SlideShare a Scribd company logo
Organisational Resilience
 Are you using it?
 Do you understand it?
 Where does it fit in at Work?
This Organisational Resilience paper seeks to move resilience from being a ‘back room’ issue to being a strategic one,
taken up and regularly debated at the highest levels within an organisation.
What does organisational resilience mean?
There are a few different interpretations out there even from various Organisations responsible to set Standards in
their related Country:
British Standard, (BSI) BS65000 (2014) defines "organisational resilience"
 The "ability of an organization to anticipate, prepare for, and respond and adapt to incremental change and
sudden disruptions in order to survive and prosper."
ISO is about to release its first Standard for Organisational Resilience around June/July 2016 and it is using this
definition.
 Organisational Resilience is the ability of an organisation to respond and adapt to change. Resilience enables
organisation to articulate and respond to threats and opportunities, arising from sudden or gradual changes
in their internal and external context. Enhancing resilience should be a strategic organisational goal.
Gartner (Jan 2002) describes organisational Resilience as
Organizational resilience has taken on a new urgency since the tragic events of Sept. 11. The ability to respond
quickly, decisively and effectively to unforeseen and unpredictable forces is now an enterprise imperative
However I prefer this more generic definition that refers to resilience:
As the ability of a business or system to absorb change gracefully whilst retaining core properties or functions and to
adopt to new evolving capabilities or opportunities.
What does resilience mean to an organisation?
Organisations deal with uncertainties and unexpected events all the time, and managing these is part of doing
business. Above a certain scale however, crisis events differ from day-to-day management, in that organisations
have to operate out of their comfort zone, interact with organisations they do not normally work alongside, and
have to make and share strategic decisions quickly and effectively. Being able to respond effectively to crisis events
is a real test of what makes an organisation ‘tick’.
Companies are faced with an ever growing threat to its survival every day, and I’m not referring to having to
compete with other companies in its chosen market sector which we would be in that case discussing its business
and or trading competitiveness and its resilience to shifting market trends, advancing technologies and product /
process improvements.
In this case I’m referring to many threats and impacts from the digital and technology worlds. Cyber threats &
attacks, hacking from various antibusiness organisations, terrorists groups, and maybe even competitors or foreign
organisation. Not to mention Mother Nature and her ever changing cycles that cause enormous disruption mostly to
the organisations reliance on technology
Organisational Resilience is a relative and dynamic concept rather than a specific activity or fixed state. There are
often many factors that when combined, enhance an organisations resilience and these can also be unique to each
and every different organisation. Even 2 organisations trading in the same market sector link Banks or
Telecommunication companies will both have variations to its own ability to be Resilient.
Now we all realise that organisations all over the world have to deal with uncertainties and unexpected
events all the time, and managing these presents both opportunities and risks for the organisation. Given
this situation is often a daily or weekly event, it is also given that some of these events will be minor and
some major, above a certain scale however, crisis events differ from day-to-day management, in that
organisations have to operate out of their comfort zone, interact with organisations they do not normally
work alongside, and have to make and share strategic decisions quickly and effectively. Being able to
respond effectively to crisis events is a real test of what makes an organisation ‘tick’
Many organisations have established disciplines, frameworks, management processes and policies that all
would be used to contribute to dealing with these various events and depending on that scale or size, there
are various level of management that are required to be involved.
Including in these frameworks and policies are:
 Strategic Planning
 Financial Planning
 Risk Management,
 Business Continuity Management
 Crisis Management
 ICT Disaster Recovery Management and ICT Continuity Management
 Security Management
These various management disciplines in isolation are insufficient to safeguard an organisations future.
In developing a Strategy or Framework for Organisational Resilience it is not the intent to replace any of these
disciplines, instead it provides a framework and set of principles to integrate and coordinate these disciplines
alongside a wider set of attributes and related principles that enhance the maturity of the organisations resilience.
[See Figure 1A]
In developing a Framework to enable the organisation to establish and maintain a high level of maturity in its
Organisational Resilience the endorsement and support of top management is required as follows.
Top management commitment to enhance organisational resilience will contribute to:
 improved capacity to anticipate and respond to threats and opportunities;
 An ability to identify and address vulnerabilities before they have a material impact;
 A more coordinated approach to integrate existing management disciplines that support organisational
resilience; and
 A greater understanding of interested parties and dependencies that support strategic goals and objectives.
A couple of important notations to consider when understanding the correct context in which the above points are
meant.
1: Objectives refers to the means by which an organisation implements its purpose and vision. Objectives may be at a strategic level set by top
management or at a lower level in structure.
2: Purpose and vision relates to an organisations current and future strategic aim. This includes an organisations mission and goals.
Your Framework should be structured to align with the four parts as shown inFigure1:
1. Principles provide the foundation for enhancing an organisations resilience;
2. Attributes describe the characteristics of an organisation that allow the principles to be achieved;
3. Activities guide the utilization, evaluation and enhancement of attributes: and
4. Disciplines contribute towards the organisations resilience maturity
Figure 1A
The other critical factor to take into account is that these organisations can be MORE or LESS resilient and there is no
single or absolute measure or definitive goal. However many organisations have developed metrics that they can use
to aid and assist in measuring their level of maturity and resilience.
How can POOR Organisational Resilience impact your future survival?
Organisations deal with uncertainties and unexpected events all the time, and managing these presents both
opportunities and risks for the organisation. These events range in size and therefore range in capacity to impact
your organisation, it there will also require different levels of management to make decisions and enact relevant
policies and procedures to protect the organisation.
Above a certain scale however, crisis events differ from day-to-day management, in that organisations have to
operate out of their comfort zone, interact with organisations they do not normally work alongside, and have to
make and share strategic decisions quickly and effectively.
As many of us already know, a company’s success can be partially measured on it being able to respond effectively
to crisis events and it is also a real test of what makes an organisation ‘tick’.
Let’s look at major events last decade.
The economic implications of organisations being unprepared for crises are significant. In the September 11th
attacks, business interruption losses far exceeded the sum of all property losses. In our increasingly interconnected
business environment, consequences go well beyond the zone of any physical damage, affecting businesses right
along the supply chain.
A second major event in USA was a failure of Power Supplies with a domino effect State by State
In Australia just like in Europe and USA, mother nature brings havoc in the form of fires, floods and some regions
earthquakes, these all are NOT planned or pre-arranged with dates set but we do know they will happen.
An organisation’s ability to survive a major crisis depends on their organisational structure, the management and
operational systems they have in place, and the resilience of these and also their suppliers, partners and thier
employee’s.
Our world and the fast moving global disruptions (we once called a war)
In recent years we have seen how the world is being challenged in cyberspace and the impact certain Anti Terrorists
groups can have on an organisation, yes many of us just say they are at war with certain countries with opposing
religious beliefs. WRONG
So some organisations may think they are not going to be affected as the war on the ground with troops etc. is not in
their state, region or maybe even country. WRONG
However, they fight their war on many different fronts and using many different techniques to win and dominate.
They plan disruption of organisations and governments that support the cause of their stated enemies. They don’t
use tanks and fighter planes to accomplish this. War over the internet, electronic data attacks, disruption of
production lines caused via computer systems. Destroying a major power source are all technics that can be
conducted almost anywhere in the world and often just from a Laptop computer.
For any CEO or organisations executive management team to take a view it won’t happen to us or the chance of it
happening is extremely low, is simply not acceptable, they may even decide the risk of it happening or causing a
