Wednesday, 26 November 2014

BCI World Conference and Exhibition

Ever reacted to something quickly and soon regretted it? That is our Inner Chimp controlling us and sometimes there is nothing we can do about it. That was the message from Prof Steve Peters during his keynote speech at the BCI World Conference. Psychology plays a major part in business continuity and sometimes you need to take into account that people don’t always respond the way you would like them to, or in a way they would like to.

In the second keynote speech of the conference, Martin Fenlon – Business Resilience Coordinator at the Houses of Parliament, told us of the challenges he faced in ensuring resilience across a highly independent and disparate organisation. Of course it’s a very British organisation, so in the event of a crisis, as long as someone is making tea then all is well. It was particularly appropriate for Martin to be speaking on the 5th November as this day marks the anniversary of when Guy Fawkes attempted, and failed, to blow up the Houses of Parliament.

Over the two days, many speakers educated us and enlightened us about different aspects of business continuity. Whether it was new research such as the BCI’s Supply Chain Resilience or Emergency Communications reports; insight into some practical application of business continuity, for example how to deal with the Ebola crisis; or whether it was developing a greater understanding of the theoretical aspects of business continuity such as how to write a BIA; there was something for everyone.

Day one of the conference ended with the Gala Dinner and Global Awards ceremony at the Science Museum. Well done to all our winners in the nine categories of the Global Awards, those whose contribution to the industry was recognised above all else, and congratulations to everyone who was honoured on the night. A full list of winners can be found here.

One of the main talking points of the conference was the debate about whether business continuity can only ever be subservient to risk management as the top thought leaders from both sides of the industry battled it out. In the end it was a home win for business continuity and the motion was voted against but there were certainly plenty of interesting discussions on the matter. The general consensus however, was that those working in business continuity, risk management or other related fields need to collaborate more in order to improve organisational resiliency.

Organisational resilience has become a common theme in many of our discussions lately and we were fortunate to have Richard Taylor from BSI announce the new Standard on this very topic which is being published on the 27th November. This was followed by Dr Rob MacFarlane from the Cabinet Office who talked about resilience in practical terms, looking beyond just individual organisations but wider communities.

As in previous years, the BCI held a BC clinic, hosted by experienced practitioners, for people to ask their BC related questions and get advice that they can take back to their own organisation and implement.


To finish off the conference in style, Crisis Guardian hosted a game show whereby those working in the industry were given the chance to answer questions with the top three being invited on stage for the grand final. Demonstrating the international flavour of the conference, this was fought between an American, an Australian and an Italian. Ultimately the winner was Chris Miller whose baggage allowance for her trip back down under was put in jeopardy by her shiny new trophy.

Thank you to everyone who came along and made the conference the great success that it was. Exhibitors, presenters and delegates all contributed to this and we look forward to welcoming you back to the London Olympia next year on the 4th and 5th November.

Wednesday, 19 November 2014

Business continuity planning according to Paddington Bear

In just a few weeks the latest blockbuster movie to hit our screens will be released at the cinema – Paddington Bear. This is the story of a well-meaning Spectacled Bear with a fondness for marmalade sandwiches who made his way over to England from Peru and was adopted by the Brown family who named him after the station he was found in.

But what has this got to do with business continuity? When arriving in England, Paddington probably wanted to write to his family and let them know he arrived safely, but had he done so then his letter would soon have been returned to him with a polite note from Royal Mail saying that they weren’t even going to try posting it. Why? Because Peru was going through a lengthy postal strike that had left such a backlog that it would take many months to recover from.

Peru may be an extreme example but postal strikes happen in many countries all the time and if your organisation is reliant on the postal service then it could cause a major disruption to you and your customers.

Of course it’s worth noting that according to the Business Continuity Institute’s latest Horizon Scan Report, industrial disputes are not something that provides most business continuity professionals with any concern. In the survey that informed the report, only 21% of respondents expressed concern or extreme concern at the prospect of an industrial dispute causing a disruption to their organisation. Perhaps they were thinking more of their own employees taking industrial action rather than the consequence of a supplier’s industrial action.

