SlideShare a Scribd company logo
1 of 41
10 Avoidable Mistakes for Executives  in Resiliency Management Presented by:  Jon Murphy, CISSP, CHS-V, PMP, CBCP, CDCP, NSA-IAM/IEM,  MBA,  AANG Copyright © 2002 – 2011 All Rights Reserved.  Jon Murphy
Disclaimer ,[object Object],[object Object]
Contents ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Objectives ,[object Object],[object Object],[object Object]
On Leadership’s Influence ,[object Object],[object Object]
(par – a – digm) ,[object Object]
Assessing Your Leadership’s Paradigm ,[object Object],[object Object],[object Object],[object Object],[object Object]
Organizational Resiliency ,[object Object]
 
Mistake # 1 ,[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
It’s Everybody’s  Business Organizational Resiliency EMERGENCY MANAGEMENT IT DISASTER RECOVERY FACILITIES MANAGEMENT HUMAN RESOURCES PHYSICAL SECURITY COMMUNICATIONS & PR KNOWLEDGE MANAGEMENT SUPPLY CHAIN MANAGEMENT QUALITY  MANAGEMENT OPERAATIONS  MANAGEMENT FINANCE  MANAGEMENT ENVIRONMENT MANAGEMENT
Mistake # 2 ,[object Object]
Failure to plan and prepare can be costly ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
BII: adequate for these or not? Risk Event Percent Affected Business Impact Power outage 88% High Telecom failure 57% Medium to High Hardware failure 56% Low to High Natural disaster 55% Medium to Very High Human error 53% Low to High Software failure 48% Low to High Service provider failure 39% Medium to High IT Security breach 36% Medium to Very High Facility move 33% Medium to High Terrorists' Acts 21% Medium to Very High Physical Security Breach  18% Medium to Very High Fire 12% Medium to Very High
Unjustified Assumptions ,[object Object],[object Object],[object Object],[object Object]
Mistake # 3 ,[object Object],[object Object]
Information Security is your Best   Partner in Getting to “Yes”
InfoSec Facts ,[object Object],[object Object],[object Object],[object Object],[object Object]
Mistake # 4 ,[object Object]
Valuing ALL the  Costs of Disaster ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Tangible Disaster Impact 6 yr Total Revenues  % Decrease  $16.98 B 0% $12.97 B 23.60% $5.38B  68.32%
Time to Recovery in Days Costs 1 3 7 20 30 R 5X 18X 45X ∞   Recovery  Costs  Factor R + C + S + Complete Market Loss (M) R + C + Shareholder Confidence Loss (S) R + Customer Confidence Loss (C) Predominantly Just Revenue Loss (R) Copyright © 2002 – 2011 All Rights Reserved.  Jon Murphy
Mistake # 5 ,[object Object]
Testing & Exercising Plans ,[object Object],[object Object],[object Object],[object Object]
Graphically Speaking … Range of Impact to the Organization C O P I N G R E S O U R C E S Normal Emergency Disaster Event  Impact Organization’s Level of Coping Resources Disaster Realm ↑ ↓ Copyright © 2002 – 2011 All Rights Reserved.  Jon Murphy
After Mitigation, Prep, Training … Range of Impact to the Organization C O P I N G R E S O U R C E S Normal Emergency Disaster Event  Impact Organization’s Level of Coping Resources Disaster Realm ↑ ↓ Copyright © 2002 – 2011 All Rights Reserved.  Jon Murphy
Mistake # 6 ,[object Object]
To Silo or Not to Silo;  The Components of  Organizational Resiliency ,[object Object],[object Object],[object Object],BC DR ER/CM RC IS The  Risk  Management  Program  Office
Mistake # 7 ,[object Object]
Asking Too Much from Too Few ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Ad Hoc or Dedicated Roles ,[object Object],[object Object],[object Object],[object Object],[object Object]
Mistake # 8 ,[object Object]
How Much Mitigation is Enough? ,[object Object],[object Object],[object Object],[object Object],[object Object]
Response & Recovery Capability Minimal, 30 days Good,  <  3 days Better,  <  1 day Initial Costs Additional  Costs ATOD Costs An Investment Starting Point Copyright © 2002 – 2011 All Rights Reserved.  Jon Murphy
Mistake # 9 ,[object Object]
Regulatory Compliance – an Ever Changing World
Mistake # 10 ,[object Object]
Service Providers – Panacea or Puffery ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Where would you rather be?
Summary ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

