Continuity management has long been tied to disaster planning and crisis response as fundamental to emergency planning but the reality is: If you’re just practicing business continuity to survive you’re never going to get much out of it.
The key to effective value creation from continuity management is a strategy that builds on how the day-to-day business is designed to create value. Today’s global market puts us all in crisis. Corporate directors are in jail. Cyber terrorists can easily hide across borders around world yet still access information kept locked away. States and countries declare bankruptcy. Instability is everywhere.
Businesses are so interdependent on one another that supply chain and technology are complex grey zones of value and accountability. The bottom line is the business needs to create value to survive. Maybe value means money, maybe it’s customer satisfaction or maybe it’s serving its nonprofit goal. Regardless, the creation of that value must be the crux of your resilience plans.
One of the most common misconceptions of business continuity planning is that it starts with a disaster and in a lucky world no one would need a plan. Luck favors the prepared. A business with a healthy continuity management program doesn’t just survive crisis; it thrives daily. The reality of the business world is that every day is more complex and risk loaded. In order to work toward corporate maturity and institutionalization of the systems that create value you have to structure and live your plan.
From DCS Planning’s partner CoreXchange Colocation Services:
CoreXchange deeply admires companies like DCS Planning that provide well-crafted solutions that protect businesses and organizations from painful and deeply damaging data loss.
Every company should have thoughtful, thorough business continuity and disaster recovery plans like the ones offered by DCS Planning. Every company needs to invest in risk assessment and a business impact analyses — again, just like the services offered by DCS Planning.
But every expertly crafted disaster recovery and business continuity plan needs to be built upon a cutting-edge, fault-tolerant network infrastructure that’s ready to withstand the digital age’s most nefarious elements.
Colocation provides a multitude of elements — including hardened space, highly managed environmentals, power & cooling, physical security, and connectivity to telecommunications and network service providers — to better protect and manage companies’ servers and networking equipment.
For example, CoreXchange’s data centers are supported by state-of-the-art power systems featuring redundant 1.5 MQ generators and four 500-ton chillers. This nearly eliminates the possibility of electrical downtime and gives us tight control over the internal environment. We also leave no stone unturned when it comes to security: Our center includes perimeter fencing, 24/7staffed check-in station with mantrap, and internal and external video surveillance.
Colocation with CoreXchange along with a solid plan from DCS Planning can be the bedrock on which your company’s data security, viability and peace of mind rests.
Yes, for the next year or two your bank examiner may make the mistake of crediting you for exercising your disaster plan when you documented an actual crisis but let’s take a step back and think about this before we consider it a “win”.
Experiencing a crisis or disruption does not meet the standard for exercising your plan and should not be adequate to count as testing your plan for many reasons. Including:
- Under best practice continuity management guidelines it is clear that establishing and testing an exercise program is not the same as documenting events that threaten or impact the business. These are two separate best practices.
- FFIEC examination guidelines state “The board and senior management should establish a testing program appropriate for the size, complexity, and risk profile of the organization and its business lines”. Passively experiencing crisis does not demonstrate a testing program has been established and, no matter what the extent of the crisis, will it be appropriate for the size, complexity and risk profile of the organization. In fact, it may be counter productive and make you look unprepared because you didn’t plan a test.
- Community banks are likely to have experienced 6-12 crises in a year. What makes this one particularly meaningful? Did you document the other ones? What are your standards for documentation?
- Test objectives were not set or met (no, “survival” does not count) and only one part of your response plan was tested. The “test” was not comprehensive.
- Since you weren’t planning to experience this problem, exercise controls were not in place when you had it. You can only manage what you measure.
- Hypothetically, would you consider going to the emergency room because you thought you might be having a heart attack to be an indicator for your ability to deal with stress? Technically the answer is “Yes”. However, that’s certainly no way to live and if this is your common practice then it indicates you don’t really have a good plan for your health. The same is true for your organization. Why have a heart attack to wait to check and see if your blood pressure is too high? It’s easier to use a blood pressure cuff and check your heart rate.
Let’s speak the truth: This is not the attitude of a healthy, mature business and will not, for much longer, meet requirements for safety and soundness.
Now, before you get frustrated, I realize you don’t want to do continuity management this way. You have a LOT on your plate that you’d rather be getting to (call reports anyone?) and you’re just not sure where to get started. So, DCS has set up some fantastic tools to make planning exercising EASY for you! Get excited now and bookmark this for future reference! First, go ahead and log that problem you had on our FREE Crisis Event Log. It’s got a couple of brief questions to help you get down the information you need to learn from and properly document the problem.
Next, use our FREE Strategic Road Map to get an idea about what a good, well-rounded financial institution can do on to build operational strength. NO, you don’t have to do that big fail-over test right away. We actually recommend against it. Start drilling the little things first. Can you guarantee that you can contact everyone when they’re not at work? Try your call tree out and write down what happens. That’s a great test!
Another quick tip is to see what your IT provider is doing to test regularly. We often find out the IT department regularly tests failover procedures but rarely documents it adequately for oversight or examination requirements. All you have to do is start documenting! It’s easy! You can do that!
We have also started a new product line: DIY Turnkey Continuity. We’re building very strong key kits for your continuity tool case at affordable prices. We’ve started with a data breach kit and will be releasing an exercise kit before the end of the summer. For our BOL friends, we are looking for pilot users to test these at a discounted rate! Private message me if you’re interested. Also let me know what other kits you’re interested in. Pandemic, social media and vendor management are on our list for 2013.
