Information is both a risk and a resource when thinking about organisational resilience, including business continuity. There are plenty of examples of information losses that have caused major embarrassment, cost a considerable amount of money to resolve and resulted in a loss of trust as well as clients. These have included hacking and cyber attack problems, lost memory devices, leaving files on the train or selling off filing cabinets with records still in them. They even involve being photographed on the way to an important meeting carrying a document the content of which can be easily read from the photographs. Organisations involved have ranged from small business to multi-nationals and public sector bodies. The nature of information as a risk is well publicised, as a result, even if after the fact of its loss. The assessment and treatment of information risks is perhaps less well understood in practice as such losses continue to occur. How well thought through is your information risk strategy? Do you fully understand the nature of this risk and have you treated it properly? No one wants to see his or her organisation’s reputation in the gutter due to the loss of sensitive information, be it commercial or personal.
Information is also a key resource when it comes to business recovery. Systems and processes are not useable if the information they require is not available in an accurate, up to date and workable form. Often it may take longer to get information, with proven integrity, loaded back onto a system than to recover the hardware itself. Perhaps this was the problem when it came to the interruption to bank account access experienced in the UK and Ireland in the recent past. The concept of the Recovery Point Objective, the time by which information must be recovered to meet the Recovery Time Objectives of critical processes, is well documented but perhaps less well implemented. If you haven’t gotten into the weeds on this one your recovery strategies may well not deliver as you had hoped. In addition some recovery strategies themselves introduce information risks that may not have existed before the business disruption that caused the strategies to be invoked. Take for example home working. How secure is sensitive or personal information, including emails, when this is your selected recovery option? It is not clear that all organisations have assessed this risk and put in place appropriate steps to treat it. The UK Information Commissioner has had recourse, for example, to fine an organisation in the past for information uploaded onto the web accidentally from a home computer during home working.
There is legislation to cover information risks with the potential for significant fines and websites that name and shame those found responsible for the loss of personal and sensitive information. Currently the EU is reviewing this legislative framework and the outcomes of this work could significantly strengthen the approach taken with those organisations that compromise such information. Planning for this issue isn’t just about what do to when information may be lost but includes a more careful analysis of what information you gather in the first place, how you store it, for how long you keep it, who you allow to access it and how it can be recovered in time. Added to this is the complication of where information ends up and how people actually access it, sometimes without organisations perhaps being aware. This covers issues as diverse as portable laptops, photocopier memory storage and Bring Your Own Devices (BYOD) such as phones or tablets. The scale of the problem can be considerable.
A key place to start is with an information policy. Such a policy could useful set out the principles by which information is to be governed, from initial collation to storage and use/sharing. It should also include destruction and disposal guidance that can be applied to information no longer of use or technology that is not required or obsolete. Such guidance should also cover the eventuality of the invocation of recovery strategies as well as how damaged or irreparable equipment that could hold information is to be safely managed. You can find out much more about this issue at the ICO’s website. Go have a look and educate yourself on this risk and resource.
Alan Elwood MBCI, FICPEM, MEPS
Risk and Resilience Ltd
www.riskresltd.com
enq@riskresltd.com
You can find out more on this subject by watching Alan's webinar - the management of information related risk.
Sunday, 25 May 2014
Friday, 23 May 2014
Is ISO27001 effective in dealing with the cyber threat?
ISO27001, the standard for information security, has recently had a face-lift. It is claimed that ISO27001 is the second largest selling management systems standard in the world and one might assume that this means there has been a significant uptake in its global implementation. The numbers of standards sold is not too surprising. It has been around since 2007 and was essentially derived from BS7799 (1995) and ISO17799 (2000), so information security professionals have had two decades to get used to it. How influential it has been in changing attitudes to security is less clear, some see it as the most important landmark in getting to topic on the management agenda; others see it as too inflexible and procedure based to help counter the real threats posed today by cyber criminality.
