FM Global Business Risk Consulting Group Business Continuity Planning and Analysis: Protecting Business Value Texas PRIMA’s 20 th Annual Conference November.

Slides:



Advertisements
Similar presentations
Museum Presentation Intermuseum Conservation Association.
Advertisements

Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Reliability of the electrical service Business Continuity Management Business Impact Analysis (BIA) Critical ITC Services Minimum Business Continuity Objective.
Business Continuity and Disaster Recovery Planning.
Disaster Preparedness I Lessons Learned Don Hall Thomson Prometric 2006 Annual ConferenceAlexandria, Virginia Council on Licensure, Enforcement and Regulation.
Control and Accounting Information Systems
BCM IN THE SUPPLY CHAIN Rupert Johnston. Format Acknowledgements. Reasons Why. Understanding the Supply Chain; Who and What are Critical? Strategies and.
Service Design – Section 4.5 Service Continuity Management.
Business Continuity Disaster Recovery Risk Management How do these fit into a Framework?
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
Introduction to Business Continuity Planning An Introduction to the Business Continuity Planning Process Including Developing your Process and the Plans.
1 Continuity Planning for transportation agencies.
BCP/DRP Consultancy Project- An approach
Business Continuity Planning and Disaster Recovery Planning
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Business Crisis and Continuity Management (BCCM) Class Session
Contractor Assurance Discussion Forrestal Building Washington, D.C. December 14, 2011.
By Saurabh Sardesai October 2014.
1 Business Continuity and Compliance Working Together Kristy Justice, AVP WaMu Card Services 08/19/2008.
John Graham – STRATEGIC Information Group Steve Lamb - QAD Disaster Recovery Planning MMUG Spring 2013 March 19, 2013 Cleveland, OH 03/19/2013MMUG Cleveland.
Crisis Management Planning Employee Health Safety and Security Expertise Panel · Presenter Name · 2008.
Change Advisory Board COIN v1.ppt Change Advisory Board ITIL COIN June 20, 2007.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Session No. 3 ICAO Safety Management Standards ICAO SMS Framework
© 2010 Plexent – All rights reserved. 1 Change –The addition, modification or removal of approved, supported or baselined CIs Request for Change –Record.
RBTC: Business Continuity 101 July 18, What is Business Continuity? Scenario Part 1 Why is BC important? What types of plans are needed? How do.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Business Crisis and Continuity Management (BCCM) Class Session
Implementing and Auditing Ethics Programs
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
Making Business Continuity Child’s Play Solutions Ltd Business Continuity Management Contact details: Contact : Mick O’Regan Mobile :
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
ISA 562 Internet Security Theory & Practice
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Operational Excellence and Sustainable Performance Improvement Date: 9 June, 2009.
Expecting the Unexpected By Shaun Lindfield. Nearly 1 in 5 businesses suffer a major disruption every year. Yours could be next. With no recovery plan,
2010 Virginia RIMS and PRIMA Conference October 5, 2010 Business Impact Analysis: The Road Map to Managing Risks.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
TREASURY REGULATIONS’ CHANGES AND POTENTIAL IMPACT
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Kathy Corbiere Service Delivery and Performance Commission
9 juni 2009 Alex van Os de Man BCI Forum 2009 Business Impact Analysis Process.
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Business Continuity Disaster Planning
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Business Continuity Planning 101
ISACA Accra, Kumasi Workshop September 2013 Business Continuity Management Compiled and presented by: Eric Magnusen ( BCM Consultant) BCM-Consult, Al Faslu.
THINK DIFFERENT. THINK SUCCESS.
Utilizing Your Business Continuity Plan.
Chris Lintern Co-operative Financial Services
Approaches to Defining Risk
BUSINESS CONTINUITY BY HUI ZHENG.
Business Continuity / Recovery
Boeing Business Continuity
Business Continuity Basics
Business Continuity Program Overview
MAZARS’ CONSULTING PRACTICE Helping your Business Venture Further
CEng progression through the IOM3
Presentation transcript:

FM Global Business Risk Consulting Group Business Continuity Planning and Analysis: Protecting Business Value Texas PRIMA’s 20 th Annual Conference November 19, 2009

Overall agenda Identify key reasons driving Business Continuity Management in today’s global economy Context and Terminology Reasons for developing a Business Continuity Management Program Framework of the strategy and process for developing and writing a Business Continuity Plan

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Today’s business environment BUSINESS Competitive pressure Reduced time to market Info available to buyers Operational efficiency High asset utilization Lean manufacturing Corporate governance Regulatory compliance Need for transparency Executive accountability Global supply chains Outsourcing ICT dependency Network interdependencies

Today’s business world we know disruptions will occur, but we don’t know when, for how long, or the cause. directors and ‘C-Suite’ officers must be proactive in mitigating risk. an excellent part of being seen to be proactive, is to have a business continuity plan in place. We can’t ELIMINATE risk, but we can at least MANAGE the impact!

