SlideShare a Scribd company logo
Presenter:
Ms Rinske Geerlings
MD, Founder and
Principal Consultant/
Trainer @ Business As
Usual
Risk Consultant of the
Year 2017 (RMIA)
Outstanding Security
Consultant of the Year
2019 (OSPAs Finalist)
Business Continuity Planning (BCP) – Virtual seminar
Using lessons learned from Covid-19 to
improve your future ‘business as usual’
Interactive session
Using lessons learned from Covid-19 to improve
your future ‘business as usual’
First question:
Who has been
capturing lessons
learned and
future
improvements,
whilst the
lockdown was
ongoing?
Using lessons learned to achieve an improved ‘business as usual’
1. Innovations
 Brainstorm with your team about new service
offerings and methods you could choose during
future disruptions (e.g. online, from different
location, using different production facilities
or supply chains)
 Review responses from your customers,
suppliers and other stakeholders to any new
products/methods you’ve developed since
COVID-19
 Identify potential improvements to productivity/efficiency, e.g. reduction in staff
travel, less need for specific office space, change in office layout, more automation,
different staff shifts, cheaper/better ways to outsource or (on the contrary) bring
activities in-house
Case studies
Question
“Which tools have you implemented to optimise your remote work
technology (e.g. network connectivity at home, device security, phone
diversion procedures, etc) and which can you retain to work more effectively
in your new ”business as usual?”
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a strategy to ensure staff comfort
and productivity during disruptions
 Make sure managers are available in case
staff need extra support
 Build stock and a fast roll-out process for
any tools that staff may need in order to
work during a disruption, e.g. two-way
radios, spare laptops, spare mobile handsets,
pre-loaded SIM cards, mobile internet modems, headsets, phone diversion
procedures, remote voice mail set-up instructions etc
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a template for centralised
communication via email/SMS/other tool,
in order to ensure all staff are headed in
the same direction during incidents
 Explore the best practices regarding holding
daily ‘huddles’ with staff during disruptions,
in case you are unable to all work from the
same location
 Discuss how these can be applied during business as usual
Question
“How are you staying
productive during a disruption,
if you are unable to sit
together with colleagues?
What are your key challenges
in this context?”
Using lessons learned to achieve an improved ‘business as usual’
3. External collaboration
 Identify which tools your suppliers,
clients and other counterparts preferred
during the lockdown (e.g. in the event of
Internet downtime, mobile network
outages or work from home situations)
 Implement and test related collaboration
tools and arrange for licensing,
installation and staff training so you are
ready to seamlessly keep sales/orders
and customer support going
Question
“If Internet and mobile telephony
were to go down for 1-2 days,
what does your BCP say?”
4. The actual transition to ‘the new normal’
 Move back by department, office/floor,
business process or technology used?
 Properly identify if return-to-work on certain
days of the week by certain staff actually
achieves the intended benefits (and doesn’t
complicate things)
 Ensure appropriate stages for facilities, HR
and IT to manage the transition including
proper testing
Using lessons learned to achieve an improved ‘business as usual’
Using lessons learned to improve your new ‘business as usual’
5. Better risk management
Revisit information sharing policies/controls in the event of a disruption, e.g.
 Secure network connectivity (incl WPS2 protection)
 Remote access software (e.g. VPN) including licences
 Patching of operating systems and ensure endpoint security (e.g. malware/virus
scanners)
 Provide regular reminders about information security to staff
 Conduct an ISO 27001 gap analysis
Revisit your Business Continuity Plan (BCP)
 Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain
disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT
system failure)
 Regularly walk-through/test your disruption scenarios
 Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and
regular ‘mini invocations’
 Less is more – Reduce document volume and make it easy to maintain
 Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and
gaming techniques including ‘red teaming’
 Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’
 Global best practice: For proper BCP as with DR, Risk Management and Security),
apply up-to-date principles/strategies (and standards!)
Making Business Continuity plans that actually work when you
need them most
• Philosophy of resilient networks
• What is different ?
• How do they work ?
• Why is it better than classic networks ?
• And all of your questions !
The topic of 2day
How to create resilience ?
We work in silos
BCP
How to create resilience ?
Multi silos in organisations
BCP
How to create resilience ?
Multi organisations in networks
BCP
BCP
BCP
BCP
BCP
BCP
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
What is resilience in this context ?
€ €
products/
services
products/
services
Take a simple chain
Examples of non resilience in chains:
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
‘Me, myself and I’ control =
the answer to all mishaps
8020
Increased risk at
customer level,
lower resilience
We need another direction !
Classic reaction to build resilience:
Risk
Costs
Quality
Profit
Statement:
The better you are, the
simpler the world, the
more resilient you are
energy,
costs,
risks
# learning cycles
complex
simple
Based on Resource Based View, Barney, 1991, and all later versions
New reaction to build resilience:
Add ‘expertise’ thinking:
Customer
100 % value
integrator
These networks are faster, cheaper, better (Q)
Based on Wouter Beelaerts, 2010
18 %
18 %
13 %
9 %
18 %
13 %
Profit = up
10 %
Resilience = up
Change the network for resilience:
utilise expertise
Next step: embrace dependency:
Resilient Customer
value
integrator
Resilience =
further up
Results in the integrator being a
resilience hub:
Resilient Supplier
value
goods & services
information & money
Remarkable results:
• speed to market: up
• total cost: down
• network profit: up
• network agility: up
• network resilience: up
Building the
resilient network
Conclusion:
classic networks F, C, B networks
embrace
dependency
Resilient
Customer
value
integrat
or
Resilient
Supplier
value
the resilient network
 Start talking about dependency with your network partners
 Add the outcome to your BCP !
Simple to start:
ISO 22301
Training Courses
• ISO 22301 Introduction
1 Day Course
• ISO 22301 Foundation
2 Days Course
• ISO 22301 Lead Implementer
5 Days Course
• ISO 22301 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
22301
www.pecb.com/events
THANK YOU
?
rinske@businessasusual.com.au
santema@scenter.nl
linkedin.com/in/businessasusual/
linkedin.com/in/siccosantema
www.businessasusual.com.au
www.scenter.nl

