SlideShare a Scribd company logo
1 of 9
Download to read offline
Information
Protection &
Business Resilience
Business Continuity
Management (BCM)
Overview Information
2013
Services Overview
Integrating Resilience and Efficiency
1© 2015 Resus Advisory. All rights reserved.
Need for Resilience
We know that in today’s world of uncertainty, the resilience of business operations during events that
impact “business as usual” is more critical than ever.
A disruption to services can occur from various internal and external threats, that are often beyond our
control, including terrorism, the supply chain and environment.
However, it is how we prepare for and respond towards those threats that develops organisational resilience,
allowing for continued value to customers, even during times of disruption. Customers expect it, and the
value they place on it is evident below.
2© 2015 Resus Advisory. All rights reserved.
Client services offered
Tailored and integrated consulting and training solutions, including:
• Enterprise Risk Management
• Business Continuity, Emergency Management,
Crisis Management and ICT Resilience
• Knowledge Management, Process Mapping and Improvement
• Information Security and Privacy Compliance
Resus Advisory is a proudly South African company
and a Licensed BCI Training Partner
3© 2015 Resus Advisory. All rights reserved.
Resilience services overview
• BCM maturity reviews (against leading ISO22301 & BCI GPG standards and practical experience)
• IT DR (continuity) reviews
• Supply chain resilience and 3rd party BCM reviews
• Full BCM Lifecycle implementation projects, or specific elements including:
• BCM programme maintenance outsourcing
• Crisis co-ordination support
• Onsite coaching for BCM / Risk staff skills transfer
• BCM training (BCI official certification training and tailored practical training as required)
• Integrating risk and other functions to support organisational resilience by embedding and aligning
responsibilities. Including Governance, Risk and Compliance functions, IT Security and Privacy, OH&S,
Process Management, Insurance and Internal Audit
BCI GPG 2013: BCM Lifecycle
AuditAdvisory
Training
4© 2015 Resus Advisory. All rights reserved.
Specialising in Business Continuity Management
What is Business Continuity Management (BCM)?
An enterprise-wide management process that identifies potential impacts that threaten an organisation and provides
a framework for building resilience and the capability for an effective response that safeguards the interests of its key
stakeholders, reputation, brand and value-creating activities.
BCM Elements include:
BUSINESSICT
RESPONSE TIMELINE
Ability to prioritise critical processes
and recovery requirements to continue
operations for key business functions
BUSINESS RECOVERY
Ability to direct response teams and
recovery actions, communications to
internal / external stakeholders
CRISIS MANAGEMENT
Ability to respond to a physical incident
safeguarding people and infrastructure,
interacting with emergency services
EMERGENCY RESPONSE
Ability to restore the IT systems, data
and communications infrastructure to
support business continuity
ICT RECOVERY
INCIDENT
5© 2015 Resus Advisory. All rights reserved.
Specialising in Business Continuity Management
Why is BCM important?
King III Risk Management,
Principle 5
Management should regularly
demonstrate to the board that
the company has adequate
business resilience
arrangements in place for
disaster recovery.
Disaster Management Act
(57 of 2002)
Provides for a co-ordinated
and prepared response to
disasters and post-disaster
recovery.
Pro-active and re-active crisis response capabilities
Reduce
impact
Accelerate
Recovery
Incident
Prevention
Response
Recovery
Service
Level
Time
100%
(Business
as usual)
Resilient Non-resilient
6© 2015 Resus Advisory. All rights reserved.
BCM system services include
BCM policy and related policies to support BCM and risk management activities within the organisation:
• Governance and policy frameworks
• The development of BCM programme schedules
• BCM response structures
• Required roles and responsibilities
• Interaction with other business areas and disciplines
Business Impact Analysis (BIA) workshop facilitation:
• Identify critical business activities, assets and processes within the organisation
• Define risk rating scales used to determine the impact (tangible and intangible) an interruption would have upon
critical business operations, including financial, legal / regulatory and stakeholder reputational impacts
• Identify key resources required to carry out critical business processes
• Identify support requirements in terms of operating equipment, IT systems / applications and personnel that support
the critical business processes of the organisation
• Identify manual or alternative procedures (work-arounds)
• Identifying key suppliers / vendors, customers, internal dependencies and external third parties which support
business operations
• BIA reporting and analysis of resource requirements information
Threat Assessment explores single points of failure and resilience related risk areas:
• IT and telecommunications
• Physical security, Operational health and safety
• Data privacy and security
• Supply Chain Management
• Succession planning
• Insurance and financial risks
• Knowledge and business processes management
7© 2015 Resus Advisory. All rights reserved.
BCM system services include (cont.)
Recovery Strategies that meet the resource requirements identified during the BIA and address key risks
identified in the Threat Assessment to address interruptions to various elements:
• Infrastructure and office premises
• Information and communication technology (ICT)
• Critical information and documents
• Supply chain and vendors
• Staff and key people dependencies
• Cost/Benefit analyses for various recovery and risk mitigation strategies
Business Continuity Plan development documents the executable strategies:
• Emergency response plans to safeguard people and infrastructure
• Business recovery plans to resume critical operations
• ICT recovery plans to restore IT and communications services
• Crisis management for executive direction and coordination
• Communications plans to conduct internal and external communications
• Scenario plans to address specific response strategies for various threats (i.e. Pandemic plan)
Testing and exercising is critical to validating a proven capability:
• Defining testing outcomes and roadmap to improving BCM maturity through testing
• Conducting the test and exercising
• Post-test reporting and follow up actions
Awareness initiatives to promote BCM knowledge throughout the organisation, practical awareness
campaign options suitable for improving and embedding BCM within each unique environment:
• Training requirements
• BCM awareness campaigns
• BCM maintenance and improvement
• Stakeholder reporting
8© 2015 Resus Advisory. All rights reserved.
Overview of the KPMG BCM Lifecycle and Services Offered
to discuss requirements and solutions
David Bollaert (MBCI, CISA, BBusSc)
Organisational Resilience Director
E david@resusadvisory.co.za
T +27 (0)82 998 8666
www.resusadvisory.co.za
Contact us

