SlideShare a Scribd company logo
Blind spots in your Pandemic Response
Have you activated
your Business
Continuity Plan?
Unpleasant surprises
1. Loss of Internet and/or mobile telephony
 What’s your Business Continuity Plan (BCP) for
such situations?
 Do you have any work-arounds left for
communication during this (partial) lockdown
period (e.g. for 2-factor authentication and staff/
client/supplier notifications)?
 Do your voice/data communication providers have BCPs?
 Have these recently been tested?
 Do you know where you are in their priority listing?
 Would you have to start looking for a new supplier from scratch… whilst everyone
else is doing the same?
 Have your executives considered conducting an exercise on such challenges whilst
in lockdown?
2. Cloud-based services/applications down
 Consider your increased dependency on
cloud-based services, e.g. for
o online sales
o data storage
o accounting
o banking
o product ordering
 What are your (manual) work-arounds that will help you sufficiently if any of these
were to be disrupted?
 Are dual supplier arrangements even possible in order to be prepared for such
situations? (in advance, yes… but on the spot?)
Unpleasant surprises
Unpleasant surprises
3. Data centre failure
 For those who have their servers in a self-managed
or outsourced data centre facility: To which degree
has regular maintenance been reduced?
 If an incident occurs, can it be fixed if IT staff are
not able/allowed to troubleshoot the problem on-site?
 Is the remote access capability of technical staff
sufficient?
 From where can you still obtain spare servers, UPSes, generators, fuel, AirCon
units and/or cabling related equipment/parts?
 Will these come soon enough, considering current disruptions in supply
(particularly from overseas) and overloads on postal services and couriers?
 Could you still develop dual supplier arrangements now, in order to be prepared
for such situations?
Unpleasant surprises
4. Cyber attacks
Considering staff are working on various WiFi
networks, BYOD devices and possibly less
controlled/secure systems, this is a realistic threat.
If you rely to a high degree of interfacing
between your systems and those of external
customers and suppliers…
 How will you know how far a cyber attack
may have travelled?
 How can you quickly get external technical assistance
if the best service providers are most likely overloaded
and snapped up by the ‘big end of town’?
Unpleasant surprises
5. Staff related challenges
 Are your policies regarding teleworking,
workplace health, flexible work, paid/unpaid
leave and staff expense reimbursements clear?
 How are you preventing ‘meeting fatigue’ and
disinterest due to inefficient group call protocols?
 How are you keeping yourself and your
colleagues/staff engaged and motivated when
stood down/not rostered in for a while?
 Could downtime be used for remote study or certification activities?
 What about staff who are suffering from health/wellbeing issues due to dealing with
limited ergonomic comforts and lack of social interaction?
Unpleasant surprises
5. Staff related challenges
 Have you explored ‘Pomodoro’ and other
techniques that may help staff being
productive whilst working more on
their own?
 How are you and your colleagues
managing distractions? Have you looked
into tools like Checky (time tracker for
phone), Hey Focus and Freedom?
 On the flipside, who in your team seems to be drawn to their beeping devices all
day and night?
 Is there a true culture in place where staff comfortably speak up if they’re
struggling?
 Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and
regular ‘mini invocations’
 More is less – Reduce document volume and make it easy to maintain
 Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and
gaming techniques including ‘red teaming’
 Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’
 Global best practice: For proper BCP as with DR, Risk Management and Security),
apply up-to-date principles/strategies (and standards!)
Making Business Continuity plans that actually work when you need
them most
2020 Pandemic
• The BCI has conducted a series of fortnightly global surveys to
learn more about how organizations are adapting to the current
pandemic:
https://www.thebci.org/knowledge/coronavirus.html
• BCI Organizational Preparedness Report