More Related Content

What's hot

Digital transformation
Digital transformationDigital transformation
Digital transformationScopernia
 
Successful KM Initiatives
Successful KM InitiativesSuccessful KM Initiatives
Successful KM InitiativesDavid Gurteen
 
Analytics in P&C Insurance
Analytics in P&C InsuranceAnalytics in P&C Insurance
Analytics in P&C InsuranceGregg Barrett
 
Managing in the digital world
Managing in the digital worldManaging in the digital world
Managing in the digital worldssuser99416c
 
Cisco Case Analysis
Cisco Case AnalysisCisco Case Analysis
Cisco Case Analysisperk2624
 
Deutsche Bank Survey Sees Blockchain Adoption in Six Years
Deutsche Bank Survey Sees Blockchain Adoption in Six YearsDeutsche Bank Survey Sees Blockchain Adoption in Six Years
Deutsche Bank Survey Sees Blockchain Adoption in Six YearsNicola Barozzi 🚘✔
 
Accenture Technology Vision 2012
Accenture Technology Vision 2012Accenture Technology Vision 2012
Accenture Technology Vision 2012Lars Kamp
 
Future Workforce: Reworking the Revolution
Future Workforce: Reworking the RevolutionFuture Workforce: Reworking the Revolution
Future Workforce: Reworking the RevolutionAccenture Insurance
 
Digital transformation sweet spot: Business operations
Digital transformation sweet spot: Business operationsDigital transformation sweet spot: Business operations
Digital transformation sweet spot: Business operationsMarcel Santilli
 
Case 9 the battle over net neutrality
Case 9 the battle over net neutralityCase 9 the battle over net neutrality
Case 9 the battle over net neutralityszarinammd
 
Operations Management - Process Technology
Operations Management - Process TechnologyOperations Management - Process Technology
Operations Management - Process TechnologyNelson Opeña
 
PESTEL Analysis: Middle East & South Asia
PESTEL Analysis: Middle East & South AsiaPESTEL Analysis: Middle East & South Asia
PESTEL Analysis: Middle East & South Asiaerifili benakopoulou
 
Understanding Digital transformation
Understanding Digital transformation Understanding Digital transformation
Understanding Digital transformation Patrizia Bertini
 
The Bionic Future - Future Work Summit
The Bionic Future - Future Work SummitThe Bionic Future - Future Work Summit
The Bionic Future - Future Work SummitMiguel Carrasco
 
Ten major global trends for 2030
Ten major global trends for 2030Ten major global trends for 2030
Ten major global trends for 2030Future Agenda
 