major disruption is something we are prepared to live with, well in fact it is NOT their decision, they are often
accountable to stockholders / shareholders / partners / investors who will want to know their investment is safe or
what plans do you have in place to provide maximum resilience?
Many organisations are using existing management disciplines to enable a degree of Organisational resilience, while
this is a good start it is not sufficient or sustainable.
Example:
Risk management is being used more extensively in organisations today, there are few organisations that apply risk
management at a strategic level across the organisation. We are seeing that the uptake of business continuity and
emergency planning is ever increasing, but still only a small proportion of organisations have any real integrated
sustainable resilience planning in place.
Those organisations that do have plans often lack the depth required to sustain a prolonged response capability. In
many resilience issues it can be seen across organisational boundaries, much of the planning being done is very
inward looking as many consider internal organisation is more critical, however they need to understand that
external planning is potentially more important for sustainability.
One of the biggest potentials for forward progress is to get organisations working together to manage risks across
this interface (external), and developing and practicing strategies for working together during crises. This is
particularly needed where outsourcing means that contracted organisations are relied upon to deliver critical
services or supplies. Many organisations outsource key corporate functions as a method to save money, provide cost
efficient services and manage operational costs. However there is a clear and defined impact here without adequate
coverage for Resilience of your suppliers and 3rd
party partners that they have contracted to supply there outsourced
services.
Information Technology is seen today as the foundations of a business, as the enabler of a successful business, the
“business” cannot survive without these critical service but it is often these crucial services that are outsourced and
the organisation does not understand or often seek to understand the level of “Organisational Resilience” that 3rd
party organisation has itself in order to protect its clients services.
Data Centre services are outsources, call centre services are outsources, and entire IT support services are
outsources and are often run from a location outside the country the client organisation operates in. While these
may appear to be cost saving measures, the potential for a major disaster has increased dramatically and no one in
the executive management team has undertaken any assessment as to their supplies own Organisational Resilience.
In our modern Technology World today we find ever and ever increasing range of services now being provided “In
the Cloud”.
 How do you assess their Organisational Resilience?
 Do you even know where their infrastructure is located?
 Who else has access to it?
Does Organisational Resilience replace Risk management or Business Continuity Management? No
Organizational Resilience is a strategic imperative for an organization to prosper in today’s dynamic, interconnected
world. It is not a one-off exercise, but achieved over time and for the long-term. Mastering Organisational
Resilience requires the adoption of excellent habits and best practice to deliver business improvement by building
competence and capability across all aspects of an organization. This allows leaders to take measured risks with
confidence, making the most of opportunities that present themselves. Risk Management and Business Continuity
Management are critical enablers of developing strong and mature organisational resilience.
How resilient is your Department, Company, Association or Organisation
In developing a methodology to assess How Resilient is an Organisation, we evaluate an organisation’s resilience on
four dimensions:
 its situation awareness of both its own operations and the environment within which it operates,
 how well it understands and manages its keystone vulnerabilities,
 the organisation’s adaptive capacity, its attitude and ability to cope with change.
 Organisations Commitment to Resilience and Sustainability
Resilience is about ensuring that an organisation is still able to achieve its core objectives in the face of adversity.
This means not only reducing the size and frequency of crises, but also improving the ability and speed of the
organisation to manage crises effectively. To be truly resilient an organisation also has to constantly be aware and
evolve in response to its changing environment and to seek out opportunities even in times of crisis.
The are some basic fundamental requirements to enable an organisation to achieve a mature level of Resiliency
 A common objective is enabling different parts of the organisation to work together to achieve a common
objective. – No Silo Management
 Giving some of its less tangible aspects of an organisation that relate to its culture, leadership and vision a
higher priority of focus
 Important qualities such as good communication and relationships within the organisation
 This also applies external communications with key customers and stakeholders, business partners and even
joint venture stakeholders
 Establishing trust, and a shared vision
The above criteria is usually treated as important to an organisation during its BAU (Business As Usual) periods.
However it is CRITICAL at times of crisis when it is often the informal networks and relationships (who you know that
you can call on for a favour…) that count.
The culture of the organisation and recognising the strengths and weaknesses that culture brings to the organisation
in times of crisis is a critical contributing process when building the Resilience of an organisation
Situation Awareness
There are many definitions of Situation Awareness, some come from ancient eastern practices, mind development,
the Military use many forms of this in their training, however for Organisational Resilience it has to core meanings,
[1] being aware of what is happening around you and understanding what that information means to you now and in
the future [2] the same applies to organisations however in additional to what is described inn point 1, it also
requires the organisation to understand, assimilate, and act on large volumes of information to perform and
maintain organisation resilience
Keystone vulnerability
In an assessment a critical area for validation is what qualifies a particular vulnerability as a keystone vulnerability
and note other uses of the term keystone: ecological and architectural. They go on to define keystone vulnerabilities
as “...components in the organizational system, which by their loss or impairment have the potential to cause
exceptional effects throughout the system” This is also addressed within the field of business continuity
management where organizations aim to identify and assess potential single points of failure, such as a single source
supplier or resource, through business impact analyses
Adaptive capacity
An organisation’s ability to adapt is at the heart of its ability to display resilient characteristics.
An organisation’s adaptive capacity is their ability to continuously design and develop solutions to match or exceed
the needs of their environment as changes in that environment emerge. What is often referred to as Continuous
Improvement, many organisation do not have clearly defined policies regarding Continuous Improvement thus it has
a direct impact on their Adaptive Capacity.
So back to the basics – Why Resilience is important?
Why resilience is important?
The business environment is fast becoming more interconnected, unpredictable and volatile and the consequences
of external events more substantial. If you respond too late or inappropriately, you risk getting left behind.
There are a number of phenomena that executives and managers may need to be aware in their strategic planning
activity such as:
- Faster and multi-faceted change
Today’s businesses are affected by changes in their political, natural and social contexts.
- Environmental changes
Environmental changes, such as global warming, are becoming a major threat to some sectors, and not just the ones
that immediately come to mind.
- Large scale mergers and acquisitions
Global organisations have wide influence, concentrating resources and even superseding some countries’ internal
product.
- Faster career transitions
Individuals in organisations are less ‘steady state’: faster career transitions are occurring, and more often than ever
before individuals are changing roles within a given organisation and across various firms.
- Unprecedented advances in Information Technologies
New information technologies are creating new communications channels, shifting consumer patterns and new
social ways of linking up.
Taking Action on Organisational Resilience
The key to developing organisational resilience is making second nature the capability to adapt and recover. In this
way, it becomes dynamic, self – organising and deeply ingrained into the organisation’s day-to-day operations, and
the way it does business.
Summary:
Unfortunately, there is no ‘silver bullet’; resilience is something that an organisation must continually work at.
But because it is so intrinsically related to the day-to-day ethos of the organisation, it can also create significant
payback in terms of helping to refocus on what is important to the organisation and creating a shared understanding
of the roles people play in making those a reality.
Most importantly, resilience needs to move from being a ‘back room’ issue to being a strategic one and be regularly
debated as part of strategic planning for any organisation
While you may not have a Silver Bullet, if you adopt the model below you will get a Sustainable Resilient
Organisation
Organisational Resilience Paper v0.021