• 3rd and 4th Edition, April 2020
• Around 350 respondents from 60 countries and roughly 20
industries
Abbreviations
Abbreviation, Acronym Term
comms Means of communication (tech)
Communications (policies, media)
wfh Work from home
Organizational Aspects
Main areas covered
1) HR/Staff Measures 18 Questions
2) Health and Hygiene 13 Questions
3) Travel 10 Questions
4) IT, Technology and Telecoms 14 Questions
5) Supply Chain 7 Questions
6) Business Continuity Plans 18 Questions
Question Selection
• Top implemented questions (100% down
to ca. 50%) Already implementing
 Considering implementing
 Not considering implementing
 Unsure
 Not applicable
1. HR/Staff Measures
• Restricted visitor and/or contractor engagements
• Ensured a plan is in place if a staff member is diagnosed with COVID-19
• Implemented non-punitive leave policies to allow quarantining staff to wfh
• Allowed staff to work from home to look after children if school/nursery closures
• Ensured staff have a dedicated helpline/contact to share personal COVID concerns
• Reviewed job roles to ensure key processes can be carried out by skeleton staff
• Implemented regular org-wide calls for staff to briefed on corporate strategy updates
• Implemented leave policies to allow staff to care for sick relatives
• Provided additional support to those struck by COVID-19
• …
2. Health and Hygiene
• Implementing social distancing measures
• Cascaded health & hygiene communications from government/other trusted sources
• Provided hand sanitizer in office spaces
• Instructed office cleaners to engage in more thorough daily cleansing
• Prepared procedure to respond in the case of a confirmed COVID-19 infection
• Taken steps to safeguard employees’ mental health and wellbeing
• Implemented daily team calls to maintain structure and reduce isolation
• Enforced a non-handshake policy
• …
3. Travel
• Implemented a domestic travel ban (e.g. to external meetings and events)
• Implemented an international travel ban
• Closed offices and other locations to access unless approved by senior management
• Asked staff to wfh for seven or more days if returning from holiday/travel in “high risk”
countries
• Implemented an inter-office travel ban
• Provided keyworker staff with travel guidance and/or alternatives
• …
4. IT, Technology and Telecoms
• Transferred meetings to conference calls where possible
• Ensured staff who are wfh have acceptable cyber-security measures in place
• Ensured IT capabilities support wfh measures to cover peak/non-peak times
• Ensured comms in place so staff can communicate if all staff wfh
• Reviewed cyber arrangements so systems stay secure in mass-staff absences
• Internal comms regarding medical advice & company procedures given to staff
• Established IT helpdesk/upscaled existing to allow increased reliance on technology
• Ensured external comms plan in place should a staff become infected
• …
5. Supply Chain
• Identified a list of critical suppliers in response to COVID-19
• Maintained regular communications with suppliers
• Reviewed the business continuity plans of key suppliers to ensure continuity of service
• Prioritised suppliers for review based on operating location
• …
6. Business Continuity Plans
• Have a validated information source which is monitored daily
• Ensured incident management teams are meeting regularly
• Activated Incident Management teams to manage the business disruption
• Considered how sustainable the business continuity response is
• Ensured all plans have been reviewed to reflect the current circumstances
• Reviewed the BIA to reflect changing priorities given prolonged impact of COVID-19
• Undertaken scenario analysis to identify range of potential outcomes/est. impacts
• Undertaken financial modelling to determine how the organization will be affected post-
COVID
• Conducted horizon scanning for other risks that may materialize during the pandemic
• …
ISO/IEC 22301
Training Courses
• ISO 22301 Introduction
1 Day Course
• ISO 22301 Foundation
2 Days Course
• ISO 22301 Lead Implementer
5 Days Course
• ISO 22301 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
22301
www.pecb.com/events
THANK YOU
?
rinske@businessasusual.com.au
wolfgang.mahr@continuuuity.ch
linkedin.com/in/businessasusual/
linkedin.com/in/continuuuity
www.businessasusual.com.au
www.continuuuity.com

