INEVOLVE SB Website

Business Continuity Planning Services.

Free Tools

Free Tools for Developing Continuity Plans and Programs.

Showing posts with label Featured Authors. Show all posts
Showing posts with label Featured Authors. Show all posts

Monday, April 14, 2014

Beware of depending on Third Party Services to assure your daily business and recovery

By Howard ‘Coach’ Pierpont

More organizations are outsourcing portions of their operations these days. Concentrating on the core competency for the organization makes sense in many cases. This allows for the streamlining of internal operations while maximizing the non-core section by utilizing best in class third parties.

The people making the decision to go with a third party need to completely define the statement of work [SOW] and assure that whoever gets the contract follows the SOW. Let me give you an example of a system that was implemented and appeared to be working. At least there was money coming in.

I went to a supplier and requested an item be drop shipped to an east coast location. The supplier had my physical address [not the delivery address] and my mailing or billing address. The supplier contacted the vendor and had the product shipped to the proper location. The vendor was responsible for monthly billing based while I was using the product. Somehow the physical address was sent to the vendor and not the billing address.

Granted, I am in a community where they are creative on their street names, but there is a method. My address is 2124 W 17th Street Road. The vendor input the following address: 2124 W 7th Street Road. There is no such address, but that didn’t seem to make a difference to the vendor who was in turn outsourcing their billing process. Each month they transmitted my information to the billing company. The billing company outsourced the physical bill creation to another party. Each month a bill was created, mailed and later returned by the Post Office as undeliverable.

One month the carrier that handles 7th Street Road went to see the carrier that handles 17th Street Road and asked if there was such an address on that street. Yes, 2 different carriers 10 blocks apart, but at least in the same sorting facility. The 17th Street Road carrier took the mail and put a big question mark on the front and delivered it.

I opened the mail and it contained 4 past due with collection notices and a current invoice. I called the customer service number to get my address fixed. The representative only wanted to set me up for electronic payment. I finally got to speak with a supervisor. She did agree to correct the mailing address and remove the dunning messages before sending me new copies of the invoices.

Soon in my physical address mailbox came the invoices without the dunning messages. Another call revealed a significant flaw in the process. It turns out the process between the billing company and the people that create the physical bill is to create the bill first, make the hardcopy and mail the hardcopy bill. Then in a following process they do the address changes.

Another call to customer service to get the address corrected indicated that their process sequence was flawed. I asked for a good invoice with no penalties for still not having paid.

This took 6 months of my working with either no bills or incorrect bills. This took time on my part to initialize the calls and, on the customer service side, to talk to me and try to resolve the issues. Ultimately this was resolved.

Customer service is a cost to any organization. The best run customer service group can reduce their own costs, adding money to the bottom line as well as potentially up selling the customer due to the positive customer service.

If an organization is going to use a third party to handle the non-core business processes, the methodology needs to be highly defined. It also needs to be tested and reviewed. Someone needs to assure that excellent service is delivered to the customer.

If the process is flawed in daily practice, it will not serve the organization well during a crisis or in recovery. Tabletop tests will not always show how things will work in a disaster situation.

A great Business Continuity Practitioner needs to ask the business how the business knows the process really works.  Use of the Socratic approach to the BIA and reviews will serve every BCP well.

About Howard Pierpont

Contact information:  Howard.Pierpont@disasters.org website: www.disasters.org

With almost 30 years of Business Continuity experience, ranging from global large-scale precision manufacturing to small, stand-alone single site operations, Howard has an extensive and unique background in merging business continuity into continuous operations.
Howard is a Certified Recovery Planner from the University of Richmond, VA as well as a Certified Business Manager with the Association of Professional in business Management, Chicago, IL. He maintains a CBCP from DRII and holds an MBCI designation from BCI.

He is a Charter Member of ICOR and is currently an instructor and training partner with ICOR. Currently, as a DHS/FEMA Reservist Community Recovery Specialist, he works with businesses, nonprofits and municipal governments in communities having received federal disaster declarations. Howard also serves as Board Chair for the Disaster Preparedness and Emergency Response Association.

                       ______________________________________________________

Tuesday, April 8, 2014

Recovery: Least Understood of the Continuity Lifecycle Elements

The post-crisis recovery phase is one of the least addressed in planning, training and simulations.  This is an area that, if not properly managed, can cost financially, reputationally and operationally.  Communications, internal and external are, at best, misjudged.  Guidelines for recovery are lacking and most entities lose focus when it comes to discussing recovery operations.  It may be that recovery is one of the most complicated of the lifecycle elements and that no two recoveries are going to follow the same pattern.  However, the recovery process can be segmented into manageable bits that can be undertaken using a project management approach.

