”
“The problem – particularly in government departments and parastatals – is that business continuity is seen as disaster recovery. But disaster recovery is only a component of business continuity. So organisations may know how to evacuate a building or locate the disaster recovery site, but they don't necessarily know how to keep their business in full operation in the event of a problem,” he says.
Ferguson says most organisations tend to draft a business continuity plan and shelve it until they face a disaster. “Most companies don't implement their business continuity strategies properly,” he says.
“A comprehensive programme needs to be put into place and be made a business culture. You need a top-down, bottom-up approach, with awareness at lower level and implementation from the top.”
Ferguson highlights his agency's experience in changing its corporate culture to focus on business continuity.
“In line with the requirements of our two major customers – the National Treasury and the Government Pensions Fund (GEPF), we had to implement a comprehensive business continuity plan. We engaged an international consultant and began training and implementation around two years ago.”
The strategy included training and BCI international certification for representative senior management, the appointment of a business continuity committee, including three Exco members, followed by the training of other practitioners. Some staff volunteers also trained as practitioners. The programme did not end with training, however. It is an ongoing project, which includes fortnightly review meetings, desktop exercises, training and awareness days, and live evacuation drills at least once every quarter.
Ferguson says, as a work in progress, the plan is constantly tweaked and revised on the feedback of emergency services and staff.
“For example, we physically move staff to our disaster recovery centre during a drill, and then ask them to report back on possible improvements after the exercise. During an evacuation drill, the emergency services will give us feedback on any problem areas.
“This is unusual – organisations or companies could have a disaster site, but not everyone moves people to test their plan on the site. We make the people own the business continuity plan. We are doing more now and cascading the plan down so every single business unit has its own plan and its own emergency box, too,” he says.
Even though the business continuity programme is relatively new, Ferguson feels the heightened awareness has already benefited the agency.
Unforeseen incidents, such as the mail server going down or the water supply being cut off for days, could previously have caused problems. However, with the new staff mindset, these problems arose recently but caused no disruptions in the agency's work, says Ferguson.
“For example, we had no water and the sanitation facilities became clogged. In a building with hundreds of staff, this was a problem. But we were well prepared, made alternative arrangements and business continued as normal – albeit with some complaints. On another occasion, we experienced power cuts, but it was business as usual. So the training paid off.”
Ferguson concludes: “Business continuity planning is critical – unexpected things can happen to anybody. All the incidents we had could have happened to anybody and we didn't know they were coming. However, just having a plan and heightened staff awareness allowed us to continue operations without a hitch when problems occurred. If something big should happen tomorrow, we would probably be prepared, and as business continuity culture improves, so will our preparedness.”
Ferguson will address the upcoming ITWeb Business Continuity 2012 Conference, at The Forum in Bryanston, on 13 November. For more information about this event, click here.
Ferguson will address the upcoming ITWeb Business Continuity 2012 Conference, at The Forum in Bryanston, on 13 November. For more information about this event, click here.
Subscribe to:
Posts (Atom)