More Related Content

What's hot

Business continuity overview slideshare
Business continuity overview slideshareBusiness continuity overview slideshare
Business continuity overview slideshare
Chris Greenhill
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
gcleary
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete Deck
SlideTeam
 
Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?
PECB
 
Information Security Governance and Strategy
Information Security Governance and Strategy Information Security Governance and Strategy
Information Security Governance and Strategy
Dam Frank
 
Endpoint Security
Endpoint SecurityEndpoint Security
Endpoint Security
Ahmed Hashem El Fiky
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
Adv Prashant Mali
 
Business continuity
Business continuityBusiness continuity
Business continuity
Alka Mehar
 
The Basics of a Business Continuity Plan
The Basics of a Business Continuity PlanThe Basics of a Business Continuity Plan
The Basics of a Business Continuity Plan
NH Division of Economic Development
 
Data governance Program PowerPoint Presentation Slides
Data governance Program PowerPoint Presentation Slides Data governance Program PowerPoint Presentation Slides
Data governance Program PowerPoint Presentation Slides
SlideTeam
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3
Tanmay Shinde
 
Business continuity-plan-template
Business continuity-plan-templateBusiness continuity-plan-template
Business continuity-plan-template
Mohamed Owaish
 
Workplace Security Awareness-Part 1
Workplace Security Awareness-Part 1Workplace Security Awareness-Part 1
Workplace Security Awareness-Part 1
David Santiago
 
Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3
Dam Frank
 
PCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
PCAOB Audit Alert #11: New Internal Control Testing Standards & ExcelPCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
PCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
Aviva Spectrum™
 
Master Data Management
Master Data ManagementMaster Data Management
Master Data Management
Sung Kuan
 
ISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdf
SerkanRafetHalil1
 
Information Technology policy
Information Technology policyInformation Technology policy
Information Technology policymarindi
 

What's hot (20)

Business continuity overview slideshare
Business continuity overview slideshareBusiness continuity overview slideshare
Business continuity overview slideshare
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
How To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete DeckHow To Present Cyber Security To Senior Management Complete Deck
How To Present Cyber Security To Senior Management Complete Deck
 
Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?
 
Information Security Governance and Strategy
Information Security Governance and Strategy Information Security Governance and Strategy
Information Security Governance and Strategy
 
Endpoint Security
Endpoint SecurityEndpoint Security
Endpoint Security
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
Business continuity
Business continuityBusiness continuity
Business continuity
 
The Basics of a Business Continuity Plan
The Basics of a Business Continuity PlanThe Basics of a Business Continuity Plan
The Basics of a Business Continuity Plan
 
Data governance Program PowerPoint Presentation Slides
Data governance Program PowerPoint Presentation Slides Data governance Program PowerPoint Presentation Slides
Data governance Program PowerPoint Presentation Slides
 
Introduction to Business Continuity Management
Introduction to Business Continuity ManagementIntroduction to Business Continuity Management
Introduction to Business Continuity Management
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3
 
Business continuity-plan-template
Business continuity-plan-templateBusiness continuity-plan-template
Business continuity-plan-template
 
Workplace Security Awareness-Part 1
Workplace Security Awareness-Part 1Workplace Security Awareness-Part 1
Workplace Security Awareness-Part 1
 
Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3Information Security Governance and Strategy - 3
Information Security Governance and Strategy - 3
 
PCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
PCAOB Audit Alert #11: New Internal Control Testing Standards & ExcelPCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
PCAOB Audit Alert #11: New Internal Control Testing Standards & Excel
 
Master Data Management
Master Data ManagementMaster Data Management
Master Data Management
 
ISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdf
 
Information Technology policy
Information Technology policyInformation Technology policy
Information Technology policy
 

Similar to Business Continuity Planning During and After the Coronavirus (COVID-19) Pandemic

EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptxEMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
ArunimaHazra2
 
Covid-19 in parcel and postal industry
Covid-19 in parcel and postal industryCovid-19 in parcel and postal industry
Covid-19 in parcel and postal industry
Theodore Dellis
 
COVID-19 outbreak for parcel and postal operations
COVID-19 outbreak for parcel and postal operationsCOVID-19 outbreak for parcel and postal operations
COVID-19 outbreak for parcel and postal operations
Grzegorz Urban
 
Covid 19 response for pharma companies
Covid 19 response for pharma companiesCovid 19 response for pharma companies
Covid 19 response for pharma companies
aakash malhotra
 
