A laypersons guide to business continuity management richard (2)


Published on

Published in: Business, Economy & Finance
1 Like
  • Be the first to comment

No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide
  • Is BCM concerned with disruption to: Markets? Finance? Operations? Staff? What does RTO stand for? Real Time Objectives Recover The Organisation Recovery Time Objectives Risking The Organisation
  • Without a tested BCM solution a disruption could affect the organisation’s: Viability Future Wellbeing Strategies
  • An example of an essential service is: Book-keeping Logistics Hiring Cash collection
  • A catastrophic event from a BCM perspective would be: Loss of access control Loss of communication system Lack of security Poor staff morale
  • A BCM solution will provide: Positive staff morale Back-ups Standby, configured computer infrastructure Restored confidence
  • A benefit of implementing BCM would be all of the following except: Preservation of reputation Recovery of critical systems Preservation of records Contact with customers and suppliers
  • A disruptive event could be: Absent staff A flood Parking congestion Inclement weather
  • A very likely cause of a disaster is: Storm damage A tsunami A stock market crash Failure of computer systems
  • Following a disaster, what could you be faced with: Embarrassment No paperwork Broken furniture A huge clean-up
  • BusinessAssist provides subscribers with: Business advice Business finance A marketing plan A continuity plan
  • What does BIA stand for? Business Impact Assessment Business Interruption Assessment Business Interruption Analysis Business Impact Analysis
  • What is the predominant purpose of a Risk Assessment? Identifying what is mission critical Identify the most likely risks and their likelihood To determine how frequent a risk may occur To measure the risk with the biggest impact
  • Mission critical activities are usually linked to: A functional canteen Corporate integrity Revenues Board meetings
  • What would have the biggest impact on a business? A fire that took out the administration building but had no impact on mission critical services A power outage on all functions for two hours Inability to answer the phones for over a week Mission critical services totally disrupted for over 3 days at peak season
  • What level of risk will threaten a business the most? Negligible likelihood but catastrophic impact Moderate impact and possible likelihood Probable risk but minor impact Significant impact and possible likelihood
  • Your BCM solution is low cost because: The insurance industry will cover me My risk profile will diminish My risk profile will increase My bank will lend me more money
  • BusinessAssist does not: Switch my incoming telephones Allow me to backup my key data Mean I should not test my recovery plan Provide me with an emergency recovery office
  • A key part of the BCM Process is to: Document risks Classify and mitigate risks Delegate risks Escalate risks
  • BCM is widely regarded as: a) The right thing to do b) A nice to have c) Pricey d) Good corporate governance
  • In a crisis, why will your company attract external scrutiny? So that the public can ridicule you Because they will be concerned about your ability to recover Because lawyers will be on standby Because liquidators will be on standby
  • In a crisis it is best to: Say “no comment” Withdraw Play down the situation Be proactive
  • In a crisis it is best to: Say “no comment” Withdraw Play down the situation Be proactive
  • Testing is critical to BCM because: It must be performed monthly It requires a budget So many people must be involved To ensure that it works
  • A stakeholder could be all of the following except: The shareholders The environment Society at large The articles of association
  • Disaster recovery traditionally referred to the restoration of: The call centre Payroll Public confidence IT
  • A laypersons guide to business continuity management richard (2)

    1. 1. An introduction to: Business Continuity Management
    2. 2. Definition <ul><li>BCM is the strategic and tactical capability of the organisation to plan for, and respond to, incidents and business disruptions in order to continue business operations at an acceptable, pre-defined level. </li></ul>