Given the strength of some arguments about the value of ISO27001 in a modern context, the need for a face-lift seemed obvious. Many argue that we need a whole new and more agile approach to dealing with cyber threats— and perhaps rigid frameworks like ISO27001 are counterproductive. An analogy that has been made is that the minute tsetse fly is now the biggest threat to human life in Africa, killing the victim slowly following an almost imperceptible bite. Is ISO27001 the equivalent of rifles designed for shooting lions and rhinos when we what we need is new preventative measures and changes in human behaviour? Organizations must be as agile and proactive as the attackers. Frameworks developed for the old world may make this harder.
If this criticism is valid then we have to question whether the revisions to ISO27001 address the main concerns. I think it is fair to say that they do not; there are very little changes and those that have been made are mainly to bring it in line with the administrative requirements now required by ISO. All management systems standards need to follow a structure defined by Annex S1 which is part of a wider ISO directive. In fact old our friend ISO22301 was the first standard to be built against that directive so all the older standards have to play catch-up. The new format for ISO27001 will thus appear very familiar to BC professionals. There are a couple of areas of improvement; beefing up the requirements for performance monitoring and bringing in the outsourced operations. Both additions are very positive improvements in my view.
Perhaps one of the real issues we need to consider is what we mean by information security and cyber resiliency. I do not believe they are necessarily the same thing, although you can’t really have one without the other. A cyber resilient organisation is one that goes beyond compliance. It is one that requires strong, clear leadership and a business model that is flexible, adaptable and agile. It needs to be multi-functional and operate outside of the traditional information security technical expert silo. It must to work closely with all other resilience disciplines as well as understanding business priorities and the key executive concerns.
So does another standard ISO/IEC 27032 provide a better approach? ISO/IEC 27032 claims to address cybersecurity, which it defines as the “preservation of confidentiality, integrity and availability of information in the cyberspace”. In turn cyberspace is defined as “the complex environment resulting from the interaction of people, software and services on the Internet by means of technology devices and networks connected to it, which does not exist in any physical form.” So, in reality this standard is purely about internet security. It does not address cyber-safety, cybercrime, internet safety, internet related crime or protection of critical information infrastructure, although there are oblique references to these aspects. It is also not a specification, only a guidance document so it provides some valuable insights but does not replace the need for or do the work of ISO27001.
Clearly, there are no shortages of formal approach to cyber security but resilience requires more than a traditional information security framework. Compliance against ISO27001 gives baseline protection against conventional cyber-threats, but it might not be agile enough to handle the ever changing landscape. Professionals need to beyond compliance and create organisations that are more pro-active in understanding threats and more flexible in response capability. ISO27001 is a useful tool but more fundamental cultural shifts are needed in the way organizations behave.
Lyndon Bird
Technical Director at The Business Continuity Institute
Given the strength of some arguments about the value of ISO27001 in a modern context, the need for a face-lift seemed obvious. Many argue that we need a whole new and more agile approach to dealing with cyber threats— and perhaps rigid frameworks like ISO27001 are counterproductive. An analogy that has been made is that the minute tsetse fly is now the biggest threat to human life in Africa, killing the victim slowly following an almost imperceptible bite. Is ISO27001 the equivalent of rifles designed for shooting lions and rhinos when we what we need is new preventative measures and changes in human behaviour? Organizations must be as agile and proactive as the attackers. Frameworks developed for the old world may make this harder.
If this criticism is valid then we have to question whether the revisions to ISO27001 address the main concerns. I think it is fair to say that they do not; there are very little changes and those that have been made are mainly to bring it in line with the administrative requirements now required by ISO. All management systems standards need to follow a structure defined by Annex S1 which is part of a wider ISO directive. In fact old our friend ISO22301 was the first standard to be built against that directive so all the older standards have to play catch-up. The new format for ISO27001 will thus appear very familiar to BC professionals. There are a couple of areas of improvement; beefing up the requirements for performance monitoring and bringing in the outsourced operations. Both additions are very positive improvements in my view.