Project management in the times of covid 19
Project management in the times of covid 19Project management in the times of covid 19
Project management in the times of covid 19
Orangescrum
 
Vrs guide bring your team back to work with maximum safety and wellness pos...
Vrs guide   bring your team back to work with maximum safety and wellness pos...Vrs guide   bring your team back to work with maximum safety and wellness pos...
Vrs guide bring your team back to work with maximum safety and wellness pos...
Dendreon
 
Convercent Case Management Guide
Convercent Case Management GuideConvercent Case Management Guide
Convercent Case Management Guide
Brooke Webster
 
Mayfield CXO Survey: Post COVID-19 Impacts to IT
Mayfield CXO Survey: Post COVID-19 Impacts to ITMayfield CXO Survey: Post COVID-19 Impacts to IT
Mayfield CXO Survey: Post COVID-19 Impacts to IT
Navin Chaddha
 
Small Business Owners & COVID-19
Small Business Owners & COVID-19Small Business Owners & COVID-19
Small Business Owners & COVID-19
Witmer Health | i-calQ | Elado
 
Business Continuity Emerging Trends - DRIE Atlantic - Summary
Business Continuity Emerging Trends - DRIE Atlantic - SummaryBusiness Continuity Emerging Trends - DRIE Atlantic - Summary
Business Continuity Emerging Trends - DRIE Atlantic - Summary
Marie Lavoie Dufort
 
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
PeopleWiz Consulting
 
Asq Article Kreg Kukor
Asq Article Kreg KukorAsq Article Kreg Kukor
Asq Article Kreg Kukorkkukor
 
Managing Through COVID-19
Managing Through COVID-19Managing Through COVID-19
Managing Through COVID-19
Net at Work
 
Practical Strategies for Taking on New Studies Post COVID-19
Practical Strategies for Taking on New Studies Post COVID-19Practical Strategies for Taking on New Studies Post COVID-19
Practical Strategies for Taking on New Studies Post COVID-19
Veeva Systems
 
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdfPrepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
arjuntiwari586
 
Managing uncertainty a practical guide
Managing uncertainty a practical guideManaging uncertainty a practical guide
Managing uncertainty a practical guide
DB Computer Solutions Ltd
 
Business continuity for SMEs
Business continuity for SMEsBusiness continuity for SMEs
Business continuity for SMEs
reedgrace1
 
Virginia Scoville 805-404-2914
Virginia Scoville 805-404-2914Virginia Scoville 805-404-2914
Virginia Scoville 805-404-2914Ginny Scoville
 

Similar to Business Continuity Planning During and After the Coronavirus (COVID-19) Pandemic (20)

EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptxEMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
EMERGENCE OF NEW DIGITALIZATION TECHNIQUES IN ORGANISATIONS IN.pptx
 
Covid-19 in parcel and postal industry
Covid-19 in parcel and postal industryCovid-19 in parcel and postal industry
Covid-19 in parcel and postal industry
 
COVID-19 outbreak for parcel and postal operations
COVID-19 outbreak for parcel and postal operationsCOVID-19 outbreak for parcel and postal operations
COVID-19 outbreak for parcel and postal operations
 
Covid 19 response for pharma companies
Covid 19 response for pharma companiesCovid 19 response for pharma companies
Covid 19 response for pharma companies
 
Project management in the times of covid 19
Project management in the times of covid 19Project management in the times of covid 19
Project management in the times of covid 19
 
Vrs guide bring your team back to work with maximum safety and wellness pos...
Vrs guide   bring your team back to work with maximum safety and wellness pos...Vrs guide   bring your team back to work with maximum safety and wellness pos...
Vrs guide bring your team back to work with maximum safety and wellness pos...
 