More Related Content

What's hot

Energy Risk Management
Energy Risk Management  Energy Risk Management
Energy Risk Management
MetricStream Inc
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
Andrew Smart
 
New Risk Management Paradigm for Not-For-Profits
New Risk Management Paradigm for Not-For-ProfitsNew Risk Management Paradigm for Not-For-Profits
New Risk Management Paradigm for Not-For-Profits
David X Martin
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational Risk
Andrew Smart
 
Building intrinsic organisation resilience 2021
Building intrinsic organisation resilience 2021Building intrinsic organisation resilience 2021
Building intrinsic organisation resilience 2021
Strategic Business & IT Services
 
Risk Management Infographic
Risk Management InfographicRisk Management Infographic
Risk Management Infographic
SAP Analytics
 
The Risk Earnings Ratio
The Risk Earnings RatioThe Risk Earnings Ratio
The Risk Earnings Ratio
Simon Baker-Chambers
 
CROs must be part of the cybersecurity solution by david x martin
CROs must be part of the cybersecurity solution by david x martinCROs must be part of the cybersecurity solution by david x martin
CROs must be part of the cybersecurity solution by david x martin
David X Martin
 
B288
B288B288
What Is Corporate Resilience
What Is Corporate ResilienceWhat Is Corporate Resilience
What Is Corporate ResilienceBBRAES
 
Erm Presentation Bsw Approach & Methodology
Erm Presentation   Bsw Approach & MethodologyErm Presentation   Bsw Approach & Methodology
Erm Presentation Bsw Approach & Methodology
steinkamps6
 