Perhaps one of the real issues we need to consider is what we mean by information security and cyber resiliency. I do not believe they are necessarily the same thing, although you can’t really have one without the other. A cyber resilient organisation is one that goes beyond compliance. It is one that requires strong, clear leadership and a business model that is flexible, adaptable and agile. It needs to be multi-functional and operate outside of the traditional information security technical expert silo. It must to work closely with all other resilience disciplines as well as understanding business priorities and the key executive concerns.
So does another standard ISO/IEC 27032 provide a better approach? ISO/IEC 27032 claims to address cybersecurity, which it defines as the “preservation of confidentiality, integrity and availability of information in the cyberspace”. In turn cyberspace is defined as “the complex environment resulting from the interaction of people, software and services on the Internet by means of technology devices and networks connected to it, which does not exist in any physical form.” So, in reality this standard is purely about internet security. It does not address cyber-safety, cybercrime, internet safety, internet related crime or protection of critical information infrastructure, although there are oblique references to these aspects. It is also not a specification, only a guidance document so it provides some valuable insights but does not replace the need for or do the work of ISO27001.
Clearly, there are no shortages of formal approach to cyber security but resilience requires more than a traditional information security framework. Compliance against ISO27001 gives baseline protection against conventional cyber-threats, but it might not be agile enough to handle the ever changing landscape. Professionals need to beyond compliance and create organisations that are more pro-active in understanding threats and more flexible in response capability. ISO27001 is a useful tool but more fundamental cultural shifts are needed in the way organizations behave.
Lyndon Bird
Technical Director at The Business Continuity Institute
Wednesday, 7 May 2014
What if...?
Keynote speaker and facilitator at this year’s BCI Executive Forum, Dr James Bellini sets the scene and identifies some of the major issues that will face business continuity professionals in the years ahead:
As a futurologist of many years’ standing I am regularly confronted with requests to ‘predict’ the outcome of some activity or development in the world of tomorrow. On occasion I’m even asked the name of the winner of an important upcoming horse race, or the score line of a major soccer match a few weeks hence. If only my crystal ball were that magical ... but it also reveals a basic misunderstanding of what futurology is all about.
I see my task as threefold: to apply a reality check on popular perceptions of the world around us, to create a framework for examining how ‘the future’ might unfold and to identify one or two possible future events or issues that would, if they actually occurred, pose very serious challenges for either business, government or the wider society – or all of these together.
A key tool of the futurologist is the ‘scenario’, in effect a way of thinking about a range of ‘possible’ futures that would have major implications for the way the world works in five, ten or fifteen years from now. To be of any value these scenarios should have a degree of realistic plausibility about them. A Star Trek future of brain transplants and off-world vacation resorts might offer a wacky or romantic vision of life in the 23rd century, but is of little use to decision-makers keen to understand what environment they may have to deal with over the decade ahead. A ‘relevant’ future timeline of perhaps a dozen years at most is the backdrop against which business continuity professionals must arrange their thinking about the risks, pitfalls and options of a changing world.
I will use my opening session to explore the emerging new realities of tomorrow, offering a range of ‘possible’ futures that would – if any of them materialised – change the rules that shape the nature of crises and threats to reputation. For example, it is clear the ‘geography’ of global business will undergo a fundamental shift in the years ahead – but in which direction? What, to take a liberty with syntax, might be the where of tomorrow’s potential crisis situations?
Other scenarios will consider the impact new technologies might have in the years ahead. How (and where) might homes and businesses, neighbourhoods, cities and even entire countries function in the ‘smart’ world of the 2020s? The social benefits may be immense, but with ever more technology in our lives, will it also bring more risks to everyday continuity?
And what are the implications for crisis management of an increasingly connected, online, digital universe. How is this changing the way information is originated, managed, distributed and owned? What if the internet collapses, or the social media revolution takes an unforeseen change of direction, or people simply grow bored with their digital lives and dump the devices and networks that are now the backbone of business, government and everyday life? What if...?
