SlideShare a Scribd company logo
1 of 29
Presenter:
Ms Rinske Geerlings
MD, Founder and
Principal Consultant/
Trainer @ Business As
Usual
Risk Consultant of the
Year 2017 (RMIA)
Outstanding Security
Consultant of the Year
2019 (OSPAs Finalist)
Business Continuity Planning (BCP) – Virtual seminar
Using lessons learned from Covid-19 to
improve your future ‘business as usual’
Interactive session
Using lessons learned from Covid-19 to improve
your future ‘business as usual’
First question:
Who has been
capturing lessons
learned and
future
improvements,
whilst the
lockdown was
ongoing?
Using lessons learned to achieve an improved ‘business as usual’
1. Innovations
 Brainstorm with your team about new service
offerings and methods you could choose during
future disruptions (e.g. online, from different
location, using different production facilities
or supply chains)
 Review responses from your customers,
suppliers and other stakeholders to any new
products/methods you’ve developed since
COVID-19
 Identify potential improvements to productivity/efficiency, e.g. reduction in staff
travel, less need for specific office space, change in office layout, more automation,
different staff shifts, cheaper/better ways to outsource or (on the contrary) bring
activities in-house
Case studies
Question
“Which tools have you implemented to optimise your remote work
technology (e.g. network connectivity at home, device security, phone
diversion procedures, etc) and which can you retain to work more effectively
in your new ”business as usual?”
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a strategy to ensure staff comfort
and productivity during disruptions
 Make sure managers are available in case
staff need extra support
 Build stock and a fast roll-out process for
any tools that staff may need in order to
work during a disruption, e.g. two-way
radios, spare laptops, spare mobile handsets,
pre-loaded SIM cards, mobile internet modems, headsets, phone diversion
procedures, remote voice mail set-up instructions etc
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a template for centralised
communication via email/SMS/other tool,
in order to ensure all staff are headed in
the same direction during incidents
 Explore the best practices regarding holding
daily ‘huddles’ with staff during disruptions,
in case you are unable to all work from the
same location
 Discuss how these can be applied during business as usual
Question
“How are you staying
productive during a disruption,
if you are unable to sit
together with colleagues?
What are your key challenges
in this context?”
Using lessons learned to achieve an improved ‘business as usual’
3. External collaboration
 Identify which tools your suppliers,
clients and other counterparts preferred
during the lockdown (e.g. in the event of
Internet downtime, mobile network
outages or work from home situations)
 Implement and test related collaboration
tools and arrange for licensing,
installation and staff training so you are
ready to seamlessly keep sales/orders
and customer support going
Question
“If Internet and mobile telephony
were to go down for 1-2 days,
what does your BCP say?”
4. The actual transition to ‘the new normal’
 Move back by department, office/floor,
business process or technology used?
 Properly identify if return-to-work on certain
days of the week by certain staff actually
achieves the intended benefits (and doesn’t
complicate things)
 Ensure appropriate stages for facilities, HR
and IT to manage the transition including
proper testing
Using lessons learned to achieve an improved ‘business as usual’
Using lessons learned to improve your new ‘business as usual’
5. Better risk management
Revisit information sharing policies/controls in the event of a disruption, e.g.
 Secure network connectivity (incl WPS2 protection)
 Remote access software (e.g. VPN) including licences
 Patching of operating systems and ensure endpoint security (e.g. malware/virus
scanners)
 Provide regular reminders about information security to staff
 Conduct an ISO 27001 gap analysis
Revisit your Business Continuity Plan (BCP)
 Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain
disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT
system failure)
 Regularly walk-through/test your disruption scenarios
 Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and
regular ‘mini invocations’
 Less is more – Reduce document volume and make it easy to maintain
 Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and
gaming techniques including ‘red teaming’
 Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’
 Global best practice: For proper BCP as with DR, Risk Management and Security),
apply up-to-date principles/strategies (and standards!)
Making Business Continuity plans that actually work when you
need them most
• Philosophy of resilient networks
• What is different ?
• How do they work ?
• Why is it better than classic networks ?
• And all of your questions !
The topic of 2day
How to create resilience ?
We work in silos
BCP
How to create resilience ?
Multi silos in organisations
BCP
How to create resilience ?
Multi organisations in networks
BCP
BCP
BCP
BCP
BCP
BCP
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
What is resilience in this context ?
€ €
products/
services
products/
services
Take a simple chain
Examples of non resilience in chains:
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
‘Me, myself and I’ control =
the answer to all mishaps
8020
Increased risk at
customer level,
lower resilience
We need another direction !
Classic reaction to build resilience:
Risk
Costs
Quality
Profit
Statement:
The better you are, the
simpler the world, the
more resilient you are
energy,
costs,
risks
# learning cycles
complex
simple
Based on Resource Based View, Barney, 1991, and all later versions
New reaction to build resilience:
Add ‘expertise’ thinking:
Customer
100 % value
integrator
These networks are faster, cheaper, better (Q)
Based on Wouter Beelaerts, 2010
18 %
18 %
13 %
9 %
18 %
13 %
Profit = up
10 %
Resilience = up
Change the network for resilience:
utilise expertise
Next step: embrace dependency:
Resilient Customer
value
integrator
Resilience =
further up
Results in the integrator being a
resilience hub:
Resilient Supplier
value
goods & services
information & money
Remarkable results:
• speed to market: up
• total cost: down
• network profit: up
• network agility: up
• network resilience: up
Building the
resilient network
Conclusion:
classic networks F, C, B networks
embrace
dependency
Resilient
Customer
value
integrat
or
Resilient
Supplier
value
the resilient network
 Start talking about dependency with your network partners
 Add the outcome to your BCP !
Simple to start:
ISO 22301
Training Courses
• ISO 22301 Introduction
1 Day Course
• ISO 22301 Foundation
2 Days Course
• ISO 22301 Lead Implementer
5 Days Course
• ISO 22301 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
22301
www.pecb.com/events
THANK YOU
?
rinske@businessasusual.com.au
santema@scenter.nl
linkedin.com/in/businessasusual/
linkedin.com/in/siccosantema
www.businessasusual.com.au
www.scenter.nl