More Related Content

What's hot

Reputational Risk
Reputational RiskReputational Risk
Reputational RiskCapco
 
ERM: DIFFERENCES BETWEEN SECTORS
ERM: DIFFERENCES BETWEEN SECTORSERM: DIFFERENCES BETWEEN SECTORS
ERM: DIFFERENCES BETWEEN SECTORSMichel Rochette
 
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...brucelb
 
Trends shaping the future of legal risk management by dave cunningham and m...
Trends shaping the future of legal risk management   by dave cunningham and m...Trends shaping the future of legal risk management   by dave cunningham and m...
Trends shaping the future of legal risk management by dave cunningham and m...David Cunningham
 
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due DiligenceHow to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due DiligenceColleen Beck-Domanico
 
Credit Union Cyber Security
Credit Union Cyber SecurityCredit Union Cyber Security
Credit Union Cyber SecurityStacy Willis
 
Common Objectives of the CRO and the CAE
Common Objectives of the CRO and the CAECommon Objectives of the CRO and the CAE
Common Objectives of the CRO and the CAEWheelhouse Advisors LLC
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches  - The Private Sector PerspectivePrivacy Breaches  - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspectivecanadianlawyer
 
Best practice in reputation management in a causal framework by Dr Kevin Money
Best practice in reputation management in a causal framework by Dr Kevin MoneyBest practice in reputation management in a causal framework by Dr Kevin Money
Best practice in reputation management in a causal framework by Dr Kevin MoneyAddison Group
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckSlideTeam
 
Experion Data Breach Response Excerpts
Experion Data Breach Response ExcerptsExperion Data Breach Response Excerpts
Experion Data Breach Response ExcerptsPeter Henley
 
Disaster management basics rev 1
Disaster management basics rev 1Disaster management basics rev 1
Disaster management basics rev 1Geary Sikich
 
The Litigation Risk Management Approach to Strategic Litigation and Settlement
The Litigation Risk Management Approach to Strategic Litigation and SettlementThe Litigation Risk Management Approach to Strategic Litigation and Settlement
The Litigation Risk Management Approach to Strategic Litigation and Settlementbrucelb
 
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...brucelb
 
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...The Role of the Chief Risk Officer Why You are the Most Important Person in Y...
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...WolfPAC - Integrated Risk Management
 

What's hot (20)

Reputational Risk
Reputational RiskReputational Risk
Reputational Risk
 
ERM: DIFFERENCES BETWEEN SECTORS
ERM: DIFFERENCES BETWEEN SECTORSERM: DIFFERENCES BETWEEN SECTORS
ERM: DIFFERENCES BETWEEN SECTORS
 
Wisegate_GeekSpeak_LG
Wisegate_GeekSpeak_LGWisegate_GeekSpeak_LG
Wisegate_GeekSpeak_LG
 
Captains in Disruption
Captains in DisruptionCaptains in Disruption
Captains in Disruption
 
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...
Negotiation Strategies: Using Game Theory and Decision Tree Analysis to Deter...
 
Trends shaping the future of legal risk management by dave cunningham and m...
Trends shaping the future of legal risk management   by dave cunningham and m...Trends shaping the future of legal risk management   by dave cunningham and m...
Trends shaping the future of legal risk management by dave cunningham and m...
 