With the theme 'a new horizon', the BCI Executive Forum takes place on the 21st and 22nd May at the Marriott Hotel in Amsterdam. For further information or to book your place, click here.
As a futurologist of many years’ standing I am regularly confronted with requests to ‘predict’ the outcome of some activity or development in the world of tomorrow. On occasion I’m even asked the name of the winner of an important upcoming horse race, or the score line of a major soccer match a few weeks hence. If only my crystal ball were that magical ... but it also reveals a basic misunderstanding of what futurology is all about.
I see my task as threefold: to apply a reality check on popular perceptions of the world around us, to create a framework for examining how ‘the future’ might unfold and to identify one or two possible future events or issues that would, if they actually occurred, pose very serious challenges for either business, government or the wider society – or all of these together.
A key tool of the futurologist is the ‘scenario’, in effect a way of thinking about a range of ‘possible’ futures that would have major implications for the way the world works in five, ten or fifteen years from now. To be of any value these scenarios should have a degree of realistic plausibility about them. A Star Trek future of brain transplants and off-world vacation resorts might offer a wacky or romantic vision of life in the 23rd century, but is of little use to decision-makers keen to understand what environment they may have to deal with over the decade ahead. A ‘relevant’ future timeline of perhaps a dozen years at most is the backdrop against which business continuity professionals must arrange their thinking about the risks, pitfalls and options of a changing world.
I will use my opening session to explore the emerging new realities of tomorrow, offering a range of ‘possible’ futures that would – if any of them materialised – change the rules that shape the nature of crises and threats to reputation. For example, it is clear the ‘geography’ of global business will undergo a fundamental shift in the years ahead – but in which direction? What, to take a liberty with syntax, might be the where of tomorrow’s potential crisis situations?
Other scenarios will consider the impact new technologies might have in the years ahead. How (and where) might homes and businesses, neighbourhoods, cities and even entire countries function in the ‘smart’ world of the 2020s? The social benefits may be immense, but with ever more technology in our lives, will it also bring more risks to everyday continuity?
And what are the implications for crisis management of an increasingly connected, online, digital universe. How is this changing the way information is originated, managed, distributed and owned? What if the internet collapses, or the social media revolution takes an unforeseen change of direction, or people simply grow bored with their digital lives and dump the devices and networks that are now the backbone of business, government and everyday life? What if...?
With the theme 'a new horizon', the BCI Executive Forum takes place on the 21st and 22nd May at the Marriott Hotel in Amsterdam. For further information or to book your place, click here.
Friday, 25 April 2014
Does business continuity in the public sector work, and does it get the buy in it deserves?
Many larger companies which have Business Continuity Management systems produce or deliver products. Failure to deliver as a result of any interruption will very likely impact upon the business financially and could ultimately put companies out of business. Is there any wonder therefore that the management of such businesses are often quite willing to spend money on protecting their interests.
Public Sector organisations tend to be on the larger size, often having a few hundred employees at the very least and in some cases going into the several thousands of staff. So why is it that the willingness of managers in the public sector to deliver BCMs is not always on the top of the priority list? I should say at this point that I am fortunate to work for a large public service organisation that is wholly behind BC and which has continued to invest in BC despite the financial restrictions which are currently impacting upon us.
In relation to public services there is often little chance of losing business as a result of an interruption and even less chance of being put out of business as a result of financial implications. There is often a cushion of ‘the public purse’ and an assumption that we can manage without BC. However there is every chance of reputational damage being done to the organisation or even to a whole group of organisations. Damage to our reputations is probably under greater scrutiny than at any time in our history.
BC is implemented in the private sector as a matter of necessity or indeed because it is seen by the companies as beneficial. It provides protection against unintended events and may even be a requirement of insurance companies to mitigate any foreseeable risks.
In the public sector BC is often implemented because it is a statutory requirement for plans to be in place. In particular the Civil Contingencies Act 1994 imposes a duty for many public sector organisations to have BC plans in place. The feeling of having something imposed upon you without having the buy in from senior management can only be detrimental to the introduction of BC planning within an organisation.