What's hot (20)

The Future of Work
The Future of WorkThe Future of Work
The Future of Work
 
Nice ventures
Nice venturesNice ventures
Nice ventures
 
Digital transformation
Digital transformationDigital transformation
Digital transformation
 
Successful KM Initiatives
Successful KM InitiativesSuccessful KM Initiatives
Successful KM Initiatives
 
Analytics in P&C Insurance
Analytics in P&C InsuranceAnalytics in P&C Insurance
Analytics in P&C Insurance
 
Managing in the digital world
Managing in the digital worldManaging in the digital world
Managing in the digital world
 
Cisco Case Analysis
Cisco Case AnalysisCisco Case Analysis
Cisco Case Analysis
 
McDonald's information systems
McDonald's information systemsMcDonald's information systems
McDonald's information systems
 
Deutsche Bank Survey Sees Blockchain Adoption in Six Years
Deutsche Bank Survey Sees Blockchain Adoption in Six YearsDeutsche Bank Survey Sees Blockchain Adoption in Six Years
Deutsche Bank Survey Sees Blockchain Adoption in Six Years
 
Accenture Technology Vision 2012
Accenture Technology Vision 2012Accenture Technology Vision 2012
Accenture Technology Vision 2012
 
Business Process Management
Business Process ManagementBusiness Process Management
Business Process Management
 
Future Workforce: Reworking the Revolution
Future Workforce: Reworking the RevolutionFuture Workforce: Reworking the Revolution
Future Workforce: Reworking the Revolution
 
Digital transformation sweet spot: Business operations
Digital transformation sweet spot: Business operationsDigital transformation sweet spot: Business operations
Digital transformation sweet spot: Business operations
 
Case 9 the battle over net neutrality
Case 9 the battle over net neutralityCase 9 the battle over net neutrality
Case 9 the battle over net neutrality
 
Operations Management - Process Technology
Operations Management - Process TechnologyOperations Management - Process Technology
Operations Management - Process Technology
 
PESTEL Analysis: Middle East & South Asia
PESTEL Analysis: Middle East & South AsiaPESTEL Analysis: Middle East & South Asia
PESTEL Analysis: Middle East & South Asia
 
Understanding Digital transformation
Understanding Digital transformation Understanding Digital transformation
Understanding Digital transformation
 
The Bionic Future - Future Work Summit
The Bionic Future - Future Work SummitThe Bionic Future - Future Work Summit
The Bionic Future - Future Work Summit
 
Case study 1
Case study 1Case study 1
Case study 1
 
Ten major global trends for 2030
Ten major global trends for 2030Ten major global trends for 2030
Ten major global trends for 2030
 

Similar to Moving to a New "Business as Usual" after COVID-19

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17jekroggel
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...360 BSI
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplacePaperjam_redaction
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Net at Work
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetAshley Deuble
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)AdaCore
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attranhcrowley
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations managementsmumbahelp
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profilescottsdale
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profilescottsdale
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 

Similar to Moving to a New "Business as Usual" after COVID-19 (20)

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17
 
Stabilizing Revenue
Stabilizing RevenueStabilizing Revenue
Stabilizing Revenue
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplace
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budget
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft Services
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attr
 
resume_alcantara
resume_alcantararesume_alcantara
resume_alcantara
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations management
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profile
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profile
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Recently uploaded

Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXMIRIAMSALINAS13
 
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...Sayali Powar
 
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptx
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptxJose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptx
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptxricssacare
 
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...Nguyen Thanh Tu Collection
 
Industrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training ReportIndustrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training ReportAvinash Rai
 
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdf
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdfINU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdf
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdfbu07226
 
Basic phrases for greeting and assisting costumers
Basic phrases for greeting and assisting costumersBasic phrases for greeting and assisting costumers
Basic phrases for greeting and assisting costumersPedroFerreira53928
 
Sectors of the Indian Economy - Class 10 Study Notes pdf
Sectors of the Indian Economy - Class 10 Study Notes pdfSectors of the Indian Economy - Class 10 Study Notes pdf
Sectors of the Indian Economy - Class 10 Study Notes pdfVivekanand Anglo Vedic Academy
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativePeter Windle
 
plant breeding methods in asexually or clonally propagated crops
plant breeding methods in asexually or clonally propagated cropsplant breeding methods in asexually or clonally propagated crops
plant breeding methods in asexually or clonally propagated cropsparmarsneha2
 