Tc11 ad14
Tc11 ad14Tc11 ad14
Tc11 ad14
 
Convercent Case Management Guide
Convercent Case Management GuideConvercent Case Management Guide
Convercent Case Management Guide
 
Mayfield CXO Survey: Post COVID-19 Impacts to IT
Mayfield CXO Survey: Post COVID-19 Impacts to ITMayfield CXO Survey: Post COVID-19 Impacts to IT
Mayfield CXO Survey: Post COVID-19 Impacts to IT
 
Small Business Owners & COVID-19
Small Business Owners & COVID-19Small Business Owners & COVID-19
Small Business Owners & COVID-19
 
NVQ Storyboard 401
NVQ Storyboard 401NVQ Storyboard 401
NVQ Storyboard 401
 
Business Continuity Emerging Trends - DRIE Atlantic - Summary
Business Continuity Emerging Trends - DRIE Atlantic - SummaryBusiness Continuity Emerging Trends - DRIE Atlantic - Summary
Business Continuity Emerging Trends - DRIE Atlantic - Summary
 
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
Reimagining the Workplace pot Covid-19 - Structure, Roles, Practices, Compete...
 
Asq Article Kreg Kukor
Asq Article Kreg KukorAsq Article Kreg Kukor
Asq Article Kreg Kukor
 
Managing Through COVID-19
Managing Through COVID-19Managing Through COVID-19
Managing Through COVID-19
 
Practical Strategies for Taking on New Studies Post COVID-19
Practical Strategies for Taking on New Studies Post COVID-19Practical Strategies for Taking on New Studies Post COVID-19
Practical Strategies for Taking on New Studies Post COVID-19
 
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdfPrepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
Prepare a 3-4 page, double-spaced paper (cite 3-4 reliable sources) .pdf
 
Managing uncertainty a practical guide
Managing uncertainty a practical guideManaging uncertainty a practical guide
Managing uncertainty a practical guide
 
Business continuity for SMEs
Business continuity for SMEsBusiness continuity for SMEs
Business continuity for SMEs
 
Virginia Scoville 805-404-2914
Virginia Scoville 805-404-2914Virginia Scoville 805-404-2914
Virginia Scoville 805-404-2914
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
PECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
PECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
PECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
PECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
PECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
PECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
PECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
PECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Recently uploaded

Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
Jean Carlos Nunes Paixão
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Atul Kumar Singh
 
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
MysoreMuleSoftMeetup
 
Introduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp NetworkIntroduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp Network
TechSoup
 
TESDA TM1 REVIEWER FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
TESDA TM1 REVIEWER  FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...TESDA TM1 REVIEWER  FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
TESDA TM1 REVIEWER FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
EugeneSaldivar
 
Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
Tamralipta Mahavidyalaya
 
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCECLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
BhavyaRajput3
 
Palestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptxPalestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptx
RaedMohamed3
 
678020731-Sumas-y-Restas-Para-Colorear.pdf
678020731-Sumas-y-Restas-Para-Colorear.pdf678020731-Sumas-y-Restas-Para-Colorear.pdf
678020731-Sumas-y-Restas-Para-Colorear.pdf
CarlosHernanMontoyab2
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
DhatriParmar
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
Atul Kumar Singh
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
JosvitaDsouza2
 
Digital Tools and AI for Teaching Learning and Research
Digital Tools and AI for Teaching Learning and ResearchDigital Tools and AI for Teaching Learning and Research
Digital Tools and AI for Teaching Learning and Research
Vikramjit Singh
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
Levi Shapiro
 
Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.
Ashokrao Mane college of Pharmacy Peth-Vadgaon
 
A Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in EducationA Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in Education
Peter Windle
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
GeoBlogs
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
siemaillard
 
The Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdfThe Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdf
kaushalkr1407
 
Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
Mohd Adib Abd Muin, Senior Lecturer at Universiti Utara Malaysia
 

Recently uploaded (20)

Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
 
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
Mule 4.6 & Java 17 Upgrade | MuleSoft Mysore Meetup #46
 
Introduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp NetworkIntroduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp Network
 
TESDA TM1 REVIEWER FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
TESDA TM1 REVIEWER  FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...TESDA TM1 REVIEWER  FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
TESDA TM1 REVIEWER FOR NATIONAL ASSESSMENT WRITTEN AND ORAL QUESTIONS WITH A...
 
Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
 
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCECLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
 
Palestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptxPalestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptx
 
678020731-Sumas-y-Restas-Para-Colorear.pdf
678020731-Sumas-y-Restas-Para-Colorear.pdf678020731-Sumas-y-Restas-Para-Colorear.pdf
678020731-Sumas-y-Restas-Para-Colorear.pdf
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
 
Digital Tools and AI for Teaching Learning and Research
Digital Tools and AI for Teaching Learning and ResearchDigital Tools and AI for Teaching Learning and Research
Digital Tools and AI for Teaching Learning and Research
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
 
Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.
 
A Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in EducationA Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in Education
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
 
The Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdfThe Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdf
 
Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
 

Business Continuity Planning During and After the Coronavirus (COVID-19) Pandemic

  • 1.
  • 2. Blind spots in your Pandemic Response Have you activated your Business Continuity Plan?
  • 3. Unpleasant surprises 1. Loss of Internet and/or mobile telephony  What’s your Business Continuity Plan (BCP) for such situations?  Do you have any work-arounds left for communication during this (partial) lockdown period (e.g. for 2-factor authentication and staff/ client/supplier notifications)?  Do your voice/data communication providers have BCPs?  Have these recently been tested?  Do you know where you are in their priority listing?  Would you have to start looking for a new supplier from scratch… whilst everyone else is doing the same?  Have your executives considered conducting an exercise on such challenges whilst in lockdown?
  • 4. 2. Cloud-based services/applications down  Consider your increased dependency on cloud-based services, e.g. for o online sales o data storage o accounting o banking o product ordering  What are your (manual) work-arounds that will help you sufficiently if any of these were to be disrupted?  Are dual supplier arrangements even possible in order to be prepared for such situations? (in advance, yes… but on the spot?) Unpleasant surprises
  • 5.
  • 6. Unpleasant surprises 3. Data centre failure  For those who have their servers in a self-managed or outsourced data centre facility: To which degree has regular maintenance been reduced?  If an incident occurs, can it be fixed if IT staff are not able/allowed to troubleshoot the problem on-site?  Is the remote access capability of technical staff sufficient?  From where can you still obtain spare servers, UPSes, generators, fuel, AirCon units and/or cabling related equipment/parts?  Will these come soon enough, considering current disruptions in supply (particularly from overseas) and overloads on postal services and couriers?  Could you still develop dual supplier arrangements now, in order to be prepared for such situations?
  • 7. Unpleasant surprises 4. Cyber attacks Considering staff are working on various WiFi networks, BYOD devices and possibly less controlled/secure systems, this is a realistic threat. If you rely to a high degree of interfacing between your systems and those of external customers and suppliers…  How will you know how far a cyber attack may have travelled?  How can you quickly get external technical assistance if the best service providers are most likely overloaded and snapped up by the ‘big end of town’?
  • 8. Unpleasant surprises 5. Staff related challenges  Are your policies regarding teleworking, workplace health, flexible work, paid/unpaid leave and staff expense reimbursements clear?  How are you preventing ‘meeting fatigue’ and disinterest due to inefficient group call protocols?  How are you keeping yourself and your colleagues/staff engaged and motivated when stood down/not rostered in for a while?  Could downtime be used for remote study or certification activities?  What about staff who are suffering from health/wellbeing issues due to dealing with limited ergonomic comforts and lack of social interaction?
  • 9. Unpleasant surprises 5. Staff related challenges  Have you explored ‘Pomodoro’ and other techniques that may help staff being productive whilst working more on their own?  How are you and your colleagues managing distractions? Have you looked into tools like Checky (time tracker for phone), Hey Focus and Freedom?  On the flipside, who in your team seems to be drawn to their beeping devices all day and night?  Is there a true culture in place where staff comfortably speak up if they’re struggling?
