SlideShare a Scribd company logo
1 of 38
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
1 |
insync.com.au/risk-compliance
Critical Infrastructure &
Systems of National
Significance: Security Risk
Management Challenges
for Managers and Industry
Tony Ridley MSc CSyP CAS MSyl M.ISRM
Tony Ridley
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
2 |
Enterprise Security Risk Management
Tony Ridley MSc CSyP CAS MSyl M.ISRM
Principal – Risk & Resilience Consulting
Education, licenses and certifications
• Master of Science (MSc) Security and Risk Management, University of Leicester
• Doctor of Public Safety, Charles Sturt University (Currently Studying)
• Chartered Security Professional (CSyP), Registered Charter of Security Professionals
(UK)
• Certified Anti-Terrorism Specialist (CATS), Anti-Terrorism Advisory Board (ATAB)
• Lead Auditor, Integrated Management Systems: Quality, OHS, Environment and
Management Systems
• Security & Risk Management, - Diploma
• Security Operations Management, Diploma
• Assessment and Workplace Training, Certificate IV
Professional Associations
• Vetted Member (MSyl), The Security Institute
• Business Continuity Institute (BCI)
LinkedIn Profile
Overview
Tony has worked in executive-level enterprise security and operational
risk & resilience roles worldwide. His extensive experience includes
remote sites, national operations, multinational firms, and government
agencies. As a criminologist, security and risk scientist, intelligence
analyst and public safety professional, he is passionate about helping
organisations build and maintain robust, risk-informed systems and
decision-making processes leading to sustainable resilience.
Tony helps clients build, review, and improve security, risk and resilience
teams, supply chains and enterprise security risk management systems,
using advanced academic methodologies, practical experience and
applied scientific means.
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
3 |
Also…
www.riskdepartment.global
www.linkedin.com/company/riskdepartment
CLIENT LOGO
Agenda
- Context (UK, US , Aust)
- Challenge
- Considerations
- Recommendations
Young Professionals
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
5 |
Critical Infrastructure &
Systems of National
Significance:
Context, Growth,
Complexity, Dependencies
Security, Risk, Resilience & Maturity
insync.com.au/risk-compliance
Protective security is an enduring process, not a state.
…the language of ‘maturity’ implies an ideal end state that does
not exist.
In reality, the risks keep moving and no security will stay
‘mature’ for long unless it too keeps moving.
Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.22
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
7 |
Security of Critical Infrastructure (Definitions) Rules (LIN 21/039)
2021
Reference:
"As the threats and risks to Australia’s critical infrastructure evolve, so too must our approach to ensuring the ongoing
security and resilience of these assets and the essential services they deliver." - (Department of Home Affairs, 2021)
Definitions
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
8 |
insync.com.au/risk-compliance
Resilience, Risk & Resourcefulness
“…although resilience appears at first sight
as a systems theory, its main effect is to
emphasize the need for adaptability at the
unit level. ”
Reference:
Bergstrom, J. and Dekker, S. (2019). The 2010s and Onward: Resilience Engineering, in Dekker, S. (ed) Foundations of Safety Science; A century of understanding accidents and disasters. pp. 391-429
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
10 |
Little, R. (2012) Managing the Risk of Ageing Infrastructure, IRGC - Public Sector
Governance of Emerging Risks - Infrastructure Case - November 2012
Reference:
Interdependence
Between one or
more assets and
those that are/aren’t
‘critical’
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
11 |
Liveable
Infrastructure Australia (2021) Reforms to meet Australia’s future
infrastructure needs, Australian Government
Reference:
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
12 |
https://www.cpni.gov.uk/protecting-your-assets
Reference:
Built
Environment
insync.com.au/risk-compliance
Risk, Resilience & Resourcefulness
“While risk and resilience are related, resilience has
been favoured for unknown, unquantifiable, systemic
risks. In other words, resilience is an “asset based”
rather than “threat based” approach. ”
Reference:
Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
14 |
Crime Prevention Through Environmental Design
(CPTED)
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
15 |
Protection
Defence In Depth
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
16 |
insync.com.au/risk-compliance
Resilience, Risk & Resourcefulness
"Complex systems, though seemingly stable, are not in
equilibrium. Rather, complex systems are constantly
adapting to balance multiple goal conflicts. Such
complex systems are inherently vulnerable to ' drifting
toward failure as defences erode in the face of
production pressure' ”
Reference:
Bergstrom, J. and Dekker, S. (2019). The 2010s and Onward: Resilience Engineering, in Dekker, S. (ed) Foundations of Safety Science; A century of understanding accidents and disasters. pp. 391-429
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
18 |
Cascading Failure(s)
Where are you?
Reference:
National recovery and resilience agency (2020) National emergency risk assessment guidelines,
Australian Disaster Resilience Handbook Collection, 1st ed (updated) , Australian Institute for