Business Continuity Lifecycle – A Perspective on Recovery

Figure 1, entitled, “Business Continuity Lifecycle” provides a top level graphic depiction of the typical cycle of event response, management, recovery and resumption of operations.  I have added the emergency response and crisis management elements as they intermingle with business continuity.  I have simplified the cycle to four major transition points.  Transition point 1 is the reactive response phase, where we react to events and invoke emergency response actions.  This phase is characterized by activation, reactive response and chaos control.


Transition point 2, I have titled “Unplanned Disruption”.  This is the phase where we begin to identify and address the unplanned developments that result from the event and the reactive response to the event.  Unplanned disruption would include those elements of surprise that the planning effort did not directly address or completely overlooked.  During this phase it is possible that crisis management becomes the lead element in the business continuity process.

Transition point 3, I have titled “Planned Disruption”.  It is in this phase that the plan is actually working as it was written (well perhaps).  This phase is critical to recovery as the recovery planning, based on actual reentry assessment activities, should commence and the recovery team should be transitioned in to the organization.

Transition point 4, I have titled “Termination”.  It is in this phase that recovery activities are in full swing.  Restoration and resumption of business operations are underway.  The resumption activities may still be conducted at an alternate location (if an evacuation has occurred).  During this phase the recovery team is moving dislocated units, entities, etc. back to the normal work area.  It is critical in this phase to get it “right” so that the transition back does not create a new event/crisis.  Note that on figure 1, I have differentiated the Recovery Management aspect, as well as the “Business Recovery” and the “Systems/Information Recovery” activities.

Business Recovery involves more than the recovery of systems/information.  Activities, such as Finance, Marketing, Legal, Production, internal support and external support (“Value Chain”) have to be reset and integrated back into the organization.  Depending on the severity of the event, realignment of operations, reorganization and resetting of corporate goals/objectives may be necessary.  While too numerous to delineate in this space, one should have a plan that outlines the functions and areas within the organization.  This plan should establish timelines for recovery of these activities and reintegration into the business operation.  To ensure smooth transition from event termination to recovery and resumption of “normal business” operations a touchpoint assessment should be part of the recovery process.  This assessment would identify the various touchpoints that major units have in order to incorporate them into the recovery timeline.  For example, if a production unit is coming back on line and new or altered processes are being put in place; training may be required for operators/staff.  The touchpoint with Human Resources would be the training program and certification of staff to operate in the new/altered environment.

Concluding Thoughts

While I have highlighted some aspects of the recovery process in this brief article, I think it is necessary to offer a suggestion regarding recovery plan validation activities.  Some may use the term “drills and exercises” or “simulations” or “war gaming” to describe the validation process.  Designing, developing and implementing a “Recovery Exercise” is, in my experience, a very rare occurrence.  I would recommend that planners take a moment to assess the actual recovery capabilities of their organization.  Design, develop and implement a drill or exercise; whether tabletop or full scale, to see if recovery operations can actually be undertaken and carried out as described in the plan or in the thought process of the organization.  This is an ideal situation for involving the public sector and the “Value Chain” components within your planning framework.  The focus should be on identification of flawed decisions to establish a context for correcting flaws within the risk assessment, business impact assessment process.

About Geary Sikich – Entrepreneur, consultant, author and business lecturer

Contact Information: E-mail: G.Sikich@att.net or gsikich@logicalmanagement.com. Telephone: 1- 219-922-7718.


Geary Sikich is a seasoned risk management professional who advises private and public sector executives to develop risk buffering strategies to protect their asset base. With a M.Ed. in Counseling and Guidance, Geary's focus is human capital: what people think, who they are, what they need and how they communicate. With over 25 years in management consulting as a trusted advisor, crisis manager, senior executive and educator, Geary brings unprecedented value to clients worldwide.

He holds a B.S. in Criminology from Indiana State University and a M.Ed., in Counseling & Guidance from the University of Texas at El Paso. A well-known author, his books and articles are readily available on Amazon, Barnes & Noble and the Internet.


 ____________________________________________________________

Monday, March 24, 2014

Tackling the Business Impact Analysis

A new business continuity analyst will need to create and/or update the organization's Business Impact Analysis (BIA). If this is a task that is new to the organization, then the analyst will need to scope the document and set out the definitions that will be used. Ideally the entire organization will be represented in one or more BIAs. The analyst should present to the sponsoring executive the plan for accomplishing the BIAs. The analyst will need to:


a) describe the objectives of the BIA,

b) show that the focus will be on the business processes,

c) introduce the concepts and terminology such as (RTO), and

d) identify the planned sources of information and validation.