Improving organizational resilience
Improving organizational resilienceImproving organizational resilience
Improving organizational resilience
salmah natoon
 
Proposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesProposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesRahul Bhan (CA, CIA, MBA)
 
Proposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesProposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesRahul Bhan (CA, CIA, MBA)
 
Risk Management Lessons From The Current Crisis Ppt2003
Risk Management Lessons From The Current Crisis Ppt2003Risk Management Lessons From The Current Crisis Ppt2003
Risk Management Lessons From The Current Crisis Ppt2003Barry Schachter
 
The Resilient Organisation
The Resilient OrganisationThe Resilient Organisation
The Resilient Organisation
PipTheoZach64_
 
Risk Management in Business
Risk Management in BusinessRisk Management in Business
Risk Management in Business
paperpublications3
 
Building Organisational Resilience
Building Organisational ResilienceBuilding Organisational Resilience
Building Organisational Resilience
Atul
 
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
Integrating Enterprise Risk Management (ERM) with Organizational StrategyIntegrating Enterprise Risk Management (ERM) with Organizational Strategy
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
henrytk2
 
Mckinley Woods Structural Implications
Mckinley Woods Structural ImplicationsMckinley Woods Structural Implications
Mckinley Woods Structural Implications
MckinleyWoods
 

What's hot (20)

Energy Risk Management
Energy Risk Management  Energy Risk Management
Energy Risk Management
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
 
New Risk Management Paradigm for Not-For-Profits
New Risk Management Paradigm for Not-For-ProfitsNew Risk Management Paradigm for Not-For-Profits
New Risk Management Paradigm for Not-For-Profits
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational Risk
 
Building intrinsic organisation resilience 2021
Building intrinsic organisation resilience 2021Building intrinsic organisation resilience 2021
Building intrinsic organisation resilience 2021
 
Risk Management Infographic
Risk Management InfographicRisk Management Infographic
Risk Management Infographic
 
The Risk Earnings Ratio
The Risk Earnings RatioThe Risk Earnings Ratio
The Risk Earnings Ratio
 
CROs must be part of the cybersecurity solution by david x martin
CROs must be part of the cybersecurity solution by david x martinCROs must be part of the cybersecurity solution by david x martin
CROs must be part of the cybersecurity solution by david x martin
 
B288
B288B288
B288
 
What Is Corporate Resilience
What Is Corporate ResilienceWhat Is Corporate Resilience
What Is Corporate Resilience
 
Erm Presentation Bsw Approach & Methodology
Erm Presentation   Bsw Approach & MethodologyErm Presentation   Bsw Approach & Methodology
Erm Presentation Bsw Approach & Methodology
 
Improving organizational resilience
Improving organizational resilienceImproving organizational resilience
Improving organizational resilience
 
Proposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesProposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management Services
 
Proposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management ServicesProposal To Chairman For Risk Management Services
Proposal To Chairman For Risk Management Services
 
Risk Management Lessons From The Current Crisis Ppt2003
Risk Management Lessons From The Current Crisis Ppt2003Risk Management Lessons From The Current Crisis Ppt2003
Risk Management Lessons From The Current Crisis Ppt2003
 
The Resilient Organisation
The Resilient OrganisationThe Resilient Organisation
The Resilient Organisation
 
Risk Management in Business
Risk Management in BusinessRisk Management in Business
Risk Management in Business
 
Building Organisational Resilience
Building Organisational ResilienceBuilding Organisational Resilience
Building Organisational Resilience
 
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
Integrating Enterprise Risk Management (ERM) with Organizational StrategyIntegrating Enterprise Risk Management (ERM) with Organizational Strategy
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
 
Mckinley Woods Structural Implications
Mckinley Woods Structural ImplicationsMckinley Woods Structural Implications
Mckinley Woods Structural Implications
 

Viewers also liked

Practical Sustainability for the Culture Sector
Practical Sustainability for the Culture SectorPractical Sustainability for the Culture Sector
Practical Sustainability for the Culture Sector
JuhiShareef
 
Resilience, Technology, Sustainability: Competing in the age of disruption, b...
Resilience, Technology, Sustainability: Competing in the age of disruption, b...Resilience, Technology, Sustainability: Competing in the age of disruption, b...
Resilience, Technology, Sustainability: Competing in the age of disruption, b...
Michael D'heur
 
Leading The Resilient Organisation
Leading The Resilient OrganisationLeading The Resilient Organisation
Leading The Resilient OrganisationTeik Oh
 
Propositional Sudy
Propositional SudyPropositional Sudy
Propositional SudyBBRAES
 
Patterns of resilience
Patterns of resiliencePatterns of resilience
Patterns of resilience
Uwe Friedrichsen
 
Business Models for Sustainability
Business Models for SustainabilityBusiness Models for Sustainability
Business Models for Sustainability
Gavin Harper
 
Resilience: how to build resilience in your people and your organization
Resilience: how to build resilience in your people and your organizationResilience: how to build resilience in your people and your organization
Resilience: how to build resilience in your people and your organization
Delta Partners
 
Sustainability Power Point
Sustainability Power PointSustainability Power Point
Sustainability Power Point
HowardLitwak
 
Organisational Sustainability
Organisational SustainabilityOrganisational Sustainability
Organisational Sustainability
David Alman
 

Viewers also liked (11)

Practical Sustainability for the Culture Sector
Practical Sustainability for the Culture SectorPractical Sustainability for the Culture Sector
Practical Sustainability for the Culture Sector
 
Resilience, Technology, Sustainability: Competing in the age of disruption, b...
Resilience, Technology, Sustainability: Competing in the age of disruption, b...Resilience, Technology, Sustainability: Competing in the age of disruption, b...
Resilience, Technology, Sustainability: Competing in the age of disruption, b...
 