Disaster Resilience, Australian Government
Risk Contexts, Considerations and Analysis
insync.com.au/risk-compliance
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
20 |
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
21 |
insync.com.au/risk-compliance
Risk, Resilience & Resourcefulness
“…recognition of resilience as an emergent property of complex
adaptive systems. Resilience is both a function of planning for and
preparing for future crisis (planned resilience), and adapting to
chronic stresses and acute shocks (adaptive resilience). ”
Reference:
Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
COSO Enterprise Risk
Management Framework
Risk – Frameworks influencing the Enterprise
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
23 |
Reference:
https://www.csu.edu/internalaudit/documents/COSOEnterpriseRiskManagementFramework.pdf
Principles, Framework
and Process
Risk – Frameworks influencing the Enterprise
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
24 |
Reference:
National recovery and resilience agency (2020) National emergency risk assessment guidelines,
Australian Disaster Resilience Handbook Collection, 1st ed (updated) , Australian Institute for Disaster
Resilience, Australian Government
insync.com.au/risk-compliance
Risk, Security & Resilience
“security is essentially preventive and proactive in
nature, ... whereas resilience, is a combination of
proactive and reactive measures aiming at reducing
the impact but not at preventing threats as such”
Reference:
Fjäder, C. (2014). “The nation-state, national security and resilience in the age of globalization.” Resilience 2 (2).pp.114– 129.
Convergence
Risk – Frameworks influencing the Enterprise
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
26 |
Reference:
Homeland Security (2006). National Infrastructure Protection Plan: Risk Management Framework,
Department of Homeland Security, US Government
Reference:
Homeland Security (2013) Supplement Tool: Executing a Critical Infrastructure Risk Management
Approach, Department of Homeland Security, US Government
insync.com.au/risk-compliance
Risk, Resilience & Vulnerabilities
“Risk and resilience are important
paradigms for guiding decisions made
under uncertainty, in particular decisions
about how to protect systems from a
portfolio of threats. ”
Reference:
Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
Assessments of “Risks”
insync.com.au/risk-compliance
Melbourne | Sydney | Gold Coast
insync.com.au
Resilience, Risk & Resourcefulness
insync.com.au/risk-compliance
Reference:
The Royal Society (1992) Risk Analysis, Perception & Management. Report of the Royal Society Study Group, page 181
“Issues of how to constitute decision advice procedures, both of an
ex-ante and ex-post kind, how to allocate blame and liability, how
to organise affective regulatory structures, how to bring together
different kinds of expertise into an affective policy debate, arise in
different ways in all of these cases and go to the heart of the
institutional aspects of risk management”
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
30 |
From security to resilience
Reference:
Homeland Security (2013) National Infrastructure Protection Plan (NIPP): Partnering of critical
infrastructure Security and Resilience, Department of Homeland Security, US Government
Security, Risk, Resilience & Human Factors
insync.com.au/risk-compliance
One of the main reasons why so many
security systems remain vulnerable is
that threat actors pay more attention to
the psychology of their victim than do
most security designers and
practitioners.*
*Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.96
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
32 |
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
33 |
Security
Contextual Layers
Security, Risk, Resilience & Protection from Harm
insync.com.au/risk-compliance
Good protective security has nine
distinguishing characteristics: it is risk-
based, well governed, holistic,
understandable, regularly tested, well
measured, layered, designed-in, and
dynamic.
Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.173
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
35 |
 Essential
Melbourne | Sydney | Gold Coast
insync.com.au
Questions??
Insync.com.au/risk-compliance
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
37 |
insync.com.au/risk-compliance
Critical Infrastructure &
Systems of National
Significance: Security Risk
Management Challenges
for Managers and Industry
Tony Ridley MSc CSyP CAS MSyl M.ISRM
All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved
38 |
But that’s not all…
Learn more about what we
think about the issues
that matter most…
You can learn more about what we think and how we contribute to various
conversations that are relevant to you and your context through visiting the
following links. As a small, focused organisation of around 50- people you
can also be guaranteed that, by engaging with Insync, you are working with
the thought leaders actively involved in leading the debate.
Risk Management
Security Risk Management
A proven and pragmatic
approach to better
decision making in
turbulent times | Insync
To make better decisions
you need 6 things | Insync
So you think you are risk
averse? | Insync
Defence-in-depth: myths,
vulnerabilities and
realities
Safety & security risks.
Transition relationships
Risk landscapes &
environments
Security risk assessments Situational security:
factor analysis
Operational security: a
formulaic approach