I hope these ideas help out. We realize you are doing everything you can to keep compliant and the business moving in a positive direction. Please let us know what else we can do to make your job easier!
Operational risk has eclipsed credit risk as national banks’ chief safety and soundness challenge, Comptroller of Currency Thomas Curry told the Exchequer Club in Washington, D.C., last week.
Operational risk – the risk of loss due to failures of people, processes, systems and external events – is “high and increasing,” Curry said. He cited flawed risk models, lack of adequate controls over third party vendors and anti-money laundering efficiencies as some examples of operational risk.
“[A]s banks and thrifts face greater resource constraints and higher compliance costs, they may feel greater pressure to economize on systems and processes in order to enhance their income and operating economies …,” Curry said. “All institutions … must resist the temptation to under-invest in the systems and controls they need to prevent greater risk and larger losses in the future.”
He emphasized the risk of operational failure is embedded in every activity and product – from a bank’s processing, accounting and information systems to the implementation of its credit risk management procedures.
“No issues look larger today than operational risk in all its dimensions, the manner in which all risks interact, and the importance of managing those risks in an integrated fashion across the entire enterprise,” Curry said. “These themes are a supervisory priority for us at the OCC today and they should similarly command the attention of the industry.”
reprinted from the Oklahoma Bankers Association Weekly Update, May 21, 2012
It might be an auto repair shop washed away by a flood. A dentist’s office scorched by a fire. A dry cleaner hit by a tornado. A pet store frozen by an ice storm and power outage. There are lots of sorts of businesses, and lots of kinds of disasters, but one thing remains the same: businesses disrupted by disaster permanently close their doors at an alarming rate. In fact, according to the Insurance Institute for Business and Home Safety, one in four small businesses closed by a disaster never re-opens.
So, when the unthinkable happens, will you be prepared to lead your business through the crisis? Preparedness is the key! By creating a disaster recovery and business continuity plan, your business can increase its recovery capabilities dramatically. A plan can help you make the right decisions quickly, cut downtime, and minimize financial losses. It can even help you avoid certain disasters through planning and mitigation measures.
The prospect of creating and implementing such a plan can be daunting, but business leaders in Tulsa have a unique opportunity to get a head start on the process by attending A Day Without Business, a business continuity summit hosted by Tulsa Partners’ Disaster Resistant Business Council.
A Day Without Business will take place on Thursday, March 15, 2012 from 9 a.m. to 3:30 p.m. at the Holiday Inn – City Center in downtown Tulsa. Registration is open through March 2, online at www.tulsapartners.org or by phone at 918-632-0044. The cost for the one-day event is $65, and space is limited.
The event’s opening speaker will be Tulsa Chamber of Commerce President and CEO Mike Neal. The luncheon keynote speakers will be Rob O’Brian and Tonya Sprenkle, President and Vice President of the Joplin Area Chamber of Commerce, who will share about their Chamber’s experience with the May 2011 Joplin Tornado.
The lead sponsors for A Day Without Business are Tulsa Partners’ Disaster Resistant Business Council, State Farm Insurance, TRC Disaster Solutions and Williams. Other participating organizations for the event include the Insurance Institute for Business and Home Safety, Titan Data Services and the Tulsa Health Department.
For more information about A Day Without Business, contact Tulsa Partners at 918-632-0044, email@example.com, or www.TulsaPartners.org.
Written by guest blogger Jessica Hill
Given that you agree with the recent post on every business having the same four core values . . . let’s continue our discussion.
Here’s a diagram for visualization: Business Value Balance. Each operational value exists in a spectrum (generally from happiest to least happy). Depending on the current score for each value on their respective spectrum, business is probably good. Referring to the chart, you can see the business as the core, four-pointed star. When the staff is happy, the customers are happy, the business is generally likable and its making a profit the business is sustainable.
There’s another star, too: a red, eight-pointed star. The eight-pointed star is the zone of risk tolerance. If you chart the scores of the four requirements for sustainability within the level of tolerance, it’s holding steady. If the level of value isn’t meeting or exceeding the least tolerable level, then its a problem. Simple enough. When one or more of the scores exceeds the level of tolerance, the business will naturally look for ways to move back toward a balance.
HERE’s THE CATCH: How the business finds its way to pull one score back to center could happen at the cost of another value. And, if no one’s managing the balancing act, it will be at the cost of another value. They’re all interrelated so they will all be effected.
If you don’t have plans to deal with keeping the four basic core values in balance, business ends up looking chaotic. It is constantly in flux, always pulling and pushing at itself. Costing the happiness of staff, the happiness of clients, likability and profit. This diminishes sustainability and resilience.
Next blog: keeping the business values at the center of your continuity program.
What do you think? Do you agree? Disagree? Case studies?
It’s astonishing in it’s simplicity. The business often gets left out of disaster recovery and the resilience picture. Disaster recovery is the continuity of your information systems but you certainly can’t recreate your business with simply a server. That server has to live somewhere, it needs people to love and care for it and it needs a purpose. Your IT manager cannot determine your purpose. It must be held in the core vision of the organization. Your plan needs the core competencies of your organization – how you create value. This is the deliverable for the Business Impact Analysis process. Don’t leave yours out!