It is important to focus on processes rather than procedures. There should be relatively few processes, however each process can have many procedures. To use an example common to many organizations, the Human Resources Department may have four processes: hiring/termination, benefits, periodic reviews, and payroll. The procedures for each of these processes may change repeatedly due new software, regulations or vendor requirements. Therefore the analyst should not try to capture details of the procedures but reference their location within the department. Depending on the organization, BIAs may be reviewed and updated on a periodic basis. In addition to periodic updates, any significant changes to business process(es) should prompt a BIA review.

Given resource or budget constraints, if BIAs can not be done for the entire organization, then the analyst needs to work with the sponsoring executive to determine which departments and processes are to be considered core to the organization’s mission.

For each process the BIA will identify the needed resources. These include people (do not forget any on premise long-term consultants), facilities, equipment, and supporting information technology. The analyst will need to note any unique features of the facility that the process uses (e.g. loading dock, clean rooms, vaults). A roster of staff and roles is important to understanding the scale of the process and the relative impact should members of the staff become unable to work. Regarding the IT resources needed, be sure to include required reference databases with applications. Also query the business for any specialized communications gear or production equipment such as check printers. Remember any handheld devices which are needed to generate sales or manage logistics. While business moves relentlessly to electronic formats, an inventory of required paper-based documents and supplies needs to be inventoried.

Once the who, what, and where have been established, the next step is determining the impact to the organization if the process can not be done. Various metrics and units of measure can be used; the analyst needs to assimilate what has been learned so far and determine the outage time frames to be used in the discussion and analysis.

What are the time frames of a business or transaction cycle? Are tasks and deliverables accomplished in weeks, days, hours, minutes, or seconds? Depending on what the business timeframes are, construct an appropriate scale for determining impacts over time. Impacts can have various dimensions: financial, reputational, legal, regulatory plus any dimension that may be important to the organization. Again, need to determine the scales for each dimension you use. The disaster may also involve the loss of data. The analyst must determine with management how little data can be lost and the associated time frame(s).

The result will be a series of RTO values that need to be coupled with RPO values.

As an analyst, you will now have a wealth of data. It is up to you to turn this data into Information that can be used in the subsequent steps towards the goal of a robust business continuity program. You will need to clearly identify the processes that are necessary for the business to carry out its mission and provide management with an understanding as to the impact should a given process stops. This will provide the inputs to the risk assessment and the basis for the business continuity plans to follow.
Tom Ryan has worked as the global business continuity manager for RBS Sempra Commodities, starting their program from a scratch to cover six trading locations with two recovery sites with data centers.  He has done business impact analysis and emergency management consulting work with Datalink, Inc.  Previous to his roles in business continuity, Tom managed a software QA testing department and was an auditor for major investment banks.
______________________________________________________

Tuesday, February 4, 2014

The Core Documents of Business Continuity Planning – Getting Started

By Tom Ryan

Congratulations!  You've just landed a job or assignment in the Business Continuity department for your company and its time to get started.  As you navigate the though the issues, it is important to remember the mission is to reduce risk to the organization by minimizing the impact of a disruptive event.   To do this you will rely on many members of the organization, from senior management to the mailroom. 

There are several core documents to be developed and revised over the course your business continuity career.  They are the Business Impact Analysis (BIA), the Risk Assessment, the Business Continuity Plan (BCP), the exercise/test plans, and the governance reporting.   But the true core deliverable, in the moment of need, is the business continuity plan.

I put the BIA first on the list of documents to create over the Risk Assessment.  You will learn that there are different schools of thought as with any discipline.  In my view, understanding what is critical to the organization is a prerequisite to scoping the risk assessment.  For example, if you run a warehousing business the critical processes will be different from that of a hospital or a financial services company.  These processes will have their own risk profiles and understanding those risks are important.

The true core document is the business continuity plan.  This is the document that will address the risk to the organization; this is the operational document to use in the event of a disaster or lesser incident.  Again, there are schools of thought on the scope and development of the BCP.  One school will look only at the impact and begin at the point of the outage.  My view is that scenario plans can be useful, particularly for events that occur on a regular basis (e.g. hurricanes and blizzards).

To ensure that the BCP is valid, sufficient, and effective one needs to test it.  Each organization will develop a test plan(s) according to its situation.  Some organizations may not be able to conduct a test.  In these less than ideal circumstances, the business continuity planner should conduct a series of desktop exercises to discuss the plan, procedures that need to be followed, and potential issues.

The conclusion of tests and/or exercises then leads to governance reporting.  Typically this will be to the business managers associated with the tests.   These reports will review the scope and objectives of the test, issues raised as a result of the tests, and the action plan to resolve or mitigate those issues.   A summary of the tests should be sent to the sponsoring senior manager, senior stakeholders, and appropriate risk committees.

The communication with senior management should illustrate the nature and means that the business continuity plan will reduce the impact of a disaster to the organization.