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due DiligenceHow to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
 
Credit Union Cyber Security
Credit Union Cyber SecurityCredit Union Cyber Security
Credit Union Cyber Security
 
Common Objectives of the CRO and the CAE
Common Objectives of the CRO and the CAECommon Objectives of the CRO and the CAE
Common Objectives of the CRO and the CAE
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches  - The Private Sector PerspectivePrivacy Breaches  - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspective
 
Best practice in reputation management in a causal framework by Dr Kevin Money
Best practice in reputation management in a causal framework by Dr Kevin MoneyBest practice in reputation management in a causal framework by Dr Kevin Money
Best practice in reputation management in a causal framework by Dr Kevin Money
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete Deck
 
The Lesson of Lost Value
The Lesson of Lost ValueThe Lesson of Lost Value
The Lesson of Lost Value
 
Experion Data Breach Response Excerpts
Experion Data Breach Response ExcerptsExperion Data Breach Response Excerpts
Experion Data Breach Response Excerpts
 
Disaster management basics rev 1
Disaster management basics rev 1Disaster management basics rev 1
Disaster management basics rev 1
 
The Litigation Risk Management Approach to Strategic Litigation and Settlement
The Litigation Risk Management Approach to Strategic Litigation and SettlementThe Litigation Risk Management Approach to Strategic Litigation and Settlement
The Litigation Risk Management Approach to Strategic Litigation and Settlement
 
IRMI Captive Insurance Issues and Trends 2017
IRMI Captive Insurance Issues and Trends 2017IRMI Captive Insurance Issues and Trends 2017
IRMI Captive Insurance Issues and Trends 2017
 
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...
Probability Assessment:
 How Do We Get "Good" Numbers For Litigation Decision...
 
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...The Role of the Chief Risk Officer Why You are the Most Important Person in Y...
The Role of the Chief Risk Officer Why You are the Most Important Person in Y...
 
BCI Counting The Cost
BCI Counting The CostBCI Counting The Cost
BCI Counting The Cost
 

Viewers also liked

Azinternettrtnete 120312140342-phpapp01
Azinternettrtnete 120312140342-phpapp01Azinternettrtnete 120312140342-phpapp01
Azinternettrtnete 120312140342-phpapp01Róbert Moór
 
Hardverek elnevezese
Hardverek elnevezeseHardverek elnevezese
Hardverek elnevezeseRóbert Moór
 
Informatika története
Informatika történeteInformatika története
Informatika történeteRóbert Moór
 
Pedagógiai információforrások
Pedagógiai információforrásokPedagógiai információforrások
Pedagógiai információforrásokRóbert Moór
 
Digitális kompetenciák - produktivitás
Digitális kompetenciák - produktivitásDigitális kompetenciák - produktivitás
Digitális kompetenciák - produktivitásRóbert Moór
 
улыбнитесь
улыбнитесьулыбнитесь
улыбнитесьjulial334
 
Code.org értékelése
Code.org értékeléseCode.org értékelése
Code.org értékeléseRóbert Moór
 
Digitális kompetenciák
Digitális kompetenciákDigitális kompetenciák
Digitális kompetenciákRóbert Moór
 
Listing site independence for vacation rental managers by vrm intel
Listing site independence for vacation rental managers by vrm intelListing site independence for vacation rental managers by vrm intel
Listing site independence for vacation rental managers by vrm intelAmy Hinote
 
Rajzok készítése android rendszerben
Rajzok készítése android rendszerbenRajzok készítése android rendszerben
Rajzok készítése android rendszerbenRóbert Moór
 
Customer Service for Vacation Rentals
Customer Service for Vacation RentalsCustomer Service for Vacation Rentals
Customer Service for Vacation RentalsAmy Hinote
 
Group assignment 2
Group assignment 2Group assignment 2
Group assignment 2Farah Azudin
 
Revenge of the Vacation Rental Manager
Revenge of the Vacation Rental ManagerRevenge of the Vacation Rental Manager
Revenge of the Vacation Rental ManagerAmy Hinote
 

Viewers also liked (18)

Azinternettrtnete 120312140342-phpapp01
Azinternettrtnete 120312140342-phpapp01Azinternettrtnete 120312140342-phpapp01
Azinternettrtnete 120312140342-phpapp01
 
Hardverek elnevezese
Hardverek elnevezeseHardverek elnevezese
Hardverek elnevezese
 
Informatika története
Informatika történeteInformatika története
Informatika története
 