    3. 3. What is Business Continuity Management ? (BCM) <ul><ul><li>BCM substantially improves the chances of business survival following a major disruption to critical operations by identifying mission critical activities (and prioritising their recovery) prior to an unforeseen event. </li></ul></ul><ul><ul><li>It identifies the tolerance to interruption of business processes that must be recovered and predetermines therefore the required recovery time frames (known as RTO – Recovery Time Objectives). </li></ul></ul><ul><li>In summary, the BCM process generates practical recovery strategies and continuity plans which, once tested, renders the organisation resilient to disastrous events by ensuring that the organisation can continue to supply critical products and services during adverse operating conditions. </li></ul>
    4. 4. The Importance of BCM <ul><li>In the absence of a tested and viable BCM programme, a major operational disruption could threaten the survival of your business. </li></ul><ul><li>A major unforeseen interruption could render you incapable of continuing mission critical functions which support your key business objectives. </li></ul><ul><li>Insurance policies do not keep your business running. They may pay for damage caused but they do not answer your phones, communicate with your clients and satisfy your stakeholders. </li></ul>
    5. 5. Mission critical and essential services <ul><li>These are example activities which are critical to the sustainability of a typical business: </li></ul><ul><li>Cash collection </li></ul><ul><li>Communication with staff, suppliers and clients </li></ul><ul><li>Meeting service level agreements </li></ul><ul><li>Meeting deadlines such as payrol and customer orders </li></ul><ul><li>Complying with statutory responsibilities </li></ul><ul><li>Meeting banking covenants </li></ul>
    6. 6. The value of BCM <ul><ul><li>On experiencing a major disaster or catastrophic event, a well-tested BCM plan can: </li></ul></ul><ul><ul><ul><li>Prevent a loss of market share </li></ul></ul></ul><ul><ul><ul><li>Enhance your reputation </li></ul></ul></ul><ul><ul><ul><li>Impress your clients </li></ul></ul></ul><ul><ul><ul><li>Improve staff retention </li></ul></ul></ul><ul><ul><ul><li>Improve your insurance ratings </li></ul></ul></ul><ul><ul><ul><li>Keep your business alive </li></ul></ul></ul>
    7. 7. What a BCM plan should provide <ul><li>A well-considered plan that can be tested </li></ul><ul><li>Alternative office accommodation </li></ul><ul><ul><li>Redirected telephone numbers </li></ul></ul><ul><ul><li>A calm environment from which you can effect a controlled recovery </li></ul></ul><ul><ul><li>A solid crisis management and communications plan </li></ul></ul><ul><ul><li>Standby, configured computer infrastructure </li></ul></ul><ul><ul><li>Restored data from previously taken back-ups </li></ul></ul>
    8. 8. The key benefits to BCM <ul><li>Survival </li></ul><ul><li>80% of companies that do not have a viable business continuity plan and suffer a disaster, go out of business within just 18 months of that disaster. </li></ul>
    9. 9. What is a Disruptive Event? Some of these are perhaps obvious but, have you considered what would happen if there was a gas leak in the street and the police prevented access to your building? What if your communications lines were cut off for a week – how would you cope?
    10. 10. The most likely causes of interruption <ul><li>2010 statistics (Global Continuity) </li></ul><ul><ul><li>Hardware failure </li></ul></ul><ul><ul><li>Power failure </li></ul></ul><ul><ul><li>Communications failure </li></ul></ul><ul><ul><li>Data corruption </li></ul></ul><ul><ul><li>Access denial </li></ul></ul><ul><ul><li>Fire </li></ul></ul><ul><ul><li>Natural disaster (regionally dependent) </li></ul></ul>
    11. 11. The potential physical consequences of a catastrophic event <ul><li>No office accommodation </li></ul><ul><li>No switchboard </li></ul><ul><li>No network </li></ul><ul><li>No ability to communicate </li></ul><ul><li>Lost records, no data </li></ul><ul><li>No computer access </li></ul><ul><li>No manufacturing ability </li></ul>
    12. 12. The benefits of BusinessAssist <ul><li>BusinessAssist provides your Company with: </li></ul><ul><ul><li>A nearby Emergency Recovery Office (ERO) with a fully fitted office infrastructure . </li></ul></ul><ul><ul><li>Your existing incoming telephone lines switched to the ERO. </li></ul></ul><ul><ul><li>A recovery strategy </li></ul></ul><ul><ul><li>A business continuity plan </li></ul></ul><ul><ul><li>The ability to test the functionality of your plan </li></ul></ul><ul><ul><li>An invocation procedure </li></ul></ul><ul><ul><li>Technical support in a crisis </li></ul></ul>