Tom Ryan has worked as the global business continuity manager for RBS Sempra Commodities, starting their program from a scratch to cover six trading locations with two recovery sites with data centers.  He has done business impact analysis and emergency management consulting work with Datalink, Inc.  Previous to his roles in business continuity, Tom managed a software QA testing department and was an auditor for major investment banks.


______________________________________________________

Wednesday, January 15, 2014

Redefining the BIA – Usefulness and Uses

By Geary W. Sikich
Copyright© Geary W. Sikich 2014. World rights reserved. Published with permission of the author.

If we agree on the basic premise that Business Continuity can be defined as sustaining what is critical to the enterprise’s survivability during periods of discontinuity; then we must recognize that the activity known as the Business Impact Assessment (Analysis) or BIA needs to be redefined. The BIA, as currently practiced does not necessarily achieve the following:

  • Define what is critical to the organization;
  • Develop strategies to recover/sustain during times of discontinuity.

I posit a two phase BIA framework consisting of a pre-event general analysis and a post-event identification and assessment of business impacts and potential consequences for the enterprise. Events are nonlinear and therefore carry uncertain outcomes. As a result, traditional pre-event BIAs are of little value when conducted using concepts such as mission critical, recovery time objectives, recovery point objectives, etc. Events evolve; the elements of randomness and nonlinearity create opaqueness (opacity: the quality of being difficult to understand or explain) that a traditional BIA underestimates.

Pre-Event General Analysis: Points and Questions

1. Customers – Sustainability within current markets, capacity to overcome disruptions and continually transform to meet the changing needs and expectations of customers, shareholders and stakeholders.
2. Current Competitors – Define immediate market areas and determine strength of competition to influence market share, human capital, customer base.
3. Providers – Sustainability, strength in markets served, loyalty, capacity to manage surge.
4. Suppliers – Ability to influence capabilities to provide product/services, readily available alternatives.
5. Stakeholders – Capability to meet expectations.
6. Government/Geo-Political – Regulatory agencies and compliance scrutiny, potential actions – direct impact, potential actions – indirect impact.
7. Substitutes – Readily available alternatives, differentiating qualities.
8. New Entrants – Barriers to entry, financial challenges, customer loyalty, customer tolerance level.
9. Economic – Changing market demands for services/products (internal/external).
10. Social – Human capital, skills, perception/image, moral, ethical impacts.
11. Technology – Infrastructure (internal/external) ability to handle surges, vulnerabilities, cascade effects of failure.
12. Financial Capacity – Ability to draw on reserves to offset cash flow disruption.

The second phase BIA focuses on the evolving situation (nonlinearity, uncertain outcomes, etc.) – identification and assessment of business impacts and potential consequences for the enterprise as they are unfolding. We rarely make a credible attempt to identify post-incident impacts and consequences in any significant detail. So, re-entry, recovery, restoration and resumption of operations are step-children that are skimmed over in the traditional BIA process.
Below are key analysis areas for an “Active Analysis” framework, as follows:

  • Human Capital – consisting of management, employees, stakeholders, suppliers, providers, partners, contract/vendor entities, etc.
  • Clients – consisting of current, new and former customers.
  • Systems – consisting of internal operating systems and critical external infrastructures.
  • Suppliers – consisting of providers of essential business logistics/services, etc.
  • Utilities – consisting of electric, gas, water and telephone service providers.
  • Telecommunications – consisting of internal telecommunications systems linked to external telecommunications providers.
  • Energy Supply – consisting of energy delivery systems and energy support systems.
  • Government Services – consisting of emergency management, police, fire, emergency medical, Federal, State and local government bodies and political support systems.
  • Transportation – consisting of air, land and water transportation system and support systems.
  • Financial Services – consisting of financial markets, investments, statutory deposit requirements and cash flow systems.

Each of these elements would be constantly assessed as part of an “Active Analysis” post-event BIA framework to determine the potential impact of loss or degradation to the enterprise and its networks. The above is an example and is not meant to be exhaustive. In the post-event environment you will have to be creative and you will have to be responsive.

Conclusion

When it comes to building your BIA program, focusing on survivability is the right approach, provided you have thoroughly done your homework and understand what survivability means to the organization. Post-event opacity will produce numerous situations that challenge survivability. Looking in the rearview mirror of the traditional BIA can result in confusion, chaos and unintended consequences.

Copyright© Geary W. Sikich 2014. World rights reserved. Published with permission of the author.
Copyright 2014, Geary W. Sikich and Logical Management Systems, Corp., all rights reserved.

Geary Sikich is a Principal with Logical Management Systems, Corp., a management consulting and executive education firm with a focus on enterprise risk management and issues analysis; the firm's web site is www.logicalmanagement.com.
______________________________________________________