It does make you consider just how reliant you are on the postal service, or any other service for that matter. Despite tending to use email and other forms of electronic communications, there are still times when we rely on ‘snail mail’. The main example is that, with many of us leading such busy lives, we often turn to goods and services that are delivered direct to our door. The rise in electronic communications has also seen the rise in online shopping so if you are a retailer then a postal strike could have a devastating impact on your business.

It is therefore worth thinking, what would you do if the postal service was no longer available to you, what are the alternatives? How would you deliver to your customers or receive goods from your suppliers?

Fortunately for Paddington, Mr Brown had a telephone so he was able to phone home instead and let his Aunt Lucy know he had arrived safely.

Tuesday, 4 November 2014

Business continuity importance to an integrated view when assessing critical infrastructures

As result of EDP Distribuição's responsibilities, its involvement was required in Portuguese efforts to comply with the European Council Directive 2008/114/EC, on the identification and designation of National Critical Infrastructures (NCI) and the assessment of the need to improve their protection.

EDP Distribuição is the Portuguese mainland Distribution System Operator, serving over 6 million customers in a regulated business with clearly defined responsibilities, being the holder of the concession to operate the Distribution Electric Power Network in Medium Voltage and High Voltage, and holding municipal concessions for the distribution of electricity in Low Voltage.

With EDP Distribuição under having responsibility for several assets and systems which are essential for the maintenance of vital societal functions - health, safety, security, economic or social well-being of people, the challenges were many. The selection of a manageable number of assets from a set of more than 400 main premises, the identification of their major threats and vulnerabilities, and writing down their emergency response procedures, were some.

With EDP Distribuição’s Business Continuity Department coordination, an integrated view of the organization was possible, enabling the address of critical infrastructure in the perspective of personal safety, facility security and information security, involving several departments from operational ones (Maintenance and Dispatch) to support departments (Automation & Remote Control, Information Systems, Health and Safety).

The key points and the key learning points we plan to cover in our presentation are:
  • Identification of major threats, vulnerabilities and cross-business risks for each NCI typology;
  • Development of risk assessment methodology in safety and security aspects and;
  • Application to each distinct vectors: people, facilities, system and communications;
  • Definition of emergency response procedures and supporting chain command enabling effective risk mitigation;
  • Upgrading the organization resilience through the implementation of this PDCA process.
Maria Luisa Pestana will be discussing business continuity importance to an integrated view when assessing critical infrastructures on day one of the BCI World Conference and Exhibition on Wednesday 5th November. You will find her in seminar room 2 starting at 13.10.

Friday, 31 October 2014

Resource-based contingency planning – an alternative approach to ISO22301 certification

Business continuity is, especially in the Anglo-American world, not that much a new concept. Being not new also means that it probably is due to be redesigned. Since the inception of Business Continuity Management in the late 80s and early 90s of the last century, the world has changed quite a bit. The main concepts, procedures and processes of BCM however have not changed that much in the past 25 or so years. We are still talking PDCA, we are still talking process-based business impact analysis, we are still trying to do the work of risk managers with our task in the fields of operational and reputation risks. We still have the BCM Lifecycle.

Those who are practitioners in the profession may have already realized that the theoretical strategies and tactics as outlined by the BCM Lifecycle approach may not always meet the needs and possibilities of an organization seeking to implement BCM. The business impact analysis for instance needs processes, since it aims to operationalize the damage because of failed process. But, which organization does have a complete and operationalized process document which allows it to just sum up losses and damages along process chains? And, how can the BCM organization define the so-called BCM-Strategies when they haven’t even asked the business what they think they need as workarounds to cover a resource which was lost or damaged because of some crisis situation?

Here we already have the word, what this presentation is about: Resources. What I do call resource-based contingency planning is actually not just contingency planning, but part of a new approach to business continuity, which offers an alternative to the BCM Lifecycle. In the first part of the presentation, I will briefly introduce this system, which covers all parts of what we know is demanded by the BCM Lifecycle, however in a quite different sequence and with partly completely different methods and tools, and which addresses all controls of the ISO22301 standard.

In the few minutes I have for the presentation, I cannot go through the complete methodology what I call resource-based business continuity. I only show a core part of it, one of the 15 deliverables and work objects of a business continuity management system – the business continuity plan, the probably most important one of five different plan types which need to be created for a complete BCMS (the others being the disaster recovery plans, the emergency and rescue plans, the crisis communication plan and the crisis management plan).