More Related Content

What's hot

Impact of fin-tech or financial technology
Impact of fin-tech or financial technology Impact of fin-tech or financial technology
Impact of fin-tech or financial technology Pankaj Bhaydiya
 
Digital banking
Digital banking Digital banking
Digital banking VIPIN KP
 
Fintech Simplified
Fintech SimplifiedFintech Simplified
Fintech SimplifiediHashmi ...
 
presentation on a successful entrepreneur
presentation on a successful entrepreneur presentation on a successful entrepreneur
presentation on a successful entrepreneur Al Shahriar
 
Digital transformation of the banking industry
Digital transformation of the banking industry Digital transformation of the banking industry
Digital transformation of the banking industry Frank Schwab
 
Fintech and Transformation of the Financial Services Industry
Fintech and Transformation of the Financial Services IndustryFintech and Transformation of the Financial Services Industry
Fintech and Transformation of the Financial Services IndustryRobin Teigland
 
Myntra e business presentation
Myntra e business presentationMyntra e business presentation
Myntra e business presentationSaumya Jha
 
Presentation On Flipkart
Presentation On FlipkartPresentation On Flipkart
Presentation On FlipkartJayUSoni
 
The Inevitable Future of Banking
The Inevitable Future of BankingThe Inevitable Future of Banking
The Inevitable Future of Bankingaccenture
 
PowerPoint Presentation on Meesho
PowerPoint Presentation on MeeshoPowerPoint Presentation on Meesho
PowerPoint Presentation on MeeshoSmritiSingh184
 
Entrepreneurship and sustainable development
Entrepreneurship and sustainable developmentEntrepreneurship and sustainable development
Entrepreneurship and sustainable developmentTecnológico de Monterrey
 