Michael Naimark
Michael NaimarkMichael Naimark
Michael Naimark
 
Pedagógiai információforrások
Pedagógiai információforrásokPedagógiai információforrások
Pedagógiai információforrások
 
ASSIGNMENT 2
ASSIGNMENT 2ASSIGNMENT 2
ASSIGNMENT 2
 
Digitális kompetenciák - produktivitás
Digitális kompetenciák - produktivitásDigitális kompetenciák - produktivitás
Digitális kompetenciák - produktivitás
 
Ac aquaero 4.00_20071105engl
Ac aquaero 4.00_20071105englAc aquaero 4.00_20071105engl
Ac aquaero 4.00_20071105engl
 
улыбнитесь
улыбнитесьулыбнитесь
улыбнитесь
 
Code.org értékelése
Code.org értékeléseCode.org értékelése
Code.org értékelése
 
Digitális kompetenciák
Digitális kompetenciákDigitális kompetenciák
Digitális kompetenciák
 
ASSIGNMENT 2
ASSIGNMENT 2ASSIGNMENT 2
ASSIGNMENT 2
 
What About Form?
What About Form?What About Form?
What About Form?
 
Listing site independence for vacation rental managers by vrm intel
Listing site independence for vacation rental managers by vrm intelListing site independence for vacation rental managers by vrm intel
Listing site independence for vacation rental managers by vrm intel
 
Rajzok készítése android rendszerben
Rajzok készítése android rendszerbenRajzok készítése android rendszerben
Rajzok készítése android rendszerben
 
Customer Service for Vacation Rentals
Customer Service for Vacation RentalsCustomer Service for Vacation Rentals
Customer Service for Vacation Rentals
 
Group assignment 2
Group assignment 2Group assignment 2
Group assignment 2
 
Revenge of the Vacation Rental Manager
Revenge of the Vacation Rental ManagerRevenge of the Vacation Rental Manager
Revenge of the Vacation Rental Manager
 

Similar to 2007 CPM West Keynote Presentation

Right size enterprise disaster recovery plans
Right size enterprise disaster recovery plansRight size enterprise disaster recovery plans
Right size enterprise disaster recovery plansInfo-Tech Research Group
 
RM_Nov14_Zurich_Special
RM_Nov14_Zurich_SpecialRM_Nov14_Zurich_Special
RM_Nov14_Zurich_SpecialTed Donovan
 
Marsh Analytics - CFO com
Marsh Analytics - CFO comMarsh Analytics - CFO com
Marsh Analytics - CFO comPeter Gold
 
Misconceptions of Business Continuity Planning
Misconceptions of Business Continuity PlanningMisconceptions of Business Continuity Planning
Misconceptions of Business Continuity PlanningSymptai Consulting Limited
 
The True Cost of Downtime and the Business Case for Continuity
The True Cost of Downtime and the Business Case for ContinuityThe True Cost of Downtime and the Business Case for Continuity
The True Cost of Downtime and the Business Case for ContinuityContinuity Co., LLC
 
Top 5 Steps to Disaster Preparedness for Businesses
Top 5 Steps to Disaster Preparedness for BusinessesTop 5 Steps to Disaster Preparedness for Businesses
Top 5 Steps to Disaster Preparedness for Businesses- Mark - Fullbright
 
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; Management
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; ManagementBCM Training Part 1 - Introduction To BCM - Business Risk &amp; Management
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; ManagementAndrew Styles
 
Anticipating an Attack: A Pre-Breach Checklist
Anticipating an Attack: A Pre-Breach ChecklistAnticipating an Attack: A Pre-Breach Checklist
Anticipating an Attack: A Pre-Breach ChecklistMorrison & Foerster
 
AlEx - Your Line of Sight to Success
AlEx - Your Line of Sight to SuccessAlEx - Your Line of Sight to Success
AlEx - Your Line of Sight to SuccessNick Anderson
 
Business Continuity and Disaster Recover Week3Part4-ISr.docx
Business Continuity and Disaster Recover  Week3Part4-ISr.docxBusiness Continuity and Disaster Recover  Week3Part4-ISr.docx
Business Continuity and Disaster Recover Week3Part4-ISr.docxhumphrieskalyn
 
