Alan Elwood
Risk and Resilience Ltd
In my last post I talked about the need to manage the process by which crisis decisions are taken and talked about the OODA Loop (read Decision Making Under Pressure – The OODA Loop). In this post I’m going to present some concepts around how you can speed up the time it takes you to complete the OODA Loop. If you can get your decision making processes to happen at a greater speed than that at which the crisis is unfolding then your decisions stand to be more effective. On top of that, making a larger number of quicker decisions, each one correcting the errors of the previous one, is likely to help you reach an optimum solution faster than if you wait for total clarity and try to take one right decision. So what to do?
CRIP: Establish and maintain a full understanding of the situation. This is sometimes referred to as the Common Recognised Information Picture (CRIP). It is built up of all available validated information. It is not a chronological list but a contextualised picture that can inform decisions. Date/time stamp it and keep it up to date, even when the decision makers are not meetings. Use information pull (gathering information in) and information push (people and organisations knowing instinctively to forward information) to achieve this.
Strategic Aims: Make sure the Crisis Management Team establish the strategic aims for the crisis early on. They may even be drafted in a plan for confirmation or adjustment on the day. These won’t change very often but they set the tone for the response, driving information management and response. If the top aim is ‘safety and staff welfare’ this will determine that things progress differently for any given situation than if it is say ‘corporate client entertainment events’. Sounds obvious and simple, but it is often overlooked.
Key Issues: Identify the key issues of the moment and when decisions have to be made by. Remember that people need time to carry out the actions that result from the decisions, so you have less time than you think. Key issues are those that arrive from looking at the CRIP through the lens of the strategic aims. They require management as they reflect the priorities that have been set. Use talented managers to select key issues and identify options prior to the CMT meeting up.
Manage Actions: Decisions need actions to make them a reality. Taking a decision is not the same as things happening. Have a process, team and resources to break decisions down into actions, allocate those actions and monitor performance. Update the CMT on progress so that they can adjust decisions accordingly.
In my final post in this series I will be looking at the reality of translating decisions into actions and all that this entails.
Monday, 30 September 2013
Thursday, 5 September 2013
Decision Making Under Pressure – The OODA Loop

Alan Elwood
Risk and Resilience Ltd
This post relates to a
presentation that I will give at the BCM World Conference on the 6 Nov 13 about
Control Centre Design. It is one of three posts I will make before then and I
hope it is of interest to you.
When United States Air Force pilot John Boyd studied the manner by which those engaged in combat took decisions in time to increase the chances of victory he developed the OODA Loop. From its origins in military doctrine the concepts around how to take decisions in time such that the actions they result in can be effective have made their way into business life. Being able to ensure that, in a crisis, an organisation is able to alter the speed at which it completes the OODA Loop can be the difference between success and failure. Ask yourself the question “Are the world’s governments able to take decisions that result in actions that are ahead of the pace at which problems in the world’s economy unfold?” It might be argued that they are not as their OODA Loop is too slow. So what is involved?
Observation: We need to be aware of what is going on around us in a crisis. That information will come from varied sources, many of which will lie outside of your organisation. Your view of the situational picture must reflect the reality of what is going on. If it does not your decisions will be ill informed and likely as not ineffective or simply too late.
Orientation: Once a handle on the situation is achieved then its implications must be determined. Clearly you need to know that has happened, you should be clear on what is currently going on but the real trick is anticipating what might change and how that could impact you and others you rely on. One way of doing this is to be clear on your strategic objectives for the crisis.
Making Decisions. Decisions must be taken in time to allow the actions they produce to be effective. To take decisions you need accurate and timely information, options to choose from and guidance on the time available to do so. You also need the right people.
Taking Actions. Decisions are really just expressed desires as to what should happen. Taking a decision is not the same as the actions it requires taking place. Decisions need to be translated into actions, allocated to teams and performance monitored. Feedback on progress influences our Observation aspect once more.
The nature of the crisis will determine how quickly you need to able to get round the OODA Loop. It is not the other way round!
You can read some more about this subject here. I will post the next blog on how to process information to achieve a suitable tempo of decision making soon.
Friday, 14 June 2013
Five things I learned from this year's Executive Forum...
![]() |
Lyndon Bird FBCI
|
1. The growth of the term Resilience in job titles is much more widespread than I had expected. In some cases BC Manager has been changed to Head of Business Resilience without any change of responsibilities. This change is not universally popular among those with the new title because "business continuity" is a strong, meaningful "internal brand" whereas "business resilience" is non-specific and aspirational.
2. Most BC professionals felt there was little or no difference between supply chain continuity or service chain continuity. The only problem is when the criteria for buying an easily specified physical item is applied to buying complex services. The main failure is when procurement professionals do not fully understand the risk associated with any interruption to the service they are acquiring.
3. The new threats that put a business at risk are too complex for one single discipline to "own". For example cyber threats are as varied and as nuanced (both in likelihood and impact) as the physical threats we face - so they cannot just be an IT or Information Security issue. However, they cannot be just a BCM issue either. Risk, Security and BCM must work together, which perhaps is really how resilience needs to be defined in the future.
4. Horizon scanning is now definitely on the BC professionals' agenda. Not necessarily "futurology" yet - but certainly the mid term assessment of trends and what might threaten business sustainability in the next decade or two.
5. There is a reluctance to consider functional integration as an effective means of breaking down silos. Integration fails to recognise the different purposes of different disciplines and although BCM might logically fit into an overarching risk framework, it has closer practical overlap with security than with conventional risk management or compliance. Collaborative working more than integration seems to be the preferred way forward.