Terminology How would you define the terms? ERMBCMBCPDRP RTO MTO

A question of scope and focus… Strategic OperationalExternal Financial Enterprise risk management… the identification and evaluation of all relevant risks an organization faces, alignment of strategies with risk appetite, and perpetual management of exposures so that entity objectives are achievable. RISK Business continuity management… a holistic management process that identifies potential impacts that threaten a company, provides a framework for building resilience and develops the capability for an effective response to safe- guard the interests of the stakeholders, reputation, brand and value creating activities*. IMPACT *Courtesy of the Business Continuity Institute

SUPPLY CHAIN MANAGEMENT QUALITY MANAGEMENT RISK MANAGEMENT DISASTER RECOVERY FACILITIES MANAGEMENT *The Business Continuity Institute 2002 SECURITY CRISIS COMMUNICATIONS & PUBLIC RELATIONS HEALTH & SAFETY KNOWLEDGE MANAGEMENT EMERGENCY MANAGEMENT The BCM ‘umbrella’ Courtesy of the Business Continuity Institute BUSINESS CONTINUITY MANAGEMENT

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture Business Continuity Plans (BCP) An element of BCM BCM

BCP and DRP Business continuity plan… a documented collection of procedures and information that is developed, compiled and maintained in readiness for use in an incident to enable an organization to continue to deliver its critical activities at an acceptable pre- defined level*. Disaster recovery plan… the management approved document that defines the resources, actions, tasks and data required to manage the recovery effort. It usually refers to the technology recovery effort and is a component of the business continuity management program*. *Courtesy of the Business Continuity Institute and DRI International

Confused? ERM BCM DRP BCP

MTO and RTO Maximum tolerable outage (also maximum tolerable period of disruption)… the duration after which an organization’s viability will be irrevocably threatened if product and service delivery cannot be resumed. Recovery time objective… the target time set for: –Resumption of product and service delivery after an incident –Resumption of performance of an activity after an incident –Recovery of an IT system or application after an incident which must support the MTO. Courtesy of the Business Continuity Institute

Why Should You Have BCM? What are common reasons for implementing Business Continuity Management?

Property Damage Risks - typically considered in isolation –Replacement cost of lost physical assets –Lost value of production/service delivery The Bigger Picture –Failed delivery ► brand damage –Cash-flow volatility ► investor confidence loss –Lost opportunities ► reduced growth potential The Bigger Picture

Case Study - University of Adelaide

Background Founded in 1874 Over 20,000 students & over 2,500 staff 3 weeks into 2005 academic year, waterline breached releasing over 100K liters of water Water released into a trench directing water downward toward roof of Plaza Building which housed 3 schools, university library, data center, and central air plant for most of the campus Carried 40 tons of silt and mud into Plant Room, IT servers, classrooms and library

Case Study - University of Adelaide

Mitigation Information Technologies Disaster recovery plan in place and activated Multiple data centers  85% of IT systems back in 36 hours Competent staff available Good relationships with subcontractors Property Services Developed an electrical risk plan Upgraded the AC/Thermal plant room Asbestos abatement program

Mitigation (continued) Property Services Move important items from exposed areas (if possible) Raise equipment off the ground Provide back-up generators and related equipment  Agreements in place for 2 hour delivery Protect vulnerable openings with curbing

Impact Summary 95% of classes resumed the following Monday 95% of electrical, A/C, fire detection equipment back up by next week Majority of ceilings, floor coverings replaced within a month Impact to IT equipment, projects and resources can be long term  Can take 4 to 6 months to get equipment recertified  “Lose IT for even a month in the middle of the semester, we lose the whole semester”

Benefits of BCM 1.Protects the company’s Brand and Reputation. 2.Safeguards and enhances the company’s shareholder value 3.Maintains standards of excellence 4.Helps to optimize and streamline a business or organization 5.Directs a focused IT expenditure 6.Mitigates loss in revenues 7.Enhances customer confidence and assurance on deliverables 8.Demonstrates improved risk quality for insurance purposes 9.Enhances selling-point for contract tenders

Companies that manage risk properly and communicate the effectiveness of these efforts to stakeholders could… – gain competitive advantage – boost financial performance – enhance shareholder value – protect the value their business creates In Summary….