Building organisational resilience
Building organisational resilienceBuilding organisational resilience
Building organisational resilience
 
Leading The Resilient Organisation
Leading The Resilient OrganisationLeading The Resilient Organisation
Leading The Resilient Organisation
 
Propositional Sudy
Propositional SudyPropositional Sudy
Propositional Sudy
 
Patterns of resilience
Patterns of resiliencePatterns of resilience
Patterns of resilience
 
Business Models for Sustainability
Business Models for SustainabilityBusiness Models for Sustainability
Business Models for Sustainability
 
What Is Sustainability
What Is SustainabilityWhat Is Sustainability
What Is Sustainability
 
Resilience: how to build resilience in your people and your organization
Resilience: how to build resilience in your people and your organizationResilience: how to build resilience in your people and your organization
Resilience: how to build resilience in your people and your organization
 
Sustainability Power Point
Sustainability Power PointSustainability Power Point
Sustainability Power Point
 
Organisational Sustainability
Organisational SustainabilityOrganisational Sustainability
Organisational Sustainability
 

Similar to Organisational Resilience Paper v0.021

STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
David Denyer
 
Toward True Organizational Resilience | Deloitte’s Global Resilience Report
Toward True Organizational Resilience | Deloitte’s Global Resilience ReportToward True Organizational Resilience | Deloitte’s Global Resilience Report
Toward True Organizational Resilience | Deloitte’s Global Resilience Report
aakash malhotra
 
Global_Resilience_report_October_2022_wc.pdf
Global_Resilience_report_October_2022_wc.pdfGlobal_Resilience_report_October_2022_wc.pdf
Global_Resilience_report_October_2022_wc.pdf
aakash malhotra
 
Two pager Enterprise Resilience
Two pager Enterprise ResilienceTwo pager Enterprise Resilience
Two pager Enterprise ResilienceFriederike Völker
 
Cracking The Organisational Resilience Code
Cracking The Organisational Resilience CodeCracking The Organisational Resilience Code
Cracking The Organisational Resilience Code
Workforce Group
 
Coordinating Security Response and Crisis Management Planning
Coordinating Security Response and Crisis Management PlanningCoordinating Security Response and Crisis Management Planning
Coordinating Security Response and Crisis Management Planning
Cognizant
 
James Trim - Business Continuity Management.pptx
James Trim - Business Continuity Management.pptxJames Trim - Business Continuity Management.pptx
James Trim - Business Continuity Management.pptx
prathmeshwaghmare10
 
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docxSTRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
susanschei
 
Solutions to Managing a Crisis
Solutions to Managing a CrisisSolutions to Managing a Crisis
Solutions to Managing a Crisis
aakash malhotra
 
The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...
Albert Vilariño
 
Module 7_Crisis Resilience.pptx
Module 7_Crisis Resilience.pptxModule 7_Crisis Resilience.pptx
Module 7_Crisis Resilience.pptx
AineHamill
 
OverseeRiskAsNewerMoreComplex
OverseeRiskAsNewerMoreComplexOverseeRiskAsNewerMoreComplex
OverseeRiskAsNewerMoreComplexKashif Ali
 
Time Frame of a Crisis
Time Frame of a CrisisTime Frame of a Crisis
Time Frame of a Crisis
aakash malhotra
 
Build Resilience through Challenging Experiences.pdf
Build Resilience through Challenging Experiences.pdfBuild Resilience through Challenging Experiences.pdf
Build Resilience through Challenging Experiences.pdf
Auraa Image Management & Consulting
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
TanaMaeskm
 
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
CIOWomenMagazine
 
2020 is the year to challenge the NORM
2020 is the year to challenge the NORM2020 is the year to challenge the NORM
2020 is the year to challenge the NORM
The BrainLink Group
 
crisis management.pptx
crisis management.pptxcrisis management.pptx
crisis management.pptx
TriptiPandey50
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB
 
Organization and management(Frontier of Public Administration)
Organization and  management(Frontier of Public Administration)Organization and  management(Frontier of Public Administration)
Organization and management(Frontier of Public Administration)
Suzana Vaidya
 

Similar to Organisational Resilience Paper v0.021 (20)

STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
STAT Part 1: An Introduction to the Strategic Tensions Assessment Tool (STAT)
 
Toward True Organizational Resilience | Deloitte’s Global Resilience Report
Toward True Organizational Resilience | Deloitte’s Global Resilience ReportToward True Organizational Resilience | Deloitte’s Global Resilience Report
Toward True Organizational Resilience | Deloitte’s Global Resilience Report
 
Global_Resilience_report_October_2022_wc.pdf
Global_Resilience_report_October_2022_wc.pdfGlobal_Resilience_report_October_2022_wc.pdf
Global_Resilience_report_October_2022_wc.pdf
 
Two pager Enterprise Resilience
Two pager Enterprise ResilienceTwo pager Enterprise Resilience
Two pager Enterprise Resilience
 
Cracking The Organisational Resilience Code
Cracking The Organisational Resilience CodeCracking The Organisational Resilience Code
Cracking The Organisational Resilience Code
 
Coordinating Security Response and Crisis Management Planning
Coordinating Security Response and Crisis Management PlanningCoordinating Security Response and Crisis Management Planning
Coordinating Security Response and Crisis Management Planning
 
James Trim - Business Continuity Management.pptx
James Trim - Business Continuity Management.pptxJames Trim - Business Continuity Management.pptx
James Trim - Business Continuity Management.pptx
 
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docxSTRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
STRATEGIC PLANNINGManaging Risks A NewFrameworkby Rob.docx
 
Solutions to Managing a Crisis
Solutions to Managing a CrisisSolutions to Managing a Crisis
Solutions to Managing a Crisis
 
The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...
 