HUB International: "Broker Insight Report: Business Interruption Insurance"
HUB International: "Broker Insight Report: Business Interruption Insurance"HUB International: "Broker Insight Report: Business Interruption Insurance"
HUB International: "Broker Insight Report: Business Interruption Insurance"Rex Preston STONER, MSc
 
Health and Safety Proposal
Health and Safety ProposalHealth and Safety Proposal
Health and Safety ProposalGreta McClain
 
Compliance & data security – the way we work
Compliance & data security – the way we workCompliance & data security – the way we work
Compliance & data security – the way we workPuneet Chopra
 
IAPP - Trust is Terrible Thing to Waste
IAPP - Trust is Terrible Thing to WasteIAPP - Trust is Terrible Thing to Waste
IAPP - Trust is Terrible Thing to WasteDave Steer
 
During the HR Manager’s audit at the India plant, The HR manager a.docx
During the HR Manager’s audit at the India plant, The HR manager a.docxDuring the HR Manager’s audit at the India plant, The HR manager a.docx
During the HR Manager’s audit at the India plant, The HR manager a.docxinfantkimber
 
The Economics of IT Risk and Reputation
The Economics of IT Risk and ReputationThe Economics of IT Risk and Reputation
The Economics of IT Risk and ReputationIBM Security
 

Similar to 2007 CPM West Keynote Presentation (20)

disaster-recovery-online
disaster-recovery-onlinedisaster-recovery-online
disaster-recovery-online
 
Ready or not?
Ready or not?Ready or not?
Ready or not?
 
Right size enterprise disaster recovery plans
Right size enterprise disaster recovery plansRight size enterprise disaster recovery plans
Right size enterprise disaster recovery plans
 
RM_Nov14_Zurich_Special
RM_Nov14_Zurich_SpecialRM_Nov14_Zurich_Special
RM_Nov14_Zurich_Special
 
Marsh Analytics - CFO com
Marsh Analytics - CFO comMarsh Analytics - CFO com
Marsh Analytics - CFO com
 
Misconceptions of Business Continuity Planning
Misconceptions of Business Continuity PlanningMisconceptions of Business Continuity Planning
Misconceptions of Business Continuity Planning
 
The True Cost of Downtime and the Business Case for Continuity
The True Cost of Downtime and the Business Case for ContinuityThe True Cost of Downtime and the Business Case for Continuity
The True Cost of Downtime and the Business Case for Continuity
 
Top 5 Steps to Disaster Preparedness for Businesses
Top 5 Steps to Disaster Preparedness for BusinessesTop 5 Steps to Disaster Preparedness for Businesses
Top 5 Steps to Disaster Preparedness for Businesses
 
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; Management
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; ManagementBCM Training Part 1 - Introduction To BCM - Business Risk &amp; Management
BCM Training Part 1 - Introduction To BCM - Business Risk &amp; Management
 
D&O
D&OD&O
D&O
 
Anticipating an Attack: A Pre-Breach Checklist
Anticipating an Attack: A Pre-Breach ChecklistAnticipating an Attack: A Pre-Breach Checklist
Anticipating an Attack: A Pre-Breach Checklist
 
AlEx - Your Line of Sight to Success
AlEx - Your Line of Sight to SuccessAlEx - Your Line of Sight to Success
AlEx - Your Line of Sight to Success
 
Business Continuity and Disaster Recover Week3Part4-ISr.docx
Business Continuity and Disaster Recover  Week3Part4-ISr.docxBusiness Continuity and Disaster Recover  Week3Part4-ISr.docx
Business Continuity and Disaster Recover Week3Part4-ISr.docx
 
HUB International: "Broker Insight Report: Business Interruption Insurance"
HUB International: "Broker Insight Report: Business Interruption Insurance"HUB International: "Broker Insight Report: Business Interruption Insurance"
HUB International: "Broker Insight Report: Business Interruption Insurance"
 
The Practice Management Seminar
The Practice Management SeminarThe Practice Management Seminar
The Practice Management Seminar
 