More Related Content

More from Enterprise Security Risk Management

Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Enterprise Security Risk Management
 
Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Enterprise Security Risk Management
 
8 security masters degrees compared.security risk management.tony ridley.se...
8  security  masters degrees compared.security risk management.tony ridley.se...8  security  masters degrees compared.security risk management.tony ridley.se...
8 security masters degrees compared.security risk management.tony ridley.se...Enterprise Security Risk Management
 
Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Enterprise Security Risk Management
 
Cheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantCheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantEnterprise Security Risk Management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Enterprise Security Risk Management
 
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Enterprise Security Risk Management
 
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Enterprise Security Risk Management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Enterprise Security Risk Management
 
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Enterprise Security Risk Management
 
Security writings.no name no credibility.risk management.tony ridley
Security writings.no name no credibility.risk management.tony ridleySecurity writings.no name no credibility.risk management.tony ridley
Security writings.no name no credibility.risk management.tony ridleyEnterprise Security Risk Management
 
Security risk management. the essentials.tony ridley.security consultant
Security risk management. the essentials.tony ridley.security consultantSecurity risk management. the essentials.tony ridley.security consultant
Security risk management. the essentials.tony ridley.security consultantEnterprise Security Risk Management
 
Security education levels. why it matters.security risk mangement.tony ridley...
Security education levels. why it matters.security risk mangement.tony ridley...Security education levels. why it matters.security risk mangement.tony ridley...
Security education levels. why it matters.security risk mangement.tony ridley...Enterprise Security Risk Management
 
Intelligence industrial complex.security risk management.tony ridley.security...
Intelligence industrial complex.security risk management.tony ridley.security...Intelligence industrial complex.security risk management.tony ridley.security...
Intelligence industrial complex.security risk management.tony ridley.security...Enterprise Security Risk Management
 
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...Ghost.shadow.overemployment.security guards.security r isk management.tony ri...
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...Enterprise Security Risk Management
 
Wise men and fools.tony ridley.security risk management.consultant
Wise men and fools.tony ridley.security risk management.consultantWise men and fools.tony ridley.security risk management.consultant
Wise men and fools.tony ridley.security risk management.consultantEnterprise Security Risk Management
 
Vicarious liability.tony ridley.security risk management.security consultant
Vicarious liability.tony ridley.security risk management.security consultantVicarious liability.tony ridley.security risk management.security consultant
Vicarious liability.tony ridley.security risk management.security consultantEnterprise Security Risk Management
 

More from Enterprise Security Risk Management (20)

Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...Security and risk management. from subject matter expert to business leader.t...
Security and risk management. from subject matter expert to business leader.t...
 
Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...Security and risk management in emerging and developing markets.tony ridley.s...
Security and risk management in emerging and developing markets.tony ridley.s...
 
8 security masters degrees compared.security risk management.tony ridley.se...
8  security  masters degrees compared.security risk management.tony ridley.se...8  security  masters degrees compared.security risk management.tony ridley.se...
8 security masters degrees compared.security risk management.tony ridley.se...
 
Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...Appreciation process.time critical decision making.security risk management.t...
Appreciation process.time critical decision making.security risk management.t...
 
Cheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultantCheap and nasty.security certification.tony ridley.security consultant
Cheap and nasty.security certification.tony ridley.security consultant
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...
 
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...Fat tail distribution hypothesis.tony ridley.security risk management.securit...
Fat tail distribution hypothesis.tony ridley.security risk management.securit...
 
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
Forecastings.intelligence.predictions.experts.accuracy.security science.risk ...
 
Get to the point..faster.tony ridley.security risk management
Get to the point..faster.tony ridley.security risk managementGet to the point..faster.tony ridley.security risk management
Get to the point..faster.tony ridley.security risk management
 
Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...Educational levels of professionals.a guide.tony ridley.security risk managem...
Educational levels of professionals.a guide.tony ridley.security risk managem...
 
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
Takes a thief to catch a thief.security ethics.tony ridley.security risk mana...
 
Seguridad y riesgo.tony ridley
Seguridad y riesgo.tony ridleySeguridad y riesgo.tony ridley
Seguridad y riesgo.tony ridley
 
Security writings.no name no credibility.risk management.tony ridley
Security writings.no name no credibility.risk management.tony ridleySecurity writings.no name no credibility.risk management.tony ridley
Security writings.no name no credibility.risk management.tony ridley
 
Security risk management. the essentials.tony ridley.security consultant
Security risk management. the essentials.tony ridley.security consultantSecurity risk management. the essentials.tony ridley.security consultant
Security risk management. the essentials.tony ridley.security consultant
 
Security education levels. why it matters.security risk mangement.tony ridley...
Security education levels. why it matters.security risk mangement.tony ridley...Security education levels. why it matters.security risk mangement.tony ridley...
Security education levels. why it matters.security risk mangement.tony ridley...
 
Securite et de risque.tony ridley
Securite et de risque.tony ridleySecurite et de risque.tony ridley
Securite et de risque.tony ridley
 
Intelligence industrial complex.security risk management.tony ridley.security...
Intelligence industrial complex.security risk management.tony ridley.security...Intelligence industrial complex.security risk management.tony ridley.security...
Intelligence industrial complex.security risk management.tony ridley.security...
 
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...Ghost.shadow.overemployment.security guards.security r isk management.tony ri...
Ghost.shadow.overemployment.security guards.security r isk management.tony ri...
 
Wise men and fools.tony ridley.security risk management.consultant
Wise men and fools.tony ridley.security risk management.consultantWise men and fools.tony ridley.security risk management.consultant
Wise men and fools.tony ridley.security risk management.consultant
 
Vicarious liability.tony ridley.security risk management.security consultant
Vicarious liability.tony ridley.security risk management.security consultantVicarious liability.tony ridley.security risk management.security consultant
Vicarious liability.tony ridley.security risk management.security consultant
 

Critical Infrastructure & Systems of National Significance: Security Risk Management Challenges for Managers and Industry