Module 7_Crisis Resilience.pptx
Module 7_Crisis Resilience.pptxModule 7_Crisis Resilience.pptx
Module 7_Crisis Resilience.pptx
 
OverseeRiskAsNewerMoreComplex
OverseeRiskAsNewerMoreComplexOverseeRiskAsNewerMoreComplex
OverseeRiskAsNewerMoreComplex
 
Time Frame of a Crisis
Time Frame of a CrisisTime Frame of a Crisis
Time Frame of a Crisis
 
Build Resilience through Challenging Experiences.pdf
Build Resilience through Challenging Experiences.pdfBuild Resilience through Challenging Experiences.pdf
Build Resilience through Challenging Experiences.pdf
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
 
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
 
2020 is the year to challenge the NORM
2020 is the year to challenge the NORM2020 is the year to challenge the NORM
2020 is the year to challenge the NORM
 
crisis management.pptx
crisis management.pptxcrisis management.pptx
crisis management.pptx
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
 
Organization and management(Frontier of Public Administration)
Organization and  management(Frontier of Public Administration)Organization and  management(Frontier of Public Administration)
Organization and management(Frontier of Public Administration)
 

Organisational Resilience Paper v0.021

  • 1. Organisational Resilience  Are you using it?  Do you understand it?  Where does it fit in at Work? This Organisational Resilience paper seeks to move resilience from being a ‘back room’ issue to being a strategic one, taken up and regularly debated at the highest levels within an organisation. What does organisational resilience mean? There are a few different interpretations out there even from various Organisations responsible to set Standards in their related Country: British Standard, (BSI) BS65000 (2014) defines "organisational resilience"  The "ability of an organization to anticipate, prepare for, and respond and adapt to incremental change and sudden disruptions in order to survive and prosper." ISO is about to release its first Standard for Organisational Resilience around June/July 2016 and it is using this definition.  Organisational Resilience is the ability of an organisation to respond and adapt to change. Resilience enables organisation to articulate and respond to threats and opportunities, arising from sudden or gradual changes in their internal and external context. Enhancing resilience should be a strategic organisational goal. Gartner (Jan 2002) describes organisational Resilience as Organizational resilience has taken on a new urgency since the tragic events of Sept. 11. The ability to respond quickly, decisively and effectively to unforeseen and unpredictable forces is now an enterprise imperative However I prefer this more generic definition that refers to resilience: As the ability of a business or system to absorb change gracefully whilst retaining core properties or functions and to adopt to new evolving capabilities or opportunities. What does resilience mean to an organisation? Organisations deal with uncertainties and unexpected events all the time, and managing these is part of doing business. Above a certain scale however, crisis events differ from day-to-day management, in that organisations
  • 2. have to operate out of their comfort zone, interact with organisations they do not normally work alongside, and have to make and share strategic decisions quickly and effectively. Being able to respond effectively to crisis events is a real test of what makes an organisation ‘tick’. Companies are faced with an ever growing threat to its survival every day, and I’m not referring to having to compete with other companies in its chosen market sector which we would be in that case discussing its business and or trading competitiveness and its resilience to shifting market trends, advancing technologies and product / process improvements. In this case I’m referring to many threats and impacts from the digital and technology worlds. Cyber threats & attacks, hacking from various antibusiness organisations, terrorists groups, and maybe even competitors or foreign organisation. Not to mention Mother Nature and her ever changing cycles that cause enormous disruption mostly to the organisations reliance on technology Organisational Resilience is a relative and dynamic concept rather than a specific activity or fixed state. There are often many factors that when combined, enhance an organisations resilience and these can also be unique to each and every different organisation. Even 2 organisations trading in the same market sector link Banks or Telecommunication companies will both have variations to its own ability to be Resilient. Now we all realise that organisations all over the world have to deal with uncertainties and unexpected events all the time, and managing these presents both opportunities and risks for the organisation. Given this situation is often a daily or weekly event, it is also given that some of these events will be minor and some major, above a certain scale however, crisis events differ from day-to-day management, in that organisations have to operate out of their comfort zone, interact with organisations they do not normally work alongside, and have to make and share strategic decisions quickly and effectively. Being able to respond effectively to crisis events is a real test of what makes an organisation ‘tick’ Many organisations have established disciplines, frameworks, management processes and policies that all would be used to contribute to dealing with these various events and depending on that scale or size, there are various level of management that are required to be involved. Including in these frameworks and policies are:  Strategic Planning  Financial Planning  Risk Management,  Business Continuity Management  Crisis Management  ICT Disaster Recovery Management and ICT Continuity Management  Security Management These various management disciplines in isolation are insufficient to safeguard an organisations future.
  • 3. In developing a Strategy or Framework for Organisational Resilience it is not the intent to replace any of these disciplines, instead it provides a framework and set of principles to integrate and coordinate these disciplines alongside a wider set of attributes and related principles that enhance the maturity of the organisations resilience. [See Figure 1A] In developing a Framework to enable the organisation to establish and maintain a high level of maturity in its Organisational Resilience the endorsement and support of top management is required as follows. Top management commitment to enhance organisational resilience will contribute to:  improved capacity to anticipate and respond to threats and opportunities;  An ability to identify and address vulnerabilities before they have a material impact;  A more coordinated approach to integrate existing management disciplines that support organisational resilience; and  A greater understanding of interested parties and dependencies that support strategic goals and objectives. A couple of important notations to consider when understanding the correct context in which the above points are meant. 1: Objectives refers to the means by which an organisation implements its purpose and vision. Objectives may be at a strategic level set by top management or at a lower level in structure. 2: Purpose and vision relates to an organisations current and future strategic aim. This includes an organisations mission and goals. Your Framework should be structured to align with the four parts as shown inFigure1: 1. Principles provide the foundation for enhancing an organisations resilience; 2. Attributes describe the characteristics of an organisation that allow the principles to be achieved; 3. Activities guide the utilization, evaluation and enhancement of attributes: and 4. Disciplines contribute towards the organisations resilience maturity