Health and Safety Proposal
Health and Safety ProposalHealth and Safety Proposal
Health and Safety Proposal
 
Compliance & data security – the way we work
Compliance & data security – the way we workCompliance & data security – the way we work
Compliance & data security – the way we work
 
IAPP - Trust is Terrible Thing to Waste
IAPP - Trust is Terrible Thing to WasteIAPP - Trust is Terrible Thing to Waste
IAPP - Trust is Terrible Thing to Waste
 
During the HR Manager’s audit at the India plant, The HR manager a.docx
During the HR Manager’s audit at the India plant, The HR manager a.docxDuring the HR Manager’s audit at the India plant, The HR manager a.docx
During the HR Manager’s audit at the India plant, The HR manager a.docx
 
The Economics of IT Risk and Reputation
The Economics of IT Risk and ReputationThe Economics of IT Risk and Reputation
The Economics of IT Risk and Reputation
 

2007 CPM West Keynote Presentation

  • 1. 10 Avoidable Mistakes for Executives in Resiliency Management Presented by: Jon Murphy, CISSP, CHS-V, PMP, CBCP, CDCP, NSA-IAM/IEM, MBA, AANG Copyright © 2002 – 2011 All Rights Reserved. Jon Murphy
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.  
  • 10.
  • 11.
  • 12. It’s Everybody’s Business Organizational Resiliency EMERGENCY MANAGEMENT IT DISASTER RECOVERY FACILITIES MANAGEMENT HUMAN RESOURCES PHYSICAL SECURITY COMMUNICATIONS & PR KNOWLEDGE MANAGEMENT SUPPLY CHAIN MANAGEMENT QUALITY MANAGEMENT OPERAATIONS MANAGEMENT FINANCE MANAGEMENT ENVIRONMENT MANAGEMENT
  • 13.
  • 14.
  • 15. BII: adequate for these or not? Risk Event Percent Affected Business Impact Power outage 88% High Telecom failure 57% Medium to High Hardware failure 56% Low to High Natural disaster 55% Medium to Very High Human error 53% Low to High Software failure 48% Low to High Service provider failure 39% Medium to High IT Security breach 36% Medium to Very High Facility move 33% Medium to High Terrorists' Acts 21% Medium to Very High Physical Security Breach 18% Medium to Very High Fire 12% Medium to Very High
  • 16.
  • 17.
  • 18. Information Security is your Best Partner in Getting to “Yes”
  • 19.
  • 20.
  • 21.
  • 22. Tangible Disaster Impact 6 yr Total Revenues % Decrease $16.98 B 0% $12.97 B 23.60% $5.38B 68.32%
  • 23. Time to Recovery in Days Costs 1 3 7 20 30 R 5X 18X 45X ∞ Recovery Costs Factor R + C + S + Complete Market Loss (M) R + C + Shareholder Confidence Loss (S) R + Customer Confidence Loss (C) Predominantly Just Revenue Loss (R) Copyright © 2002 – 2011 All Rights Reserved. Jon Murphy
  • 24.
  • 25.
  • 26. Graphically Speaking … Range of Impact to the Organization C O P I N G R E S O U R C E S Normal Emergency Disaster Event Impact Organization’s Level of Coping Resources Disaster Realm ↑ ↓ Copyright © 2002 – 2011 All Rights Reserved. Jon Murphy
  • 27. After Mitigation, Prep, Training … Range of Impact to the Organization C O P I N G R E S O U R C E S Normal Emergency Disaster Event Impact Organization’s Level of Coping Resources Disaster Realm ↑ ↓ Copyright © 2002 – 2011 All Rights Reserved. Jon Murphy
  • 28.
  • 29.
  • 30.
  • 31.
  • 32.
  • 33.
  • 34.
  • 35. Response & Recovery Capability Minimal, 30 days Good, < 3 days Better, < 1 day Initial Costs Additional Costs ATOD Costs An Investment Starting Point Copyright © 2002 – 2011 All Rights Reserved. Jon Murphy
  • 36.
  • 37. Regulatory Compliance – an Ever Changing World
  • 38.
  • 39.
  • 40. Where would you rather be?
  • 41.