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptx
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptxSolid waste management & Types of Basic civil Engineering notes by DJ Sir.pptx
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptxDenish Jangid
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismDeeptiGupta154
 
Fish and Chips - have they had their chips
Fish and Chips - have they had their chipsFish and Chips - have they had their chips
Fish and Chips - have they had their chipsGeoBlogs
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationDelapenabediema
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxJisc
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaasiemaillard
 

Recently uploaded (20)

Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
 
Introduction to Quality Improvement Essentials
Introduction to Quality Improvement EssentialsIntroduction to Quality Improvement Essentials
Introduction to Quality Improvement Essentials
 
Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
 
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
 
NCERT Solutions Power Sharing Class 10 Notes pdf
NCERT Solutions Power Sharing Class 10 Notes pdfNCERT Solutions Power Sharing Class 10 Notes pdf
NCERT Solutions Power Sharing Class 10 Notes pdf
 
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptx
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptxJose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptx
Jose-Rizal-and-Philippine-Nationalism-National-Symbol-2.pptx
 
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
 
B.ed spl. HI pdusu exam paper-2023-24.pdf
B.ed spl. HI pdusu exam paper-2023-24.pdfB.ed spl. HI pdusu exam paper-2023-24.pdf
B.ed spl. HI pdusu exam paper-2023-24.pdf
 
Industrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training ReportIndustrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training Report
 
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdf
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdfINU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdf
INU_CAPSTONEDESIGN_비밀번호486_업로드용 발표자료.pdf
 
Basic phrases for greeting and assisting costumers
Basic phrases for greeting and assisting costumersBasic phrases for greeting and assisting costumers
Basic phrases for greeting and assisting costumers
 
Sectors of the Indian Economy - Class 10 Study Notes pdf
Sectors of the Indian Economy - Class 10 Study Notes pdfSectors of the Indian Economy - Class 10 Study Notes pdf
Sectors of the Indian Economy - Class 10 Study Notes pdf
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic Imperative
 
plant breeding methods in asexually or clonally propagated crops
plant breeding methods in asexually or clonally propagated cropsplant breeding methods in asexually or clonally propagated crops
plant breeding methods in asexually or clonally propagated crops
 
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptx
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptxSolid waste management & Types of Basic civil Engineering notes by DJ Sir.pptx
Solid waste management & Types of Basic civil Engineering notes by DJ Sir.pptx
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
 
Fish and Chips - have they had their chips
Fish and Chips - have they had their chipsFish and Chips - have they had their chips
Fish and Chips - have they had their chips
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptx
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
 