  • 4. Figure 1A The other critical factor to take into account is that these organisations can be MORE or LESS resilient and there is no single or absolute measure or definitive goal. However many organisations have developed metrics that they can use to aid and assist in measuring their level of maturity and resilience. How can POOR Organisational Resilience impact your future survival? Organisations deal with uncertainties and unexpected events all the time, and managing these presents both opportunities and risks for the organisation. These events range in size and therefore range in capacity to impact your organisation, it there will also require different levels of management to make decisions and enact relevant policies and procedures to protect the organisation. Above a certain scale however, crisis events differ from day-to-day management, in that organisations have to operate out of their comfort zone, interact with organisations they do not normally work alongside, and have to make and share strategic decisions quickly and effectively. As many of us already know, a company’s success can be partially measured on it being able to respond effectively to crisis events and it is also a real test of what makes an organisation ‘tick’. Let’s look at major events last decade. The economic implications of organisations being unprepared for crises are significant. In the September 11th attacks, business interruption losses far exceeded the sum of all property losses. In our increasingly interconnected business environment, consequences go well beyond the zone of any physical damage, affecting businesses right along the supply chain.
  • 5. A second major event in USA was a failure of Power Supplies with a domino effect State by State In Australia just like in Europe and USA, mother nature brings havoc in the form of fires, floods and some regions earthquakes, these all are NOT planned or pre-arranged with dates set but we do know they will happen. An organisation’s ability to survive a major crisis depends on their organisational structure, the management and operational systems they have in place, and the resilience of these and also their suppliers, partners and thier employee’s. Our world and the fast moving global disruptions (we once called a war) In recent years we have seen how the world is being challenged in cyberspace and the impact certain Anti Terrorists groups can have on an organisation, yes many of us just say they are at war with certain countries with opposing religious beliefs. WRONG So some organisations may think they are not going to be affected as the war on the ground with troops etc. is not in their state, region or maybe even country. WRONG However, they fight their war on many different fronts and using many different techniques to win and dominate. They plan disruption of organisations and governments that support the cause of their stated enemies. They don’t use tanks and fighter planes to accomplish this. War over the internet, electronic data attacks, disruption of production lines caused via computer systems. Destroying a major power source are all technics that can be conducted almost anywhere in the world and often just from a Laptop computer. For any CEO or organisations executive management team to take a view it won’t happen to us or the chance of it happening is extremely low, is simply not acceptable, they may even decide the risk of it happening or causing a major disruption is something we are prepared to live with, well in fact it is NOT their decision, they are often accountable to stockholders / shareholders / partners / investors who will want to know their investment is safe or what plans do you have in place to provide maximum resilience? Many organisations are using existing management disciplines to enable a degree of Organisational resilience, while this is a good start it is not sufficient or sustainable. Example: Risk management is being used more extensively in organisations today, there are few organisations that apply risk management at a strategic level across the organisation. We are seeing that the uptake of business continuity and emergency planning is ever increasing, but still only a small proportion of organisations have any real integrated sustainable resilience planning in place.
  • 6. Those organisations that do have plans often lack the depth required to sustain a prolonged response capability. In many resilience issues it can be seen across organisational boundaries, much of the planning being done is very inward looking as many consider internal organisation is more critical, however they need to understand that external planning is potentially more important for sustainability. One of the biggest potentials for forward progress is to get organisations working together to manage risks across this interface (external), and developing and practicing strategies for working together during crises. This is particularly needed where outsourcing means that contracted organisations are relied upon to deliver critical services or supplies. Many organisations outsource key corporate functions as a method to save money, provide cost efficient services and manage operational costs. However there is a clear and defined impact here without adequate coverage for Resilience of your suppliers and 3rd party partners that they have contracted to supply there outsourced services. Information Technology is seen today as the foundations of a business, as the enabler of a successful business, the “business” cannot survive without these critical service but it is often these crucial services that are outsourced and the organisation does not understand or often seek to understand the level of “Organisational Resilience” that 3rd party organisation has itself in order to protect its clients services. Data Centre services are outsources, call centre services are outsources, and entire IT support services are outsources and are often run from a location outside the country the client organisation operates in. While these may appear to be cost saving measures, the potential for a major disaster has increased dramatically and no one in the executive management team has undertaken any assessment as to their supplies own Organisational Resilience. In our modern Technology World today we find ever and ever increasing range of services now being provided “In the Cloud”.  How do you assess their Organisational Resilience?  Do you even know where their infrastructure is located?  Who else has access to it? Does Organisational Resilience replace Risk management or Business Continuity Management? No Organizational Resilience is a strategic imperative for an organization to prosper in today’s dynamic, interconnected world. It is not a one-off exercise, but achieved over time and for the long-term. Mastering Organisational Resilience requires the adoption of excellent habits and best practice to deliver business improvement by building competence and capability across all aspects of an organization. This allows leaders to take measured risks with confidence, making the most of opportunities that present themselves. Risk Management and Business Continuity Management are critical enablers of developing strong and mature organisational resilience.