Editor's Notes

  1. And… In keeping with that thought… Lets find out exactly what we will look at today.
  2. Why apocalyptic How to avoid
  3. Eisenhower quote vs Shane &amp; John M approach Are key responders fully aware of the org’s dependency and has the org made plans to take care of their special needs What about critical responders who are temporarily unavailable or impaired What is your org’s policy on impaired persons in an emergency?
  4. BCP Activities include: Customer, partner, supplier communications and manual workarounds; possible alternate quarters DRP activities include: data recovery, server recovery, network re-routing, hot site spin up, etc. Tell the oilwell fitting company story Mention other domains Why apocalyptic and how to avoid
  5. All these functions, and probably more, need BC addressed, though as I said, DR for us is a more critical role than for some others firms What about support functions we take for granted, mail and other deliveries, custodial, etc.
  6. CPM surveyed the Fortune 5000 in 2004 and some 2800 respondents reported these results. 30% of all businesses that have a major fire go out of business within a year. 70% fail within 5 years. ( Research by Gartner Group ) 93% of companies that lost their works-in-progress data for 10 days or more due to a disaster, filed for bankruptcy within 1 year of the disaster. ( National Archives &amp; Records Administration, Washington DC ) 50% of businesses that found themselves without data recovery from PCs for this same time period filed for bankruptcy immediately. ( National Archives &amp; Records Administration, Washington DC ) What about a pandemic, has your org started any research or planning around Avian Flu mutating to a human infectious form? What about falling water? Will your BII cover the expensive decorations that adorn HQ?
  7. You need to know where to get replacement employees or contract workers who can take up the slack in such a situation.  If your systems are so customized that such workers can’t be found, then you’ve identified another key vulnerability for your organization. Many planners simply assume that because of the nature of their organization (bank, nursing home, etc), the utility companies will assign them a high priority in their recovery operations.  During the 2004 hurricane devastation in Florida, many nursing home operators - who simply assumed that they had the same priority as hospitals - found out that they were actually lower-level in priority than most businesses. Find out BEFORE disaster strikes! Most diesel-powered generators only have about a three-day supply of fuel in their supply tanks.  Often, during a disaster, areas become inaccessible to fuel trucks for longer periods of time than that, and alternate plans need to be drawn up for that eventuality. Many organizations are dependent upon air deliveries of key items.  An example would be drug companies who are delivering test samples for clinical trials.  These deliveries were completely disrupted after 9/11 when the entire air fleet of the country was grounded.  Another example would be organizations who have arranged for air delivery of replacement computers in a disaster–just the time when airports might be closed.  Alternative means of transportation need to be identified in advance to cover these eventualities.
  8. Mention article coming out and prez at DRJ FW 06 on IS meeting Homeland security
  9. All lines represent all the EI brands’ contribution. Green is Business As Usual, Orange is impact of the 50% loss of Hotels.com (complete outage time of 15 days, plus less than 100% operation time, plus damage to brand) and red is the impact of the 50% loss of Expedia.com (complete outage time of 30 days, plus less than 100% operation time, plus damage to brand)
  10. Recovery Costs Factor exponential growth over time curve source; Sir Andrew Hiles, the British Continuity Institute and the British Standards Institute 2002. Actual $ figures sourced from Expedia FP&amp;A 2005
  11. Discuss loss of ability to purchase and pay Coordination with local jurisdiction’s emergency services and EPD
  12. The less mitigation/prep/training is undertaken, the organization’s coping level is lower and makes the Disaster Realm larger.
  13. As more mitigation/prep/training is undertaken, the organization’s coping level rises and makes the Disaster Realm smaller.
  14. Repository and corporate memory of lessons learned Nearby risks?
  15. Up front costs + RTO costs + Additional recovery costs = total cost / impact Include cost to manage brand impact (advertising, coupons, marketing…) Investing more up front reduces other costs
  16. I thought about alternately titling this slide…”And the regulators shall inherit the earth”. I know you all realize that is not even all the pertinent heavy hitter regs, for instance FACTA, FISMA, GLBA are not even covered here!