    13. 13. The key elements to a BCM plan (1) <ul><li>Business Impact Analysis </li></ul><ul><ul><li>Assess : </li></ul></ul><ul><ul><ul><li>What are your mission critical activities? </li></ul></ul></ul><ul><ul><ul><li>What would happen if you lost them (the impact of loss)? </li></ul></ul></ul><ul><ul><ul><li>How long could you afford to be without them? </li></ul></ul></ul><ul><ul><ul><li>What are impacts of loss: </li></ul></ul></ul><ul><ul><ul><ul><li>Financial? </li></ul></ul></ul></ul><ul><ul><ul><ul><li>Reputation? </li></ul></ul></ul></ul><ul><ul><ul><ul><li>Market share? </li></ul></ul></ul></ul><ul><ul><ul><ul><li>Missed deadlines? </li></ul></ul></ul></ul><ul><ul><ul><li>Are their times (cycles) when mission critical activities are more or less important i.e. end of the month, financial reporting periods etc.? </li></ul></ul></ul>
    14. 14. The key elements to a BCM plan (2) <ul><li>Risk Analysis </li></ul><ul><ul><li>Assess : </li></ul></ul><ul><ul><ul><li>What risks exist that could affect the mission critical services? </li></ul></ul></ul><ul><ul><ul><li>What is the likelihood of those risks happening? </li></ul></ul></ul><ul><ul><ul><li>Consider: </li></ul></ul></ul><ul><ul><ul><ul><li>Environmental risks e.g. flood plains, neighbourhood activity e.g. Chemical plants, gas storage etc. </li></ul></ul></ul></ul><ul><ul><ul><ul><li>Seasonal risks e.g. weather </li></ul></ul></ul></ul><ul><ul><ul><ul><li>Proximity terrorist targets </li></ul></ul></ul></ul>
    15. 15. What are Mission Critical activities? <ul><li>It changes from business to business and even the time of the year and commercial cycle of the business. </li></ul><ul><li>It is usually linked to: </li></ul><ul><ul><li>Revenue flows (debtors / creditors) </li></ul></ul><ul><ul><li>Banking </li></ul></ul><ul><ul><li>Payroll </li></ul></ul><ul><li>or: Legal or regulatory obligations </li></ul><ul><li>and: Reputation / brand / public image </li></ul><ul><li>Essentially it is any activity that is the core to the success of the business. </li></ul>
    16. 16. Impact and Risk Assessment
    17. 17. The key elements to a BCM plan (3) <ul><li>Risk assessments are produced by combining the assessed likelihood and impact scores of a hazard or threat by plotting them on a risk matrix. </li></ul><ul><li>High likelihood and high impact risks are your essential priority. </li></ul><ul><li>Low impact and low risk may be ignored (if your assessment process allows it). </li></ul><ul><li>Imagine a risk and plot it on the chart that follows. </li></ul>
    18. 18. Impact vs Likelihood
    19. 19. The costs associated with producing a BCM plan <ul><li>Plans cost time to create. </li></ul><ul><li>They cost time to keep maintained and current (they must be reviewed regularly). </li></ul><ul><li>You may have to invest in data backup systems albeit BusinessAssist cares for your critical documents (for free). </li></ul><ul><li>There will be a cost of ownership – somebody in your company must be responsible for the plan. </li></ul><ul><li>It does require a budget however, if BCM is considered as an element of any key project at inception, then it will be cheaper to implement. </li></ul>
    20. 20. BusinessAssist (detail and recap) <ul><li>Guarantees the next working day availability of an Emergency Recovery Office (ERO), near you. </li></ul><ul><li>The switching of your main incoming telephone lines to your ERO in time for your arrival. </li></ul><ul><li>This training module and an online assessment of your BCM knowledge. </li></ul><ul><li>An automated continuity planning tool. </li></ul><ul><li>The storage (and online retrieval) of your key documents and your key contacts. </li></ul><ul><li>Crisis management support in a disaster (just call your hotline number). </li></ul><ul><li>Evidence to a compliance officer, insurer or bank that you have a viable BCM plan. </li></ul><ul><li>To invoke your BusinessAssist Contract call - 0800 334 5738 </li></ul>
    21. 21. The BCM process (recap) <ul><li>Identify your mission critical activities and conduct a Business Impact Analysis (BIA). </li></ul><ul><li>Determine the exposure to risk and interruption. </li></ul><ul><li>Mitigate risks (where possible). </li></ul><ul><li>Decide what activities must be recovered. </li></ul><ul><li>Determine the Recovery Time Objectives (RTO). </li></ul><ul><li>Complete the BusinessAssist continuity plan template. </li></ul>