Many Public Sector organisations utilise ISO22301 to align their BC planning to, or certify their planning against. Is this standard really suitable for the Public Sector? I have heard comments from various sources that the standard doesn’t work for certain organisations.
Many public sector organisations rely upon specialist equipment, very often things which can only be supplied by one manufacturer and sometimes with extremely long lead times. For instance if an individual piece of medical equipment, or a specialised vehicle, is rendered unavailable, no business continuity plan would provide resilience, or would it?
I firmly believe that ISO22301 provides all organisations with the opportunity to create BCMs which are appropriate to their individual requirements. Alignment to most parts of the standard can be achieved and for those organisations wishing to certify against the standard then there are ample opportunities to achieve this.
Due to the very nature of public services, usually a ‘can do’ attitude and the ability to obtain mutual aid from each other, perhaps the very existence of Business Continuity Plans provides the opportunity for us to document this reliable form of restoring services. Borrowing both staff and equipment is not unusual throughout much of the public sector. There will always be occasions when a single point of failure cannot be wholly mitigated against, but this is a rarity and should not be used as an excuse not to establish a course of action, as a minimum, should a failure occur.
In the current climate, where most public sector organisations are trying to deliver services with less financial backing there seems to be an increase in appetite for BC plans to identify resilience, especially in relation to reputational issues. It is clear to the majority that massive reductions in staff numbers across the sector lead to a reduction of services and certainly do not allow for any depth of resilience should the worst occur.
It is imperative that public services spend their available finances wisely. A small amount of expenditure spent now to provide suitable resilience could save large chunks of their budget in the future.
The smallest of changes can make a difference. BC managers should grasp every opportunity to join groups of BC professionals, enabling them to share experiences and collaborate with each other. They should take advantage of training opportunities, which don’t always have to be expensive, participation in webinars and locally arranged events are a great source of information. They should also take advantage of organised promotions to put plans in place and embed them throughout their organisations.
Russ Parramore
Business Continuity Manager
South Yorkshire Fire & Rescue
Public Sector organisations tend to be on the larger size, often having a few hundred employees at the very least and in some cases going into the several thousands of staff. So why is it that the willingness of managers in the public sector to deliver BCMs is not always on the top of the priority list? I should say at this point that I am fortunate to work for a large public service organisation that is wholly behind BC and which has continued to invest in BC despite the financial restrictions which are currently impacting upon us.
In relation to public services there is often little chance of losing business as a result of an interruption and even less chance of being put out of business as a result of financial implications. There is often a cushion of ‘the public purse’ and an assumption that we can manage without BC. However there is every chance of reputational damage being done to the organisation or even to a whole group of organisations. Damage to our reputations is probably under greater scrutiny than at any time in our history.
BC is implemented in the private sector as a matter of necessity or indeed because it is seen by the companies as beneficial. It provides protection against unintended events and may even be a requirement of insurance companies to mitigate any foreseeable risks.
In the public sector BC is often implemented because it is a statutory requirement for plans to be in place. In particular the Civil Contingencies Act 1994 imposes a duty for many public sector organisations to have BC plans in place. The feeling of having something imposed upon you without having the buy in from senior management can only be detrimental to the introduction of BC planning within an organisation.
Many Public Sector organisations utilise ISO22301 to align their BC planning to, or certify their planning against. Is this standard really suitable for the Public Sector? I have heard comments from various sources that the standard doesn’t work for certain organisations.
Many public sector organisations rely upon specialist equipment, very often things which can only be supplied by one manufacturer and sometimes with extremely long lead times. For instance if an individual piece of medical equipment, or a specialised vehicle, is rendered unavailable, no business continuity plan would provide resilience, or would it?
I firmly believe that ISO22301 provides all organisations with the opportunity to create BCMs which are appropriate to their individual requirements. Alignment to most parts of the standard can be achieved and for those organisations wishing to certify against the standard then there are ample opportunities to achieve this.