  • 10.  Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and regular ‘mini invocations’  More is less – Reduce document volume and make it easy to maintain  Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and gaming techniques including ‘red teaming’  Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’  Global best practice: For proper BCP as with DR, Risk Management and Security), apply up-to-date principles/strategies (and standards!) Making Business Continuity plans that actually work when you need them most
  • 11. 2020 Pandemic • The BCI has conducted a series of fortnightly global surveys to learn more about how organizations are adapting to the current pandemic: https://www.thebci.org/knowledge/coronavirus.html • BCI Organizational Preparedness Report • 3rd and 4th Edition, April 2020 • Around 350 respondents from 60 countries and roughly 20 industries
  • 12. Abbreviations Abbreviation, Acronym Term comms Means of communication (tech) Communications (policies, media) wfh Work from home
  • 13. Organizational Aspects Main areas covered 1) HR/Staff Measures 18 Questions 2) Health and Hygiene 13 Questions 3) Travel 10 Questions 4) IT, Technology and Telecoms 14 Questions 5) Supply Chain 7 Questions 6) Business Continuity Plans 18 Questions
  • 14. Question Selection • Top implemented questions (100% down to ca. 50%) Already implementing  Considering implementing  Not considering implementing  Unsure  Not applicable
  • 15. 1. HR/Staff Measures • Restricted visitor and/or contractor engagements • Ensured a plan is in place if a staff member is diagnosed with COVID-19 • Implemented non-punitive leave policies to allow quarantining staff to wfh • Allowed staff to work from home to look after children if school/nursery closures • Ensured staff have a dedicated helpline/contact to share personal COVID concerns • Reviewed job roles to ensure key processes can be carried out by skeleton staff • Implemented regular org-wide calls for staff to briefed on corporate strategy updates • Implemented leave policies to allow staff to care for sick relatives • Provided additional support to those struck by COVID-19 • …
  • 16. 2. Health and Hygiene • Implementing social distancing measures • Cascaded health & hygiene communications from government/other trusted sources • Provided hand sanitizer in office spaces • Instructed office cleaners to engage in more thorough daily cleansing • Prepared procedure to respond in the case of a confirmed COVID-19 infection • Taken steps to safeguard employees’ mental health and wellbeing • Implemented daily team calls to maintain structure and reduce isolation • Enforced a non-handshake policy • …
  • 17. 3. Travel • Implemented a domestic travel ban (e.g. to external meetings and events) • Implemented an international travel ban • Closed offices and other locations to access unless approved by senior management • Asked staff to wfh for seven or more days if returning from holiday/travel in “high risk” countries • Implemented an inter-office travel ban • Provided keyworker staff with travel guidance and/or alternatives • …
  • 18. 4. IT, Technology and Telecoms • Transferred meetings to conference calls where possible • Ensured staff who are wfh have acceptable cyber-security measures in place • Ensured IT capabilities support wfh measures to cover peak/non-peak times • Ensured comms in place so staff can communicate if all staff wfh • Reviewed cyber arrangements so systems stay secure in mass-staff absences • Internal comms regarding medical advice & company procedures given to staff • Established IT helpdesk/upscaled existing to allow increased reliance on technology • Ensured external comms plan in place should a staff become infected • …
  • 19. 5. Supply Chain • Identified a list of critical suppliers in response to COVID-19 • Maintained regular communications with suppliers • Reviewed the business continuity plans of key suppliers to ensure continuity of service • Prioritised suppliers for review based on operating location • …
  • 20. 6. Business Continuity Plans • Have a validated information source which is monitored daily • Ensured incident management teams are meeting regularly • Activated Incident Management teams to manage the business disruption • Considered how sustainable the business continuity response is • Ensured all plans have been reviewed to reflect the current circumstances • Reviewed the BIA to reflect changing priorities given prolonged impact of COVID-19 • Undertaken scenario analysis to identify range of potential outcomes/est. impacts • Undertaken financial modelling to determine how the organization will be affected post- COVID • Conducted horizon scanning for other risks that may materialize during the pandemic • …
  • 21. ISO/IEC 22301 Training Courses • ISO 22301 Introduction 1 Day Course • ISO 22301 Foundation 2 Days Course • ISO 22301 Lead Implementer 5 Days Course • ISO 22301 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 22301 www.pecb.com/events