    22. 22. The subtle importance of BCM <ul><li>Statistics prove you will have an interruption of some sort. </li></ul><ul><li>Evidence shows that in a major disaster, your share price can increase if the market thinks you were well prepared. </li></ul><ul><li>You have no control of your neighbours and their activities. Their actions could interrupt your business. </li></ul><ul><li>It is sound business practice and will help you stay ahead of your competitors. </li></ul><ul><li>It gives your staff confidence that you care. </li></ul><ul><li>It is good governance and will impress your stakeholders. </li></ul><ul><li>In some industries legislation demands it. </li></ul><ul><li>It can make you more able to take advantage of your competitors if they are also in crisis. </li></ul>
    23. 23. Crisis Management <ul><li>A key element to a sound BCM strategy. </li></ul><ul><li>It ‘defines’ your reputation during a crisis. </li></ul><ul><li>Ensures the effective and efficient recovery, in a controlled environment, of your business. </li></ul><ul><li>Ensures good press relations. </li></ul><ul><li>Is the calming effect on your crisis. </li></ul><ul><li>Is the controlled recovery of all that has been lost. </li></ul><ul><li>Is evidence to your stakeholders that you are in control. </li></ul>
    24. 24. Crisis Management in action <ul><li>Early in the crisis: </li></ul><ul><li>Identify affected stakeholder groups. </li></ul><ul><li>Engage relevant groups (inc. Staff): </li></ul><ul><ul><li>Quickly, be proactive </li></ul></ul><ul><ul><li>Acknowledge the situation </li></ul></ul><ul><ul><li>Communicate regularly (even if there is little to say) </li></ul></ul><ul><ul><li>Reassure that a tested recovery plan is in place </li></ul></ul><ul><ul><li>Maintain confidence (back to normal within 24 hours) </li></ul></ul><ul><ul><li>Tell the truth </li></ul></ul><ul><ul><li>Never attempt to bluff your stakeholders </li></ul></ul><ul><ul><li>Always be available </li></ul></ul>
    25. 25. Role of the Crisis Manager <ul><li>Diagnose the impending trouble or danger signals. </li></ul><ul><li>Choose appropriate turnaround strategy. </li></ul><ul><li>Build an environment of trust and calm. </li></ul><ul><li>Divert the organisations mind set from shock and fear to action and remedy. </li></ul><ul><li>Identify obvious and obscure vulnerability of the organisation. </li></ul><ul><li>Make wise and rapid decisions. </li></ul>
    26. 26. BCM plan viability <ul><li>The plan will fail if it is written and then left ignored. </li></ul><ul><li>Regularly update the plan and ensure key contact details of staff, customers etc. are current. </li></ul><ul><li>Regularly check that the data (files) you have backed up can be restored. </li></ul><ul><li>Regularly update the answers you gave when you first activated your BusinessAssist service. </li></ul><ul><li>‘ Exercise’ the plans regularly. </li></ul><ul><li>Make sure BCM is a Board agenda item. </li></ul>
    27. 27. Frequently asked questions <ul><li>Is supply chain management a component of BCM? A: Yes. If you lost a key supplier and have no contingency plan, you could be compromised. Have you asked your supplier if they have a BCM plan? Have you seen it? </li></ul><ul><li>Is BCM Enterprise Risk Management? A: No. It is more aligned to operational and reputational risk. </li></ul><ul><li>Is there legislation that insists my company must have a BCM plan? A: it depends which industry you are in. Financial services companies must have a viable plan as must solicitor practices. Check with your industry forums. </li></ul><ul><li>Is my bank a stakeholder in my business? A: Yes if you borrow from them or depend on them in any way. Stakeholders are entities that have an influence on (or are influenced by) your company. </li></ul>
    28. 28. Disaster Recovery and BCM <ul><li>Disaster recovery is an element of BCM and focuses on post disaster activity. BCM prevents as well as cures. </li></ul><ul><li>Business needs to focus on the recovery of critical business processes. </li></ul><ul><li>Businesses invariably have a critical dependency on IT. Recovery of IT infrastructure accordingly remains crucial to the recovery of operations and is the origin of most externally available disaster recovery services. </li></ul><ul><li>BusinessAssist includes an emergency recovery office (this is disaster recovery). </li></ul>
    29. 29. That concludes the training on Business Continuity Management. Thank you. Now complete the online Continuity Management Test which will then automatically produce a Business Continuity Plan for you.