TOP 10 YOUNG ENTREPRENEURS FROM INDIA
TOP 10 YOUNG ENTREPRENEURS FROM INDIATOP 10 YOUNG ENTREPRENEURS FROM INDIA
TOP 10 YOUNG ENTREPRENEURS FROM INDIAKaranMere2
 
Suchi Mukherjee (Founder & CEO LIMEROAD)
Suchi Mukherjee (Founder & CEO LIMEROAD)Suchi Mukherjee (Founder & CEO LIMEROAD)
Suchi Mukherjee (Founder & CEO LIMEROAD)Asaf09MBA2021
 

What's hot (20)

Impact of fin-tech or financial technology
Impact of fin-tech or financial technology Impact of fin-tech or financial technology
Impact of fin-tech or financial technology
 
Anand mahindra
Anand mahindraAnand mahindra
Anand mahindra
 
Digital banking
Digital banking Digital banking
Digital banking
 
Fintech Simplified
Fintech SimplifiedFintech Simplified
Fintech Simplified
 
Fintech in india
Fintech in indiaFintech in india
Fintech in india
 
presentation on a successful entrepreneur
presentation on a successful entrepreneur presentation on a successful entrepreneur
presentation on a successful entrepreneur
 
Digital transformation of the banking industry
Digital transformation of the banking industry Digital transformation of the banking industry
Digital transformation of the banking industry
 
Fintech and Transformation of the Financial Services Industry
Fintech and Transformation of the Financial Services IndustryFintech and Transformation of the Financial Services Industry
Fintech and Transformation of the Financial Services Industry
 
Infosys ppt
Infosys pptInfosys ppt
Infosys ppt
 
Myntra e business presentation
Myntra e business presentationMyntra e business presentation
Myntra e business presentation
 
Presentation On Flipkart
Presentation On FlipkartPresentation On Flipkart
Presentation On Flipkart
 
TESCO SWOT Analysis 2019
TESCO SWOT Analysis 2019TESCO SWOT Analysis 2019
TESCO SWOT Analysis 2019
 
The Inevitable Future of Banking
The Inevitable Future of BankingThe Inevitable Future of Banking
The Inevitable Future of Banking
 
PowerPoint Presentation on Meesho
PowerPoint Presentation on MeeshoPowerPoint Presentation on Meesho
PowerPoint Presentation on Meesho
 
Ppt on Byju
Ppt on ByjuPpt on Byju
Ppt on Byju
 
Entrepreneurship and sustainable development
Entrepreneurship and sustainable developmentEntrepreneurship and sustainable development
Entrepreneurship and sustainable development
 
TOP 10 YOUNG ENTREPRENEURS FROM INDIA
TOP 10 YOUNG ENTREPRENEURS FROM INDIATOP 10 YOUNG ENTREPRENEURS FROM INDIA
TOP 10 YOUNG ENTREPRENEURS FROM INDIA
 
Suchi Mukherjee (Founder & CEO LIMEROAD)
Suchi Mukherjee (Founder & CEO LIMEROAD)Suchi Mukherjee (Founder & CEO LIMEROAD)
Suchi Mukherjee (Founder & CEO LIMEROAD)
 
CSR for sustainable business
CSR  for sustainable businessCSR  for sustainable business
CSR for sustainable business
 
Fintech introduction
Fintech introductionFintech introduction
Fintech introduction
 

Similar to Moving to a New "Business as Usual" after COVID-19

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17jekroggel
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...360 BSI
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplacePaperjam_redaction
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Net at Work
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetAshley Deuble
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)AdaCore
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attranhcrowley
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations managementsmumbahelp
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profilescottsdale
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profilescottsdale
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 

Similar to Moving to a New "Business as Usual" after COVID-19 (20)

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17
 
Stabilizing Revenue
Stabilizing RevenueStabilizing Revenue
Stabilizing Revenue
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplace
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budget
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft Services
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attr
 
resume_alcantara
resume_alcantararesume_alcantara
resume_alcantara
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations management
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profile
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profile
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Recently uploaded

Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfadityarao40181
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfMahmoud M. Sallam
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17Celine George
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)eniolaolutunde
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfSumit Tiwari
 
EPANDING THE CONTENT OF AN OUTLINE using notes.pptx
EPANDING THE CONTENT OF AN OUTLINE using notes.pptxEPANDING THE CONTENT OF AN OUTLINE using notes.pptx
EPANDING THE CONTENT OF AN OUTLINE using notes.pptxRaymartEstabillo3
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsKarinaGenton
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTiammrhaywood
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaVirag Sontakke
 
History Class XII Ch. 3 Kinship, Caste and Class (1).pptx
History Class XII Ch. 3 Kinship, Caste and Class (1).pptxHistory Class XII Ch. 3 Kinship, Caste and Class (1).pptx
History Class XII Ch. 3 Kinship, Caste and Class (1).pptxsocialsciencegdgrohi
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxAvyJaneVismanos
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformChameera Dedduwage
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentInMediaRes1
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,Virag Sontakke
 

Recently uploaded (20)

Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdf
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdf
 
How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17How to Configure Email Server in Odoo 17
How to Configure Email Server in Odoo 17
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
 
EPANDING THE CONTENT OF AN OUTLINE using notes.pptx
EPANDING THE CONTENT OF AN OUTLINE using notes.pptxEPANDING THE CONTENT OF AN OUTLINE using notes.pptx
EPANDING THE CONTENT OF AN OUTLINE using notes.pptx
 
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its Characteristics
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of India
 
History Class XII Ch. 3 Kinship, Caste and Class (1).pptx
History Class XII Ch. 3 Kinship, Caste and Class (1).pptxHistory Class XII Ch. 3 Kinship, Caste and Class (1).pptx
History Class XII Ch. 3 Kinship, Caste and Class (1).pptx
 
Final demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptxFinal demo Grade 9 for demo Plan dessert.pptx
Final demo Grade 9 for demo Plan dessert.pptx
 
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Bikash Puri  Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Bikash Puri Delhi reach out to us at 🔝9953056974🔝
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy Reform
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media Component
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
 