Due to the very nature of public services, usually a ‘can do’ attitude and the ability to obtain mutual aid from each other, perhaps the very existence of Business Continuity Plans provides the opportunity for us to document this reliable form of restoring services. Borrowing both staff and equipment is not unusual throughout much of the public sector. There will always be occasions when a single point of failure cannot be wholly mitigated against, but this is a rarity and should not be used as an excuse not to establish a course of action, as a minimum, should a failure occur.
In the current climate, where most public sector organisations are trying to deliver services with less financial backing there seems to be an increase in appetite for BC plans to identify resilience, especially in relation to reputational issues. It is clear to the majority that massive reductions in staff numbers across the sector lead to a reduction of services and certainly do not allow for any depth of resilience should the worst occur.
It is imperative that public services spend their available finances wisely. A small amount of expenditure spent now to provide suitable resilience could save large chunks of their budget in the future.
The smallest of changes can make a difference. BC managers should grasp every opportunity to join groups of BC professionals, enabling them to share experiences and collaborate with each other. They should take advantage of training opportunities, which don’t always have to be expensive, participation in webinars and locally arranged events are a great source of information. They should also take advantage of organised promotions to put plans in place and embed them throughout their organisations.
Russ Parramore
Business Continuity Manager
South Yorkshire Fire & Rescue
Friday, 11 April 2014
Business Continuity Flash Blog
On Tuesday 18th March 2014, as part of the Business Continuity Awareness Week activities, we witnessed the first ever BC Flash Blog. This is probably a new term to most readers, it is a virtual Flash Mob – but instead of a dance routine the participants wrote and published their own blog post or article.
The event featured 22 writers, from all sectors of the BC industry – and from various corners of the globe. All the articles were on the same subject, and published at the same time. In keeping with the BCAW theme, the subject was “Counting the costs, and benefits, for business continuity”, with each writer taking their own, unique, perspective on this issue.
If you haven’t already done so, you can find links to all 22 of these blogs here. If we do nothing else, we can at least pay these writers the respect of reading their work.
For those who are interested in statistics, the page with the list of articles has had over 600 views (as of the 7th April). The list is hosted on a service called List.ly that facilitates social media style interactions with the community. Readers are able to flag like/dislike; indicate which articles they have read and, perhaps just as importantly, which subjects they would like to learn more about.
To date there have been 123 of these interactions recorded – but sadly these have come from only 11 people. You do have to register with the service to interact, which may have stopped many from casting a vote. These interactions are still open, and it would provide useful feedback to guide future articles if you could visit the site and record your thoughts.
Despite the relatively low number of interactions recorded, the feedback from a number of the writers indicates a good level of hits on these articles. While not everybody had full scale analytics, reported around 100 hits on their article and another over 180 hits. This may, in part, represent the existing audience of some of these writers as much as the BCAW promotion - but that is part of the educational value to be derived from the exercise.
BC folk need to learn about tapping into, and leveraging, existing networks and communities if we want to promote our cause and our message. The extra reader base accessed by distributed, rather than centralised, blog hosting. Just as importantly, the extended reach of the Social Media networks of the various writers and the 'priceless' publicity that was generated by the Tweets and Retweets. These are lessons we can look at applying to our own BC programmes. How we can use tools like blogs and wikis in our organizations; improving our understanding (and adoption) of the various social media tools (like List.ly) and the value of debate and interaction, rather than passive consumption, in promoting a vibrant discipline.
One message that comes through very clearly in several of these articles is the passion that BC people have for the work we do. It was a joy to see that passion from old practitioners as well as from newer ones. The passion for the work and promoting the cause also spanned geography and language.
That passion means we can at times be forceful when we debate our different views and perspectives on how to count the costs – and even what constitutes benefits and value from BC. But it also drives a genuine desire to promote improvement and learning across our practices. Without debate, and passion, no field of knowledge will develop. But debate requires engagement.