  • 1. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 1 | insync.com.au/risk-compliance Critical Infrastructure & Systems of National Significance: Security Risk Management Challenges for Managers and Industry Tony Ridley MSc CSyP CAS MSyl M.ISRM
  • 2. Tony Ridley All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 2 | Enterprise Security Risk Management Tony Ridley MSc CSyP CAS MSyl M.ISRM Principal – Risk & Resilience Consulting Education, licenses and certifications • Master of Science (MSc) Security and Risk Management, University of Leicester • Doctor of Public Safety, Charles Sturt University (Currently Studying) • Chartered Security Professional (CSyP), Registered Charter of Security Professionals (UK) • Certified Anti-Terrorism Specialist (CATS), Anti-Terrorism Advisory Board (ATAB) • Lead Auditor, Integrated Management Systems: Quality, OHS, Environment and Management Systems • Security & Risk Management, - Diploma • Security Operations Management, Diploma • Assessment and Workplace Training, Certificate IV Professional Associations • Vetted Member (MSyl), The Security Institute • Business Continuity Institute (BCI) LinkedIn Profile Overview Tony has worked in executive-level enterprise security and operational risk & resilience roles worldwide. His extensive experience includes remote sites, national operations, multinational firms, and government agencies. As a criminologist, security and risk scientist, intelligence analyst and public safety professional, he is passionate about helping organisations build and maintain robust, risk-informed systems and decision-making processes leading to sustainable resilience. Tony helps clients build, review, and improve security, risk and resilience teams, supply chains and enterprise security risk management systems, using advanced academic methodologies, practical experience and applied scientific means.
  • 3. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 3 | Also… www.riskdepartment.global www.linkedin.com/company/riskdepartment
  • 4. CLIENT LOGO Agenda - Context (UK, US , Aust) - Challenge - Considerations - Recommendations Young Professionals
  • 5. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 5 | Critical Infrastructure & Systems of National Significance: Context, Growth, Complexity, Dependencies
  • 6. Security, Risk, Resilience & Maturity insync.com.au/risk-compliance Protective security is an enduring process, not a state. …the language of ‘maturity’ implies an ideal end state that does not exist. In reality, the risks keep moving and no security will stay ‘mature’ for long unless it too keeps moving. Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.22
  • 7. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 7 | Security of Critical Infrastructure (Definitions) Rules (LIN 21/039) 2021 Reference: "As the threats and risks to Australia’s critical infrastructure evolve, so too must our approach to ensuring the ongoing security and resilience of these assets and the essential services they deliver." - (Department of Home Affairs, 2021) Definitions
  • 8. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 8 |
  • 9. insync.com.au/risk-compliance Resilience, Risk & Resourcefulness “…although resilience appears at first sight as a systems theory, its main effect is to emphasize the need for adaptability at the unit level. ” Reference: Bergstrom, J. and Dekker, S. (2019). The 2010s and Onward: Resilience Engineering, in Dekker, S. (ed) Foundations of Safety Science; A century of understanding accidents and disasters. pp. 391-429
  • 10. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 10 | Little, R. (2012) Managing the Risk of Ageing Infrastructure, IRGC - Public Sector Governance of Emerging Risks - Infrastructure Case - November 2012 Reference: Interdependence Between one or more assets and those that are/aren’t ‘critical’
  • 11. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 11 | Liveable Infrastructure Australia (2021) Reforms to meet Australia’s future infrastructure needs, Australian Government Reference:
  • 12. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 12 | https://www.cpni.gov.uk/protecting-your-assets Reference: Built Environment
  • 13. insync.com.au/risk-compliance Risk, Resilience & Resourcefulness “While risk and resilience are related, resilience has been favoured for unknown, unquantifiable, systemic risks. In other words, resilience is an “asset based” rather than “threat based” approach. ” Reference: Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
  • 14. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 14 | Crime Prevention Through Environmental Design (CPTED)
  • 15. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 15 | Protection Defence In Depth
  • 16. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 16 |
  • 17. insync.com.au/risk-compliance Resilience, Risk & Resourcefulness "Complex systems, though seemingly stable, are not in equilibrium. Rather, complex systems are constantly adapting to balance multiple goal conflicts. Such complex systems are inherently vulnerable to ' drifting toward failure as defences erode in the face of production pressure' ” Reference: Bergstrom, J. and Dekker, S. (2019). The 2010s and Onward: Resilience Engineering, in Dekker, S. (ed) Foundations of Safety Science; A century of understanding accidents and disasters. pp. 391-429
  • 18. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 18 | Cascading Failure(s) Where are you? Reference: National recovery and resilience agency (2020) National emergency risk assessment guidelines, Australian Disaster Resilience Handbook Collection, 1st ed (updated) , Australian Institute for Disaster Resilience, Australian Government