Moving to a New "Business as Usual" after COVID-19

  • 1.
  • 2. Presenter: Ms Rinske Geerlings MD, Founder and Principal Consultant/ Trainer @ Business As Usual Risk Consultant of the Year 2017 (RMIA) Outstanding Security Consultant of the Year 2019 (OSPAs Finalist) Business Continuity Planning (BCP) – Virtual seminar Using lessons learned from Covid-19 to improve your future ‘business as usual’ Interactive session
  • 3. Using lessons learned from Covid-19 to improve your future ‘business as usual’ First question: Who has been capturing lessons learned and future improvements, whilst the lockdown was ongoing?
  • 4. Using lessons learned to achieve an improved ‘business as usual’ 1. Innovations  Brainstorm with your team about new service offerings and methods you could choose during future disruptions (e.g. online, from different location, using different production facilities or supply chains)  Review responses from your customers, suppliers and other stakeholders to any new products/methods you’ve developed since COVID-19  Identify potential improvements to productivity/efficiency, e.g. reduction in staff travel, less need for specific office space, change in office layout, more automation, different staff shifts, cheaper/better ways to outsource or (on the contrary) bring activities in-house
  • 6. Question “Which tools have you implemented to optimise your remote work technology (e.g. network connectivity at home, device security, phone diversion procedures, etc) and which can you retain to work more effectively in your new ”business as usual?”
  • 7. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a strategy to ensure staff comfort and productivity during disruptions  Make sure managers are available in case staff need extra support  Build stock and a fast roll-out process for any tools that staff may need in order to work during a disruption, e.g. two-way radios, spare laptops, spare mobile handsets, pre-loaded SIM cards, mobile internet modems, headsets, phone diversion procedures, remote voice mail set-up instructions etc
  • 8. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a template for centralised communication via email/SMS/other tool, in order to ensure all staff are headed in the same direction during incidents  Explore the best practices regarding holding daily ‘huddles’ with staff during disruptions, in case you are unable to all work from the same location  Discuss how these can be applied during business as usual
  • 9. Question “How are you staying productive during a disruption, if you are unable to sit together with colleagues? What are your key challenges in this context?”
  • 10. Using lessons learned to achieve an improved ‘business as usual’ 3. External collaboration  Identify which tools your suppliers, clients and other counterparts preferred during the lockdown (e.g. in the event of Internet downtime, mobile network outages or work from home situations)  Implement and test related collaboration tools and arrange for licensing, installation and staff training so you are ready to seamlessly keep sales/orders and customer support going
  • 11. Question “If Internet and mobile telephony were to go down for 1-2 days, what does your BCP say?”
  • 12. 4. The actual transition to ‘the new normal’  Move back by department, office/floor, business process or technology used?  Properly identify if return-to-work on certain days of the week by certain staff actually achieves the intended benefits (and doesn’t complicate things)  Ensure appropriate stages for facilities, HR and IT to manage the transition including proper testing Using lessons learned to achieve an improved ‘business as usual’
  • 13. Using lessons learned to improve your new ‘business as usual’ 5. Better risk management Revisit information sharing policies/controls in the event of a disruption, e.g.  Secure network connectivity (incl WPS2 protection)  Remote access software (e.g. VPN) including licences  Patching of operating systems and ensure endpoint security (e.g. malware/virus scanners)  Provide regular reminders about information security to staff  Conduct an ISO 27001 gap analysis Revisit your Business Continuity Plan (BCP)  Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT system failure)  Regularly walk-through/test your disruption scenarios
  • 14.  Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and regular ‘mini invocations’  Less is more – Reduce document volume and make it easy to maintain  Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and gaming techniques including ‘red teaming’  Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’  Global best practice: For proper BCP as with DR, Risk Management and Security), apply up-to-date principles/strategies (and standards!) Making Business Continuity plans that actually work when you need them most
  • 15. • Philosophy of resilient networks • What is different ? • How do they work ? • Why is it better than classic networks ? • And all of your questions ! The topic of 2day
  • 16. How to create resilience ? We work in silos BCP
  • 17. How to create resilience ? Multi silos in organisations BCP
  • 18. How to create resilience ? Multi organisations in networks BCP BCP BCP BCP BCP BCP
  • 19. Customer 100 % value Suppliers 60 % value OEM 40 % value What is resilience in this context ? € € products/ services products/ services Take a simple chain
  • 20. Examples of non resilience in chains:
  • 21. Customer 100 % value Suppliers 60 % value OEM 40 % value ‘Me, myself and I’ control = the answer to all mishaps 8020 Increased risk at customer level, lower resilience We need another direction ! Classic reaction to build resilience:
  • 22. Risk Costs Quality Profit Statement: The better you are, the simpler the world, the more resilient you are energy, costs, risks # learning cycles complex simple Based on Resource Based View, Barney, 1991, and all later versions New reaction to build resilience: Add ‘expertise’ thinking:
  • 23. Customer 100 % value integrator These networks are faster, cheaper, better (Q) Based on Wouter Beelaerts, 2010 18 % 18 % 13 % 9 % 18 % 13 % Profit = up 10 % Resilience = up Change the network for resilience: utilise expertise
  • 24. Next step: embrace dependency:
  • 25. Resilient Customer value integrator Resilience = further up Results in the integrator being a resilience hub: Resilient Supplier value goods & services information & money Remarkable results: • speed to market: up • total cost: down • network profit: up • network agility: up • network resilience: up
  • 26. Building the resilient network Conclusion: classic networks F, C, B networks embrace dependency Resilient Customer value integrat or Resilient Supplier value the resilient network
  • 27.  Start talking about dependency with your network partners  Add the outcome to your BCP ! Simple to start:
  • 28. ISO 22301 Training Courses • ISO 22301 Introduction 1 Day Course • ISO 22301 Foundation 2 Days Course • ISO 22301 Lead Implementer 5 Days Course • ISO 22301 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 22301 www.pecb.com/events