Monday, 30 September 2013

Managing Information - Speeding Up Your OODA Loop

Alan Elwood
Risk and Resilience Ltd

In my last post I talked about the need to manage the process by which crisis decisions are taken and talked about the OODA Loop (read Decision Making Under Pressure – The OODA Loop). In this post I’m going to present some concepts around how you can speed up the time it takes you to complete the OODA Loop. If you can get your decision making processes to happen at a greater speed than that at which the crisis is unfolding then your decisions stand to be more effective. On top of that, making a larger number of quicker decisions, each one correcting the errors of the previous one, is likely to help you reach an optimum solution faster than if you wait for total clarity and try to take one right decision. So what to do?

CRIP: Establish and maintain a full understanding of the situation. This is sometimes referred to as the Common Recognised Information Picture (CRIP). It is built up of all available validated information. It is not a chronological list but a contextualised picture that can inform decisions. Date/time stamp it and keep it up to date, even when the decision makers are not meetings. Use information pull (gathering information in) and information push (people and organisations knowing instinctively to forward information) to achieve this.

Strategic Aims: Make sure the Crisis Management Team establish the strategic aims for the crisis early on. They may even be drafted in a plan for confirmation or adjustment on the day. These won’t change very often but they set the tone for the response, driving information management and response. If the top aim is ‘safety and staff welfare’ this will determine that things progress differently for any given situation than if it is say ‘corporate client entertainment events’. Sounds obvious and simple, but it is often overlooked.

Key Issues: Identify the key issues of the moment and when decisions have to be made by. Remember that people need time to carry out the actions that result from the decisions, so you have less time than you think. Key issues are those that arrive from looking at the CRIP through the lens of the strategic aims. They require management as they reflect the priorities that have been set. Use talented managers to select key issues and identify options prior to the CMT meeting up.

Manage Actions: Decisions need actions to make them a reality. Taking a decision is not the same as things happening. Have a process, team and resources to break decisions down into actions, allocate those actions and monitor performance. Update the CMT on progress so that they can adjust decisions accordingly.

In my final post in this series I will be looking at the reality of translating decisions into actions and all that this entails.

Thursday, 5 September 2013

Decision Making Under Pressure – The OODA Loop


Alan Elwood
Risk and Resilience Ltd

This post relates to a presentation that I will give at the BCM World Conference on the 6 Nov 13 about Control Centre Design. It is one of three posts I will make before then and I hope it is of interest to you.

When United States Air Force pilot John Boyd studied the manner by which those engaged in combat took decisions in time to increase the chances of victory he developed the OODA Loop. From its origins in military doctrine the concepts around how to take decisions in time such that the actions they result in can be effective have made their way into business life. Being able to ensure that, in a crisis, an organisation is able to alter the speed at which it completes the OODA Loop can be the difference between success and failure. Ask yourself the question “Are the world’s governments able to take decisions that result in actions that are ahead of the pace at which problems in the world’s economy unfold?” It might be argued that they are not as their OODA Loop is too slow. So what is involved?

Observation: We need to be aware of what is going on around us in a crisis. That information will come from varied sources, many of which will lie outside of your organisation. Your view of the situational picture must reflect the reality of what is going on. If it does not your decisions will be ill informed and likely as not ineffective or simply too late.  

Orientation: Once a handle on the situation is achieved then its implications must be determined. Clearly you need to know that has happened, you should be clear on what is currently going on but the real trick is anticipating what might change and how that could impact you and others you rely on.  One way of doing this is to be clear on your strategic objectives for the crisis.

Making Decisions. Decisions must be taken in time to allow the actions they produce to be effective. To take decisions you need accurate and timely information, options to choose from and guidance on the time available to do so. You also need the right people.

Taking Actions. Decisions are really just expressed desires as to what should happen. Taking a decision is not the same as the actions it requires taking place. Decisions need to be translated into actions, allocated to teams and performance monitored. Feedback on progress influences our Observation aspect once more.

The nature of the crisis will determine how quickly you need to able to get round the OODA Loop. It is not the other way round!

You can read some more about this subject here. I will post the next blog on how to process information to achieve a suitable tempo of decision making soon.










Friday, 14 June 2013

Five things I learned from this year's Executive Forum...

Lyndon Bird FBCI
Leadership in Resilience was the theme of this year's well-attended Executive Forum and the whole programme was set up to ensure a lively debate around resilience and how BC professionals can take the initiative and lead on this hot issue.   These two-days in Brussels made real progress in clearing the fog and providing some specific examples of where BC professionals can make a difference.  For me the five key learning points were:

1. The growth of the term Resilience in job titles is much more widespread than I had expected. In some cases BC Manager has been changed to Head of Business Resilience without any change of responsibilities. This change is not universally popular among those with the new title because "business continuity" is a strong, meaningful "internal brand" whereas "business resilience" is non-specific and aspirational.

2. Most BC professionals felt there was little or no difference between supply chain continuity or service chain continuity. The only problem is when the criteria for buying an easily specified physical item is applied to buying complex services. The main failure is when procurement professionals do not fully understand the risk associated with any interruption to the service they are acquiring.

3. The new threats that put a business at risk are too complex for one single discipline to "own". For example cyber threats are as varied and as nuanced (both in likelihood and impact) as the physical threats we face - so they cannot just be an IT or Information Security issue. However, they cannot be just a BCM issue either. Risk, Security and BCM must work together, which perhaps is really how resilience needs to be defined in the future.

4. Horizon scanning is now definitely on the BC professionals' agenda. Not necessarily "futurology" yet  - but certainly the mid term assessment of trends and what might threaten business sustainability in the next decade or two.