I spoke about this passion, and used three of the articles as examples, in my BCAW webinar. It is recorded and can be accessed here, it also contains some instruction on how to access and engage with the List of articles.
It would be great to hear some feedback about the concept of a Flash Blog, about the articles, or even what topic you would like to see for a future Flash Blog event. You can comment here on The BC Eye, or start a discussion in one of the many Linked In groups where this post will be promoted.
My thanks to all those who contributed articles, I hope you all keep writing! Thank you also to those who take the time to read – and extra special thanks to those who make it all worthwhile by engaging and debating these ideas.
Finally, if you are wondering why we chose to have our Flash Mob write a blog post rather than demonstrate a dance routine – then this YouTube clip (featuring one of our contributors) should provide an adequate explanation.
Ken Simpson
Director of The VR Group
The event featured 22 writers, from all sectors of the BC industry – and from various corners of the globe. All the articles were on the same subject, and published at the same time. In keeping with the BCAW theme, the subject was “Counting the costs, and benefits, for business continuity”, with each writer taking their own, unique, perspective on this issue.
If you haven’t already done so, you can find links to all 22 of these blogs here. If we do nothing else, we can at least pay these writers the respect of reading their work.
For those who are interested in statistics, the page with the list of articles has had over 600 views (as of the 7th April). The list is hosted on a service called List.ly that facilitates social media style interactions with the community. Readers are able to flag like/dislike; indicate which articles they have read and, perhaps just as importantly, which subjects they would like to learn more about.
To date there have been 123 of these interactions recorded – but sadly these have come from only 11 people. You do have to register with the service to interact, which may have stopped many from casting a vote. These interactions are still open, and it would provide useful feedback to guide future articles if you could visit the site and record your thoughts.
Despite the relatively low number of interactions recorded, the feedback from a number of the writers indicates a good level of hits on these articles. While not everybody had full scale analytics, reported around 100 hits on their article and another over 180 hits. This may, in part, represent the existing audience of some of these writers as much as the BCAW promotion - but that is part of the educational value to be derived from the exercise.
BC folk need to learn about tapping into, and leveraging, existing networks and communities if we want to promote our cause and our message. The extra reader base accessed by distributed, rather than centralised, blog hosting. Just as importantly, the extended reach of the Social Media networks of the various writers and the 'priceless' publicity that was generated by the Tweets and Retweets. These are lessons we can look at applying to our own BC programmes. How we can use tools like blogs and wikis in our organizations; improving our understanding (and adoption) of the various social media tools (like List.ly) and the value of debate and interaction, rather than passive consumption, in promoting a vibrant discipline.
One message that comes through very clearly in several of these articles is the passion that BC people have for the work we do. It was a joy to see that passion from old practitioners as well as from newer ones. The passion for the work and promoting the cause also spanned geography and language.
That passion means we can at times be forceful when we debate our different views and perspectives on how to count the costs – and even what constitutes benefits and value from BC. But it also drives a genuine desire to promote improvement and learning across our practices. Without debate, and passion, no field of knowledge will develop. But debate requires engagement.
I spoke about this passion, and used three of the articles as examples, in my BCAW webinar. It is recorded and can be accessed here, it also contains some instruction on how to access and engage with the List of articles.
It would be great to hear some feedback about the concept of a Flash Blog, about the articles, or even what topic you would like to see for a future Flash Blog event. You can comment here on The BC Eye, or start a discussion in one of the many Linked In groups where this post will be promoted.
My thanks to all those who contributed articles, I hope you all keep writing! Thank you also to those who take the time to read – and extra special thanks to those who make it all worthwhile by engaging and debating these ideas.
Finally, if you are wondering why we chose to have our Flash Mob write a blog post rather than demonstrate a dance routine – then this YouTube clip (featuring one of our contributors) should provide an adequate explanation.
Ken Simpson
Director of The VR Group
Subscribe to:
Posts (Atom)