Moving to a New "Business as Usual" after COVID-19

  • 1.
  • 2. Presenter: Ms Rinske Geerlings MD, Founder and Principal Consultant/ Trainer @ Business As Usual Risk Consultant of the Year 2017 (RMIA) Outstanding Security Consultant of the Year 2019 (OSPAs Finalist) Business Continuity Planning (BCP) – Virtual seminar Using lessons learned from Covid-19 to improve your future ‘business as usual’ Interactive session
  • 3. Using lessons learned from Covid-19 to improve your future ‘business as usual’ First question: Who has been capturing lessons learned and future improvements, whilst the lockdown was ongoing?
  • 4. Using lessons learned to achieve an improved ‘business as usual’ 1. Innovations  Brainstorm with your team about new service offerings and methods you could choose during future disruptions (e.g. online, from different location, using different production facilities or supply chains)  Review responses from your customers, suppliers and other stakeholders to any new products/methods you’ve developed since COVID-19  Identify potential improvements to productivity/efficiency, e.g. reduction in staff travel, less need for specific office space, change in office layout, more automation, different staff shifts, cheaper/better ways to outsource or (on the contrary) bring activities in-house
  • 6. Question “Which tools have you implemented to optimise your remote work technology (e.g. network connectivity at home, device security, phone diversion procedures, etc) and which can you retain to work more effectively in your new ”business as usual?”
  • 7. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a strategy to ensure staff comfort and productivity during disruptions  Make sure managers are available in case staff need extra support  Build stock and a fast roll-out process for any tools that staff may need in order to work during a disruption, e.g. two-way radios, spare laptops, spare mobile handsets, pre-loaded SIM cards, mobile internet modems, headsets, phone diversion procedures, remote voice mail set-up instructions etc
  • 8. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a template for centralised communication via email/SMS/other tool, in order to ensure all staff are headed in the same direction during incidents  Explore the best practices regarding holding daily ‘huddles’ with staff during disruptions, in case you are unable to all work from the same location  Discuss how these can be applied during business as usual
  • 9. Question “How are you staying productive during a disruption, if you are unable to sit together with colleagues? What are your key challenges in this context?”
  • 10. Using lessons learned to achieve an improved ‘business as usual’ 3. External collaboration  Identify which tools your suppliers, clients and other counterparts preferred during the lockdown (e.g. in the event of Internet downtime, mobile network outages or work from home situations)  Implement and test related collaboration tools and arrange for licensing, installation and staff training so you are ready to seamlessly keep sales/orders and customer support going
  • 11. Question “If Internet and mobile telephony were to go down for 1-2 days, what does your BCP say?”
  • 12. 4. The actual transition to ‘the new normal’  Move back by department, office/floor, business process or technology used?  Properly identify if return-to-work on certain days of the week by certain staff actually achieves the intended benefits (and doesn’t complicate things)  Ensure appropriate stages for facilities, HR and IT to manage the transition including proper testing Using lessons learned to achieve an improved ‘business as usual’
  • 13. Using lessons learned to improve your new ‘business as usual’ 5. Better risk management Revisit information sharing policies/controls in the event of a disruption, e.g.  Secure network connectivity (incl WPS2 protection)  Remote access software (e.g. VPN) including licences  Patching of operating systems and ensure endpoint security (e.g. malware/virus scanners)  Provide regular reminders about information security to staff  Conduct an ISO 27001 gap analysis Revisit your Business Continuity Plan (BCP)  Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT system failure)  Regularly walk-through/test your disruption scenarios
  • 14.  Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and regular ‘mini invocations’  Less is more – Reduce document volume and make it easy to maintain  Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and gaming techniques including ‘red teaming’  Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’  Global best practice: For proper BCP as with DR, Risk Management and Security), apply up-to-date principles/strategies (and standards!) Making Business Continuity plans that actually work when you need them most
  • 15. • Philosophy of resilient networks • What is different ? • How do they work ? • Why is it better than classic networks ? • And all of your questions ! The topic of 2day
  • 16. How to create resilience ? We work in silos BCP
  • 17. How to create resilience ? Multi silos in organisations BCP
  • 18. How to create resilience ? Multi organisations in networks BCP BCP BCP BCP BCP BCP
  • 19. Customer 100 % value Suppliers 60 % value OEM 40 % value What is resilience in this context ? € € products/ services products/ services Take a simple chain
  • 20. Examples of non resilience in chains:
  • 21. Customer 100 % value Suppliers 60 % value OEM 40 % value ‘Me, myself and I’ control = the answer to all mishaps 8020 Increased risk at customer level, lower resilience We need another direction ! Classic reaction to build resilience:
  • 22. Risk Costs Quality Profit Statement: The better you are, the simpler the world, the more resilient you are energy, costs, risks # learning cycles complex simple Based on Resource Based View, Barney, 1991, and all later versions New reaction to build resilience: Add ‘expertise’ thinking:
  • 23. Customer 100 % value integrator These networks are faster, cheaper, better (Q) Based on Wouter Beelaerts, 2010 18 % 18 % 13 % 9 % 18 % 13 % Profit = up 10 % Resilience = up Change the network for resilience: utilise expertise
  • 24. Next step: embrace dependency:
  • 25. Resilient Customer value integrator Resilience = further up Results in the integrator being a resilience hub: Resilient Supplier value goods & services information & money Remarkable results: • speed to market: up • total cost: down • network profit: up • network agility: up • network resilience: up
  • 26. Building the resilient network Conclusion: classic networks F, C, B networks embrace dependency Resilient Customer value integrat or Resilient Supplier value the resilient network
  • 27.  Start talking about dependency with your network partners  Add the outcome to your BCP ! Simple to start:
  • 28. ISO 22301 Training Courses • ISO 22301 Introduction 1 Day Course • ISO 22301 Foundation 2 Days Course • ISO 22301 Lead Implementer 5 Days Course • ISO 22301 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 22301 www.pecb.com/events