5. There is a reluctance to consider functional integration as an effective means of breaking down silos. Integration fails to recognise the different purposes of different disciplines and although BCM might logically fit into an overarching risk framework, it has closer practical overlap with security than with conventional risk management or compliance. Collaborative working more than integration seems to be the preferred way forward.

If you missed this year's Executive Forum - I'd certainly recommend you buy a copy of the report when it's available and sign-up for next year's Forum.  It is a rather unique opportunity for senior experienced professionals to think strategically and look ahead.



Monday, 20 May 2013

Business Continuity relationship with other activities

BC shares common goals and objectives with other management activities. When
John Bartlett CBCI, DBCI
implemented correctly and with maturity, BC can provide significant benefit through the sharing of key information and the prioritisation of activities.

The Business Continuity Institute (BCI), a recognised world leader in setting and communication best practices for BC, states that an organisation’s vulnerabilities in its business and operating model can be categorised into seven areas: Reputation, Supply Chain, Information and Communication, Sites and Facilities, People, Finance and Customers. It can also be argued that the categories of Technology and Processes should also be included in this list. Anything that can affect one or more of these categories can potentially disrupt the organisation and therefore should be reviewed and/or considered by the organisations BC.
That does not mean that the BC function should manage areas that could introduce a vulnerability under these categories, but it does mean that BC should perform a Quality Assurance and Governance role to ensure activities that could introduce vulnerabilities are being performed correctly, diligently and with the necessary controls. This will ensure BC remains a pro-active measure within the organisation as well as a reactive one. 
Looking at these vulnerabilities in a more depth allows us to build an understanding of their relationship with BC, and therefore some of the considerations required when conducting a BC risk assessment as well as performing the on-going BC management:
Reputation & Customers
Any activities that are customer facing (such as product or service quality and reliability, help desk, websites, branches, sales people, reception desks) could impact the customers perception of the organisation and therefore the organisations reputation and possibly result in negative publicity which would require management attention and could lead to more wide scale impact and disruption.
Supply Chain
Selection and management of suppliers is an important quality criteria, get it wrong and you place your organisation in jeopardy. Therefore due diligence of suppliers and confidence in their ability to deliver reliable, quality services and have their own risk management and BC in place (for continuance of services to you in the event of an incident is critical). Being able to monitor and measure supplier performance (quality and reliability) and ensure controls are in place will help identify issues early and enable proactive management before an incident becomes a crisis. This may require specific contractual clauses in supplier agreements. For BC, spreading key supplies across suppliers and identifying alternative suppliers will also help manage the risks.
Information and Communication
Ensuring that key information is identified (e.g. during the BIA) and has the necessary controls for safe and secure storage and retrieval, along with preservation will help ensure the information can be available if something goes wrong.
Communication is vital in today’s world of technology, maintaining contact details for key suppliers and staff, and maintaining contact even following disruption is critical. Problems often occur with communication links, so controls should be in place to protect them and alternative links or methods of communication which can be relied upon in the event of an incident should be in place (e.g. email, SMS, GSM, fixed line, data links, satellite links/phones).
Sites and Facilities
Building and site facilities are essential for the smooth running of organisations and numerous resilience options are available from UPS systems and backup generators to spreading occupation over multiple sites. However, the right controls should also be in place to manage and maintain the sites, conducting risk assessments before maintenance work is carried out, notifying stakeholders and ensuring that only authorised or appropriate people conduct work or have access to facilities. It should not be forgotten that BC recovery facilities require the same level of maintenance and control as primary sites.
People
People are sometimes referred to as the ‘life blood’ of organisations therefore it is important to develop resilience and protection for them. This should include implementing Health and Safety (HSSE) to protect their wellbeing, providing suitable training to remove single points of failure (knowledge), improve staff morale & job satisfaction to reduce staff turnover rates, ensure BC requirements are included in job responsibilities and performance measurement. Assessing these is all part of the BC risk assessment as they could contribute to significant risks in the organisation.
Finance
Financial due diligence of suppliers as a control helps protect the organisation. But BC also requires budget, without the right budget facility BC can itself become a risk to the organisation as information and facilities may not be available or maintained as required and therefore not available when needed following a disruption. Also, the information from the BIA should help prioritise expenditure on risk reduction and resilience for critical activities and facilities to help protect the organisation from disruptions.
Technology
Ensuring controls and resilience over technology and infrastructure is paramount in protecting an organisation and developing resilience. This should include regular backups of systems, maintaining IT DR systems in-line with primary systems, include BC and DR assessments in projects and changes, ensuring security and access controls are in place to provide protection, controlling and managing the desktop environment at normal and Business recovery locations, and ensuring focus on the critical systems identified during the BIA and CRA.
Processes
A breakdown in a process often results in a disruption to the organisation. Therefore processes should be designed with controls in place and wherever possible alternative methods for conducting an activity. All these should be documented with procedures to ensure consistency and enforce controls, and maintained.
All of the above should be regularly monitored by the BC function to ensure the controls are in place, being managed and being maintained as they should be. The BC function should have the confidence that this is happening and the capability of escalating any problems if they are not.
BC cannot be implemented and managed in isolation. It holds critical information (from the BIA, RA and CRA) on the organisation, its critical activities, systems, information and suppliers. This should be shared with other management activities such as Enterprise Risk Management (ERM), IT, procurement and Quality Assurance, helping to focus controls, ensure prioritisation on expenditure, projects, etc. and enhance risk reporting. Thereby helping to manage risk more effectively and ensure informed risk-based decisions are made, reducing the likelihood of disruption and level of impact if it does occur. This is the proactive nature of BC and where it will truly add value to any organisation.