More Related Content

What's hot

Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...BCM Institute
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management systemsubbusai82
 
FM Facility Maintenance - Management for Multi-Site Locations
FM Facility Maintenance - Management for Multi-Site Locations FM Facility Maintenance - Management for Multi-Site Locations
FM Facility Maintenance - Management for Multi-Site Locations Matthias Wholley
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planningSandeep Kashyap
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.inSatya Yadav
 
what is Business Continuity Management System?
what is Business Continuity Management System?what is Business Continuity Management System?
what is Business Continuity Management System?Ascent World
 
BCM For Outsourced Vendors
BCM For Outsourced VendorsBCM For Outsourced Vendors
BCM For Outsourced Vendorspmbs
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiwNaresh Rao
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT Continuity and Resilience
 
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’sBest-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’sMissionMode
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewAhmed Riad .
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301mascot4u
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014Paul Simidi
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationPECB
 
Management of Risk and its integration within ITIL
Management of Risk and its integration within ITILManagement of Risk and its integration within ITIL
Management of Risk and its integration within ITILhdoornbos
 
Ten Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRCTen Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRCBill Graham CP.APMP
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectContinuity and Resilience
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIABCM Institute
 

What's hot (20)

Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
FM Facility Maintenance - Management for Multi-Site Locations
FM Facility Maintenance - Management for Multi-Site Locations FM Facility Maintenance - Management for Multi-Site Locations
FM Facility Maintenance - Management for Multi-Site Locations
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.in
 
SAMA BCM Framework
SAMA BCM Framework SAMA BCM Framework
SAMA BCM Framework
 
what is Business Continuity Management System?
what is Business Continuity Management System?what is Business Continuity Management System?
what is Business Continuity Management System?
 