  • 7. How resilient is your Department, Company, Association or Organisation In developing a methodology to assess How Resilient is an Organisation, we evaluate an organisation’s resilience on four dimensions:  its situation awareness of both its own operations and the environment within which it operates,  how well it understands and manages its keystone vulnerabilities,  the organisation’s adaptive capacity, its attitude and ability to cope with change.  Organisations Commitment to Resilience and Sustainability Resilience is about ensuring that an organisation is still able to achieve its core objectives in the face of adversity. This means not only reducing the size and frequency of crises, but also improving the ability and speed of the organisation to manage crises effectively. To be truly resilient an organisation also has to constantly be aware and evolve in response to its changing environment and to seek out opportunities even in times of crisis. The are some basic fundamental requirements to enable an organisation to achieve a mature level of Resiliency  A common objective is enabling different parts of the organisation to work together to achieve a common objective. – No Silo Management  Giving some of its less tangible aspects of an organisation that relate to its culture, leadership and vision a higher priority of focus  Important qualities such as good communication and relationships within the organisation  This also applies external communications with key customers and stakeholders, business partners and even joint venture stakeholders  Establishing trust, and a shared vision The above criteria is usually treated as important to an organisation during its BAU (Business As Usual) periods. However it is CRITICAL at times of crisis when it is often the informal networks and relationships (who you know that you can call on for a favour…) that count. The culture of the organisation and recognising the strengths and weaknesses that culture brings to the organisation in times of crisis is a critical contributing process when building the Resilience of an organisation Situation Awareness There are many definitions of Situation Awareness, some come from ancient eastern practices, mind development, the Military use many forms of this in their training, however for Organisational Resilience it has to core meanings, [1] being aware of what is happening around you and understanding what that information means to you now and in the future [2] the same applies to organisations however in additional to what is described inn point 1, it also requires the organisation to understand, assimilate, and act on large volumes of information to perform and maintain organisation resilience Keystone vulnerability
  • 8. In an assessment a critical area for validation is what qualifies a particular vulnerability as a keystone vulnerability and note other uses of the term keystone: ecological and architectural. They go on to define keystone vulnerabilities as “...components in the organizational system, which by their loss or impairment have the potential to cause exceptional effects throughout the system” This is also addressed within the field of business continuity management where organizations aim to identify and assess potential single points of failure, such as a single source supplier or resource, through business impact analyses Adaptive capacity An organisation’s ability to adapt is at the heart of its ability to display resilient characteristics. An organisation’s adaptive capacity is their ability to continuously design and develop solutions to match or exceed the needs of their environment as changes in that environment emerge. What is often referred to as Continuous Improvement, many organisation do not have clearly defined policies regarding Continuous Improvement thus it has a direct impact on their Adaptive Capacity. So back to the basics – Why Resilience is important? Why resilience is important? The business environment is fast becoming more interconnected, unpredictable and volatile and the consequences of external events more substantial. If you respond too late or inappropriately, you risk getting left behind. There are a number of phenomena that executives and managers may need to be aware in their strategic planning activity such as: - Faster and multi-faceted change Today’s businesses are affected by changes in their political, natural and social contexts. - Environmental changes Environmental changes, such as global warming, are becoming a major threat to some sectors, and not just the ones that immediately come to mind. - Large scale mergers and acquisitions Global organisations have wide influence, concentrating resources and even superseding some countries’ internal product. - Faster career transitions Individuals in organisations are less ‘steady state’: faster career transitions are occurring, and more often than ever before individuals are changing roles within a given organisation and across various firms. - Unprecedented advances in Information Technologies New information technologies are creating new communications channels, shifting consumer patterns and new social ways of linking up. Taking Action on Organisational Resilience The key to developing organisational resilience is making second nature the capability to adapt and recover. In this way, it becomes dynamic, self – organising and deeply ingrained into the organisation’s day-to-day operations, and the way it does business.
  • 9. Summary: Unfortunately, there is no ‘silver bullet’; resilience is something that an organisation must continually work at. But because it is so intrinsically related to the day-to-day ethos of the organisation, it can also create significant payback in terms of helping to refocus on what is important to the organisation and creating a shared understanding of the roles people play in making those a reality. Most importantly, resilience needs to move from being a ‘back room’ issue to being a strategic one and be regularly debated as part of strategic planning for any organisation While you may not have a Silver Bullet, if you adopt the model below you will get a Sustainable Resilient Organisation