The most astonishing part of these BCPs may be the inclusion of a risk assessment as a part of this plan. The risk assessment, being a core element of ISO22301 requirements, is no longer a work package of its own, but an integral part of contingency planning. The reasons for this, and why this makes much more sense than to emulate the work of a risk manager prior to actually planning for catastrophes, will be given in my presentation. The same by the way, is true for the identification of critical suppliers and clients, which also is done in the course of discussing and deciding on a workaround in the case of the loss of a critical resource.

However, in the title of my presentation, you find the most important difference between the BCM Lifecycle approach to business continuity compared to what I am doing. Where the lifecycle’s objective and basis of action and contingency planning is the business process, in my world it is the resource. One does not need the availability of documented and operationalized business processes to implement a BCMS, but only knowledge about what resources an organization has. And, differently from processes, this bit of information is most often readily available, and if not, can be created without much work.

With the presentation, I will provide a view into a core part of an alternative approach to ISO22301 certification, which delivers some novel ideas how to structure a contingency plan, how to identify critical clients and suppliers, and how to identify and assess operational risks. And if you pay attention, you might get an idea, why this approach to implement business continuity allows for applying for certification some six months after start of the project already, and why this approach reduces the cost of BCM between 50% and 80%.

Rainer Hubert will be discussing ISO22301 further on day two of the BCI World Conference and Exhibition on Thursday 6th November. You will find him in seminar room 1 starting at 13.10.

Thursday, 30 October 2014

Becoming certified to ISO22301 - what NOT to do! (Why auditors get grumpy!)

Tip number 1: The lack of a regular supply of good quality biscuits is the first non-conformity!

Looking forward to my presentation at 13:10hrs on November 6th in seminar room 2 of the free exhibition part of this year’s BCI World Conference and Exhibition. I realise that there are many BC practitioners who, although practiced in the creation and maintenance of a Business Continuity Management System (BCMS), have yet to seek certification to a standard. Additionally I recognise that others may have only assisted in achieving certification and even those though certified constantly struggle with a stream of nonconformities found by external auditors and which if left unresolved threaten the organisations certification.

During the past three years I have been working as an externally contracted assessor and ‘Technical Specialist’ with one of the top assessment organisations in the world who, via audit, assess companies for the suitability of their BCMS for certification to initially the BS25999:2006 standard and subsequently its replacement ISO22301:2012. Over this time I have been fortunate to audit the BCMS of around 100 companies by pre-assessments, Stage 1, Stage 2 and Continuous Assessment Visits (CAV’s).

Fellow practitioners sometimes ask me if I get bored with assessing to the same standard day after day. Fortunately this is not a problem as although the same standard no BCMS is alike and understanding the multiple ways of constructing a BCMS compliant with the standard has been fascinating and provides me with continuous opportunities for my own personal development, sometimes by observing good practice but unfortunately all too often from seeing practices which fail to meet the basic requirements.

I should make it clear, and possibly surprising for those who know me, that I am a big supporter of the 22301 standard. Now it is by no means the perfect standard, if indeed that could ever be achieved. However, I am someone who began in this business when training courses, good practice guides and the words “Business Continuity Management System” were things of the future and, to be frank, “making it up as we went along” was the name of the game. As a result it is in my view great to have a common structure around which to create a Business Continuity Management System. Now of course we need to improve it.

So what will I be presenting? Will it be the secret formula which all Business Continuity practitioners seek to create the perfect BCMS? Will it be the best way to smooth the ego of your auditor to the point where they are purring over your perfect creation? Only one way to find out, be there, oh and bring a biscuit or two.

Colin Ive has been a Member of the Business Continuity Institute since 2001 and is a qualified Lead Auditor for ISO9001, ISO22301 & ISO28000. He is a regular presenter at European & USA Business Continuity and Business Resilience Conferences and a contributing author to both the ‘BCI Good Practice Guide for Business Continuity Planning’ and the acclaimed ‘Business Continuity for Dummies’, in addition to numerous articles.

Colin will be discussing ISO22301 further on day two of the BCI World Conference and Exhibition on Thursday 6th November. You will find him in seminar room 2 starting at 13.10.