BCM For Outsourced Vendors
BCM For Outsourced VendorsBCM For Outsourced Vendors
BCM For Outsourced Vendors
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiw
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
 
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’sBest-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
 
Bcp drp
Bcp drpBcp drp
Bcp drp
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
 
Management of Risk and its integration within ITIL
Management of Risk and its integration within ITILManagement of Risk and its integration within ITIL
Management of Risk and its integration within ITIL
 
Ten Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRCTen Slides in Ten Minutes - Company Realities - GRC
Ten Slides in Ten Minutes - Company Realities - GRC
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR Project
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 

Viewers also liked

Sistemas Operativos
Sistemas OperativosSistemas Operativos
Sistemas OperativosJosé Macedo
 
Analysis of different types of thriller films.
Analysis of different types of thriller films. Analysis of different types of thriller films.
Analysis of different types of thriller films. 123sunbul
 
Google world newest
Google world newestGoogle world newest
Google world newestsammevanss
 
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...BCM Institute
 
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...Willem A. Hoekstra Business Continuity Management in Banking Industry World C...
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...BCM Institute
 
A business continuity challenge - Joseph Thomas
A business continuity challenge - Joseph ThomasA business continuity challenge - Joseph Thomas
A business continuity challenge - Joseph ThomasBCM Institute
 
Filming issues 2
Filming issues 2Filming issues 2
Filming issues 2123sunbul
 
Pwc 19th Annual Global CEO Survey
Pwc 19th Annual Global CEO SurveyPwc 19th Annual Global CEO Survey
Pwc 19th Annual Global CEO SurveyPwC
 
How the animation was done
How the animation was doneHow the animation was done
How the animation was done123sunbul
 
Evidence of radio trailer
Evidence of radio trailer Evidence of radio trailer
Evidence of radio trailer 123sunbul
 

Viewers also liked (15)

Spm
SpmSpm
Spm
 
Sistemas Operativos
Sistemas OperativosSistemas Operativos
Sistemas Operativos
 
Analysis of different types of thriller films.
Analysis of different types of thriller films. Analysis of different types of thriller films.
Analysis of different types of thriller films.
 
Google world newest
Google world newestGoogle world newest
Google world newest
 
BCM revised
BCM revisedBCM revised
BCM revised
 
Costumes
Costumes Costumes
Costumes
 
Resume othman sulaiman
Resume othman sulaimanResume othman sulaiman
Resume othman sulaiman
 
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...
BCM Institute MTE Dr Goh Moh Heng - Threats and Trends in Business Continuity...
 
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...Willem A. Hoekstra Business Continuity Management in Banking Industry World C...
Willem A. Hoekstra Business Continuity Management in Banking Industry World C...
 
A business continuity challenge - Joseph Thomas
A business continuity challenge - Joseph ThomasA business continuity challenge - Joseph Thomas
A business continuity challenge - Joseph Thomas
 
Deloitte Business Continuity Management
Deloitte Business Continuity ManagementDeloitte Business Continuity Management
Deloitte Business Continuity Management
 
Filming issues 2
Filming issues 2Filming issues 2
Filming issues 2
 
Pwc 19th Annual Global CEO Survey
Pwc 19th Annual Global CEO SurveyPwc 19th Annual Global CEO Survey
Pwc 19th Annual Global CEO Survey
 
How the animation was done
How the animation was doneHow the animation was done
How the animation was done
 
Evidence of radio trailer
Evidence of radio trailer Evidence of radio trailer
Evidence of radio trailer
 

Similar to Resus Advisory Profile - Resilience services Nov 15

Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...360 BSI
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a CareerBonnie Canal
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guideAstalapulosListestos
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guideCenapSerdarolu
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectCORE Consulting
 
IT Outsourcing Risks In Financial Sector
IT Outsourcing Risks In Financial SectorIT Outsourcing Risks In Financial Sector
IT Outsourcing Risks In Financial SectorUKNGroupLtd
 
Healthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPHealthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPMohammed Al Ayoubi
 
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...360 BSI
 
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...360 BSI
 
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...360 BSI
 
IT Risk assessment and Audit Planning
IT Risk assessment and Audit PlanningIT Risk assessment and Audit Planning
IT Risk assessment and Audit Planninggoreankush1
 