  • 19. Risk Contexts, Considerations and Analysis insync.com.au/risk-compliance
  • 20. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 20 |
  • 21. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 21 |
  • 22. insync.com.au/risk-compliance Risk, Resilience & Resourcefulness “…recognition of resilience as an emergent property of complex adaptive systems. Resilience is both a function of planning for and preparing for future crisis (planned resilience), and adapting to chronic stresses and acute shocks (adaptive resilience). ” Reference: Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
  • 23. COSO Enterprise Risk Management Framework Risk – Frameworks influencing the Enterprise All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 23 | Reference: https://www.csu.edu/internalaudit/documents/COSOEnterpriseRiskManagementFramework.pdf
  • 24. Principles, Framework and Process Risk – Frameworks influencing the Enterprise All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 24 | Reference: National recovery and resilience agency (2020) National emergency risk assessment guidelines, Australian Disaster Resilience Handbook Collection, 1st ed (updated) , Australian Institute for Disaster Resilience, Australian Government
  • 25. insync.com.au/risk-compliance Risk, Security & Resilience “security is essentially preventive and proactive in nature, ... whereas resilience, is a combination of proactive and reactive measures aiming at reducing the impact but not at preventing threats as such” Reference: Fjäder, C. (2014). “The nation-state, national security and resilience in the age of globalization.” Resilience 2 (2).pp.114– 129.
  • 26. Convergence Risk – Frameworks influencing the Enterprise All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 26 | Reference: Homeland Security (2006). National Infrastructure Protection Plan: Risk Management Framework, Department of Homeland Security, US Government Reference: Homeland Security (2013) Supplement Tool: Executing a Critical Infrastructure Risk Management Approach, Department of Homeland Security, US Government
  • 27. insync.com.au/risk-compliance Risk, Resilience & Vulnerabilities “Risk and resilience are important paradigms for guiding decisions made under uncertainty, in particular decisions about how to protect systems from a portfolio of threats. ” Reference: Kekovic, Z. and Ninkovic, V. (2020). Towards a conceptualisation of resilience in security studies, Institute for Political Studies: Faculty of Security Studies, University of Belgrade.pp.153-173
  • 29. Melbourne | Sydney | Gold Coast insync.com.au Resilience, Risk & Resourcefulness insync.com.au/risk-compliance Reference: The Royal Society (1992) Risk Analysis, Perception & Management. Report of the Royal Society Study Group, page 181 “Issues of how to constitute decision advice procedures, both of an ex-ante and ex-post kind, how to allocate blame and liability, how to organise affective regulatory structures, how to bring together different kinds of expertise into an affective policy debate, arise in different ways in all of these cases and go to the heart of the institutional aspects of risk management”
  • 30. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 30 | From security to resilience Reference: Homeland Security (2013) National Infrastructure Protection Plan (NIPP): Partnering of critical infrastructure Security and Resilience, Department of Homeland Security, US Government
  • 31. Security, Risk, Resilience & Human Factors insync.com.au/risk-compliance One of the main reasons why so many security systems remain vulnerable is that threat actors pay more attention to the psychology of their victim than do most security designers and practitioners.* *Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.96
  • 32. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 32 |
  • 33. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 33 | Security Contextual Layers
  • 34. Security, Risk, Resilience & Protection from Harm insync.com.au/risk-compliance Good protective security has nine distinguishing characteristics: it is risk- based, well governed, holistic, understandable, regularly tested, well measured, layered, designed-in, and dynamic. Reference: Martin, P. (2019) The Rules of Security: Staying Safe in a Risky World, Oxford University Press, p.173
  • 35. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 35 |  Essential
  • 36. Melbourne | Sydney | Gold Coast insync.com.au Questions?? Insync.com.au/risk-compliance
  • 37. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 37 | insync.com.au/risk-compliance Critical Infrastructure & Systems of National Significance: Security Risk Management Challenges for Managers and Industry Tony Ridley MSc CSyP CAS MSyl M.ISRM
  • 38. All slides and material are commercial-in-confidence. © Insync Surveys Pty Ltd. All rights reserved 38 | But that’s not all… Learn more about what we think about the issues that matter most… You can learn more about what we think and how we contribute to various conversations that are relevant to you and your context through visiting the following links. As a small, focused organisation of around 50- people you can also be guaranteed that, by engaging with Insync, you are working with the thought leaders actively involved in leading the debate. Risk Management Security Risk Management A proven and pragmatic approach to better decision making in turbulent times | Insync To make better decisions you need 6 things | Insync So you think you are risk averse? | Insync Defence-in-depth: myths, vulnerabilities and realities Safety & security risks. Transition relationships Risk landscapes & environments Security risk assessments Situational security: factor analysis Operational security: a formulaic approach