If you missed this year's Executive Forum - I'd certainly recommend you buy a copy of the report when it's available and sign-up for next year's Forum. It is a rather unique opportunity for senior experienced professionals to think strategically and look ahead.
Friday, 31 May 2013
Monday, 20 May 2013
Business Continuity relationship with other activities
BC
shares common goals and objectives with other management activities. When
| John Bartlett CBCI, DBCI |
The
Business Continuity Institute (BCI), a recognised world leader in setting and
communication best practices for BC, states that an organisation’s
vulnerabilities in its business and operating model can be categorised into
seven areas: Reputation, Supply Chain, Information and Communication, Sites and
Facilities, People, Finance and Customers. It can also be argued that the
categories of Technology and Processes should also be included in this list. Anything
that can affect one or more of these categories can potentially disrupt the
organisation and therefore should be reviewed and/or considered by the
organisations BC.
That
does not mean that the BC function should manage areas that could introduce a
vulnerability under these categories, but it does mean that BC should perform a
Quality Assurance and Governance role to ensure activities that could introduce
vulnerabilities are being performed correctly, diligently and with the
necessary controls. This will ensure BC remains a pro-active measure within the
organisation as well as a reactive one.
Looking
at these vulnerabilities in a more depth allows us to build an understanding of
their relationship with BC, and therefore some of the considerations required
when conducting a BC risk assessment as well as performing the on-going BC
management:
Reputation
& Customers
Any
activities that are customer facing (such as product or service quality and
reliability, help desk, websites, branches, sales people, reception desks)
could impact the customers perception of the organisation and therefore the
organisations reputation and possibly result in negative publicity which would
require management attention and could lead to more wide scale impact and
disruption.
Supply
Chain
Selection
and management of suppliers is an important quality criteria, get it wrong and
you place your organisation in jeopardy. Therefore due diligence of suppliers
and confidence in their ability to deliver reliable, quality services and have
their own risk management and BC in place (for continuance of services to you
in the event of an incident is critical). Being able to monitor and measure
supplier performance (quality and reliability) and ensure controls are in place
will help identify issues early and enable proactive management before an
incident becomes a crisis. This may require specific contractual clauses in
supplier agreements. For BC, spreading key supplies across suppliers and
identifying alternative suppliers will also help manage the risks.
Information
and Communication
Ensuring
that key information is identified (e.g. during the BIA) and has the necessary
controls for safe and secure storage and retrieval, along with preservation
will help ensure the information can be available if something goes wrong.
Communication
is vital in today’s world of technology, maintaining contact details for key
suppliers and staff, and maintaining contact even following disruption is
critical. Problems often occur with communication links, so controls should be
in place to protect them and alternative links or methods of communication
which can be relied upon in the event of an incident should be in place (e.g.
email, SMS, GSM, fixed line, data links, satellite links/phones).
Sites
and Facilities
Building
and site facilities are essential for the smooth running of organisations and
numerous resilience options are available from UPS systems and backup
generators to spreading occupation over multiple sites. However, the right
controls should also be in place to manage and maintain the sites, conducting
risk assessments before maintenance work is carried out, notifying stakeholders
and ensuring that only authorised or appropriate people conduct work or have
access to facilities. It should not be forgotten that BC recovery facilities
require the same level of maintenance and control as primary sites.
People
People
are sometimes referred to as the ‘life blood’ of organisations therefore it is
important to develop resilience and protection for them. This should include
implementing Health and Safety (HSSE) to protect their wellbeing, providing
suitable training to remove single points of failure (knowledge), improve staff
morale & job satisfaction to reduce staff turnover rates, ensure BC
requirements are included in job responsibilities and performance measurement.
Assessing these is all part of the BC risk assessment as they could contribute
to significant risks in the organisation.
Finance
Financial
due diligence of suppliers as a control helps protect the organisation. But BC
also requires budget, without the right budget facility BC can itself become a
risk to the organisation as information and facilities may not be available or
maintained as required and therefore not available when needed following a
disruption. Also, the information from the BIA should help prioritise
expenditure on risk reduction and resilience for critical activities and
facilities to help protect the organisation from disruptions.
Technology
Ensuring
controls and resilience over technology and infrastructure is paramount in
protecting an organisation and developing resilience. This should include
regular backups of systems, maintaining IT DR systems in-line with primary
systems, include BC and DR assessments in projects and changes, ensuring
security and access controls are in place to provide protection, controlling
and managing the desktop environment at normal and Business recovery locations,
and ensuring focus on the critical systems identified during the BIA and CRA.
Processes
A
breakdown in a process often results in a disruption to the organisation.
Therefore processes should be designed with controls in place and wherever
possible alternative methods for conducting an activity. All these should be
documented with procedures to ensure consistency and enforce controls, and
maintained.
All
of the above should be regularly monitored by the BC function to ensure the
controls are in place, being managed and being maintained as they should be.
The BC function should have the confidence that this is happening and the
capability of escalating any problems if they are not.
BC
cannot be implemented and managed in isolation. It holds critical information
(from the BIA, RA and CRA) on the organisation, its critical activities,
systems, information and suppliers. This should be shared with other management
activities such as Enterprise Risk Management (ERM), IT, procurement and
Quality Assurance, helping to focus controls, ensure prioritisation on
expenditure, projects, etc. and enhance risk reporting. Thereby helping to
manage risk more effectively and ensure informed risk-based decisions are made,
reducing the likelihood of disruption and level of impact if it does occur.
This is the proactive nature of BC and where it will truly add value to any
organisation.
Subscribe to:
Posts (Atom)