Managing Service Operations and why ITSM Matters
Managing Service Operations and why ITSM Matters Managing Service Operations and why ITSM Matters
Managing Service Operations and why ITSM Matters Invensis Learning
 
Axis Technology - Consulting Overview
Axis Technology - Consulting OverviewAxis Technology - Consulting Overview
Axis Technology - Consulting OverviewAxis Technology, LLC
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyNICSA
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationWilliam McBorrough
 

Similar to Resus Advisory Profile - Resilience services Nov 15 (20)

Qatar Proposal
Qatar ProposalQatar Proposal
Qatar Proposal
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
 
BiznetGio Presentation Business Continuity
BiznetGio Presentation Business ContinuityBiznetGio Presentation Business Continuity
BiznetGio Presentation Business Continuity
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a Career
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guide
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guide
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR project
 
IT Outsourcing Risks In Financial Sector
IT Outsourcing Risks In Financial SectorIT Outsourcing Risks In Financial Sector
IT Outsourcing Risks In Financial Sector
 
Healthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPHealthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCP
 
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...
Business Continuity & Disaster Recovery Planning, 23 - 25 February 2016 Kuala...
 
Understanding co bit 4.1
Understanding co bit 4.1Understanding co bit 4.1
Understanding co bit 4.1
 
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...
Business Continuity & Disaster Recovery Planning, 30 November - 02 December 2...
 
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...
Business Continuity & Disaster Recovery Planning 02 - 04 December 2013 Kuala ...
 
IT Risk assessment and Audit Planning
IT Risk assessment and Audit PlanningIT Risk assessment and Audit Planning
IT Risk assessment and Audit Planning
 
Chris Gould - BCM case
Chris Gould - BCM caseChris Gould - BCM case
Chris Gould - BCM case
 
Managing Service Operations and why ITSM Matters
Managing Service Operations and why ITSM Matters Managing Service Operations and why ITSM Matters
Managing Service Operations and why ITSM Matters
 
Axis Technology - Consulting Overview
Axis Technology - Consulting OverviewAxis Technology - Consulting Overview
Axis Technology - Consulting Overview
 
Risk - IT Services
Risk - IT ServicesRisk - IT Services
Risk - IT Services
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a Strategy
 
MCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service Presentation
 

Resus Advisory Profile - Resilience services Nov 15

  • 1. Information Protection & Business Resilience Business Continuity Management (BCM) Overview Information 2013 Services Overview Integrating Resilience and Efficiency
  • 2. 1© 2015 Resus Advisory. All rights reserved. Need for Resilience We know that in today’s world of uncertainty, the resilience of business operations during events that impact “business as usual” is more critical than ever. A disruption to services can occur from various internal and external threats, that are often beyond our control, including terrorism, the supply chain and environment. However, it is how we prepare for and respond towards those threats that develops organisational resilience, allowing for continued value to customers, even during times of disruption. Customers expect it, and the value they place on it is evident below.
  • 3. 2© 2015 Resus Advisory. All rights reserved. Client services offered Tailored and integrated consulting and training solutions, including: • Enterprise Risk Management • Business Continuity, Emergency Management, Crisis Management and ICT Resilience • Knowledge Management, Process Mapping and Improvement • Information Security and Privacy Compliance Resus Advisory is a proudly South African company and a Licensed BCI Training Partner
  • 4. 3© 2015 Resus Advisory. All rights reserved. Resilience services overview • BCM maturity reviews (against leading ISO22301 & BCI GPG standards and practical experience) • IT DR (continuity) reviews • Supply chain resilience and 3rd party BCM reviews • Full BCM Lifecycle implementation projects, or specific elements including: • BCM programme maintenance outsourcing • Crisis co-ordination support • Onsite coaching for BCM / Risk staff skills transfer • BCM training (BCI official certification training and tailored practical training as required) • Integrating risk and other functions to support organisational resilience by embedding and aligning responsibilities. Including Governance, Risk and Compliance functions, IT Security and Privacy, OH&S, Process Management, Insurance and Internal Audit BCI GPG 2013: BCM Lifecycle AuditAdvisory Training
  • 5. 4© 2015 Resus Advisory. All rights reserved. Specialising in Business Continuity Management What is Business Continuity Management (BCM)? An enterprise-wide management process that identifies potential impacts that threaten an organisation and provides a framework for building resilience and the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value-creating activities. BCM Elements include: BUSINESSICT RESPONSE TIMELINE Ability to prioritise critical processes and recovery requirements to continue operations for key business functions BUSINESS RECOVERY Ability to direct response teams and recovery actions, communications to internal / external stakeholders CRISIS MANAGEMENT Ability to respond to a physical incident safeguarding people and infrastructure, interacting with emergency services EMERGENCY RESPONSE Ability to restore the IT systems, data and communications infrastructure to support business continuity ICT RECOVERY INCIDENT
  • 6. 5© 2015 Resus Advisory. All rights reserved. Specialising in Business Continuity Management Why is BCM important? King III Risk Management, Principle 5 Management should regularly demonstrate to the board that the company has adequate business resilience arrangements in place for disaster recovery. Disaster Management Act (57 of 2002) Provides for a co-ordinated and prepared response to disasters and post-disaster recovery. Pro-active and re-active crisis response capabilities Reduce impact Accelerate Recovery Incident Prevention Response Recovery Service Level Time 100% (Business as usual) Resilient Non-resilient
  • 7. 6© 2015 Resus Advisory. All rights reserved. BCM system services include BCM policy and related policies to support BCM and risk management activities within the organisation: • Governance and policy frameworks • The development of BCM programme schedules • BCM response structures • Required roles and responsibilities • Interaction with other business areas and disciplines Business Impact Analysis (BIA) workshop facilitation: • Identify critical business activities, assets and processes within the organisation • Define risk rating scales used to determine the impact (tangible and intangible) an interruption would have upon critical business operations, including financial, legal / regulatory and stakeholder reputational impacts • Identify key resources required to carry out critical business processes • Identify support requirements in terms of operating equipment, IT systems / applications and personnel that support the critical business processes of the organisation • Identify manual or alternative procedures (work-arounds) • Identifying key suppliers / vendors, customers, internal dependencies and external third parties which support business operations • BIA reporting and analysis of resource requirements information Threat Assessment explores single points of failure and resilience related risk areas: • IT and telecommunications • Physical security, Operational health and safety • Data privacy and security • Supply Chain Management • Succession planning • Insurance and financial risks • Knowledge and business processes management
  • 8. 7© 2015 Resus Advisory. All rights reserved. BCM system services include (cont.) Recovery Strategies that meet the resource requirements identified during the BIA and address key risks identified in the Threat Assessment to address interruptions to various elements: • Infrastructure and office premises • Information and communication technology (ICT) • Critical information and documents • Supply chain and vendors • Staff and key people dependencies • Cost/Benefit analyses for various recovery and risk mitigation strategies Business Continuity Plan development documents the executable strategies: • Emergency response plans to safeguard people and infrastructure • Business recovery plans to resume critical operations • ICT recovery plans to restore IT and communications services • Crisis management for executive direction and coordination • Communications plans to conduct internal and external communications • Scenario plans to address specific response strategies for various threats (i.e. Pandemic plan) Testing and exercising is critical to validating a proven capability: • Defining testing outcomes and roadmap to improving BCM maturity through testing • Conducting the test and exercising • Post-test reporting and follow up actions Awareness initiatives to promote BCM knowledge throughout the organisation, practical awareness campaign options suitable for improving and embedding BCM within each unique environment: • Training requirements • BCM awareness campaigns • BCM maintenance and improvement • Stakeholder reporting
  • 9. 8© 2015 Resus Advisory. All rights reserved. Overview of the KPMG BCM Lifecycle and Services Offered to discuss requirements and solutions David Bollaert (MBCI, CISA, BBusSc) Organisational Resilience Director E david@resusadvisory.co.za T +27 (0)82 998 8666 www.resusadvisory.co.za Contact us