Protecting Business Value: Effective Business Continuity Planning Framework

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Strategy –Engage executive management –Define objectives: managed resilience –Establish steering committee –Think resilience at design not execution –Make business continuity strategic Culture –Elevate and expand continuity awareness –Communicate the benefits widely –Embed continuity in culture: be active not reactive Design for Resilience

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Why? In times of crisis, resources – money, people, time, materials – are scarce. You can’t solve everything at once – you need to know where to direct these scarce resources. To know where to direct resources, you must determine which activities are critical to maintaining continuity and achieving your strategic objectives You must Understand Your Business Design for resilience Understand your business

The Business Impact Analysis What are the key hazards? What are the credible loss scenarios? What is the quality of risk mitigation within the business? Risk Analysis How much profit do these products and services generate? Where are the costs associated with their delivery to customers? Financial Analysis Business Impact Analysis What are the key facilities and processes that drive revenues and costs, what could go wrong within these and what would be the cost to the business if it did go wrong? How can these exposures be mitigated in order to ensure business continuity and protect shareholder value? Risk Mitigation Opportunities How do products and services flow through the internal and external supply chain? How could these flows be interrupted? Business Model Analysis

BIA outcomes Improved protection of critical processes Changes to production/service processes Product range rationalization Dual/multiple sourcing of suppliers Increased levels of key components Continuity plans developed/refined Supplier approval process extended Recovery Time Objective (RTO)

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Strategy Objective Make decisions regarding business continuity strategies and identify actions required for the development of a Business Continuity Plan

Strategic Objectives Remember… the overriding objectives of a BCP are: –…to reduce the time in which products are unavailable to the company’s key customers and markets –…to maintain an optimum volume of sales to these customers & markets while normal operations are being re- established, and –…to ensure the company’s survival

Purpose of Strategy Stop the event Make any interruption “transparent” to your clients Have plans in place to deal with residual risk

Strategies: Corporate Tips Tips to keep in mind when developing strategies: 1. Collect available documentation 2. Six key areas for consideration 3. Identify viable strategies 4. Identify resource and asset needs 5. Methodology for evaluation of strategies 6. Consolidate your strategies 7. Formalize the business unit or division strategy 8. Obtain executive commitment

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework Implement strategies to build resilience Develop response, recovery, and continuity plans

…the Business Continuity Plan …the Business Continuity Plan (BCP) provides a framework for decision-making by: identifying necessary actions to be taken assigning roles & responsibilities establishing resources to implement the plan …that will achieve stated strategic objectives set by the board…

Minimum operations to achieve survival Normal operations BCM: phases of response Time Service Capacity 100% 0% Incident Response Plan Immediate and short term Emergency Response Plans Account for personnel Damage containment Damage assessment Decision to invoke BCP Disaster Recovery Plan Short to medium term Contact staff, customers and suppliers Recover critical business processes locally Recover work schedule Decision to invoke BCP Business Continuity Plan Short to long term Implement business continuity strategies for critical business processes Address customer base and market impact Implement Business Resumption Plan Unplanned business restoration Decision to invoke BCP

Business Unit Plans Provide business function managers with a reference guide early recovery of essential services Identify key internal and external resources Identify mission critical processes Key actions/decisions

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Why Plans Fail Do you know the number one reason why BC plans fail?

Why Business Continuity Training? Needs a series of complex, interdependent and independent tasks to be executed in a coordinated manner under stressful conditions. All personnel need to know: –What is my role? What do I need to do? –Where should I go? Manuals are unlikely to be read during the incident. Situations will arise which will be alien to traditional styles of management for normal operations

To evaluate current BCM competence To identify areas for improvement To validate assumptions To improve confidence To develop teamwork To raise awareness There is no PASS/FAIL, only an accumulation of knowledge Why Business Continuity Training?

BCM: Maintenance Is driven from changes in people, processes, market environment, legislation, risk and business strategy. Ensures your plan is current, accurate, complete and exercised. Should be performed at least annually. Maintenance of your plan:

Summary Exercise your plans –Design and enact plan exercises –Learn from successes and shortcomings –Revise plans accordingly Maintain and improve –Understand changes to business model –Review and refine continuity strategies –Revise plans accordingly

Brian J. Hunt, CPA, CFE, CBCP Senior Consultant FM Global 5700 Granite Parkway, Suite 700 Plano, Texas Linkedin: Protecting the value business creates!

Design for resilience Develop your continuity strategies Keep continuity alive Implement your continuity strategies Understand your business Strategy Culture BCM Framework

Follow-up at your workplace, question…. Do you know which product/service generates most of your profits? Do you know its path through your business? Who is your most critical supplier and what’s the business impact of their failure? Are validated, updated, tested and reasonable BCPs in place across your business? Can your business withstand a major unplanned interruption?

Seven simple questions 1.What is your organization trying to achieve? 2.What products and services does it deliver to achieve this? 3.Which markets does it deliver them to? 4.What processes enable their delivery? 5.How much money do they generate? 6.What could happen to stop these processes? 7.What would happen if these processes stopped?