Everything you want to know about Business Continuity
eBook - ePub

Everything you want to know about Business Continuity

Tony Drewitt

  1. 260 páginas
  2. English
  3. ePUB (apto para móviles)
  4. Disponible en iOS y Android
eBook - ePub

Everything you want to know about Business Continuity

Tony Drewitt

Detalles del libro
Vista previa del libro
Índice
Citas

Información del libro

Everything you want to know about Business Continuity will show you how to develop a modern response to the operational risk landscape and how to prepare your organisation for interruptions to your key activities, minimising the impact on your bottom line, reputation and credibility. You will be able to identify and assess the risks to your company and put in place a ‘fit-for-purpose’ business continuity plan which will enable you to meet the expectations of your customers and stakeholders in the event of an unforeseen incident.

Preguntas frecuentes

¿Cómo cancelo mi suscripción?
Simplemente, dirígete a la sección ajustes de la cuenta y haz clic en «Cancelar suscripción». Así de sencillo. Después de cancelar tu suscripción, esta permanecerá activa el tiempo restante que hayas pagado. Obtén más información aquí.
¿Cómo descargo los libros?
Por el momento, todos nuestros libros ePub adaptables a dispositivos móviles se pueden descargar a través de la aplicación. La mayor parte de nuestros PDF también se puede descargar y ya estamos trabajando para que el resto también sea descargable. Obtén más información aquí.
¿En qué se diferencian los planes de precios?
Ambos planes te permiten acceder por completo a la biblioteca y a todas las funciones de Perlego. Las únicas diferencias son el precio y el período de suscripción: con el plan anual ahorrarás en torno a un 30 % en comparación con 12 meses de un plan mensual.
¿Qué es Perlego?
Somos un servicio de suscripción de libros de texto en línea que te permite acceder a toda una biblioteca en línea por menos de lo que cuesta un libro al mes. Con más de un millón de libros sobre más de 1000 categorías, ¡tenemos todo lo que necesitas! Obtén más información aquí.
¿Perlego ofrece la función de texto a voz?
Busca el símbolo de lectura en voz alta en tu próximo libro para ver si puedes escucharlo. La herramienta de lectura en voz alta lee el texto en voz alta por ti, resaltando el texto a medida que se lee. Puedes pausarla, acelerarla y ralentizarla. Obtén más información aquí.
¿Es Everything you want to know about Business Continuity un PDF/ePUB en línea?
Sí, puedes acceder a Everything you want to know about Business Continuity de Tony Drewitt en formato PDF o ePUB, así como a otros libros populares de Computer Science y System Administration. Tenemos más de un millón de libros disponibles en nuestro catálogo para que explores.

Información

Año
2012
ISBN
9781849282024

CHAPTER 1: THE OPERATIONAL RISK
LANDSCAPE FOR BUSINESS AND OTHER
ORGANISATIONS

Most people in management and senior jobs have a good understanding of risks: what they are, how they are managed and even how to measure them. But there remains in many organisations a blurring of definition about types of risk and who is responsible for them, as well as all sorts of risk that haven’t even been identified.
Like not having insurance, this is usually only a problem if something actually goes wrong, and in the minds of most people that is really rather unlikely. The majority of people tend to be concerned about things that have gone wrong before–and not for others, but for themselves. That is human nature.
Typically, in commercial or ‘for profit’ organisations, risk is divided into ‘core business’ and ‘other’ categories. Core business risks nearly always get far more attention and usually quite rightly. But let’s look again at the three types of risk put forward in this book:
1   that the organisation ceases to be viable due to adverse levels of business, profitability, cost fluctuations and compliance with relevant legislation, contracts and codes;
2   that the organisation’s viability is jeopardised because it engages in some activity that its customers haven’t directly asked for;
3   that the organisation is viable, but its ability to operate is reduced or removed by some unexpected situation, incident or materialised threat.
These risk types aren’t concerned with the cause, or hazard–that comes later–but they should enable most people in an organisation’s management to decide whether all risks should be dealt with by one person or department, or whether there are some different groupings of risks that fall into separate areas.
The business of risk management is not necessarily as straightforward as some other organisational activities; there is no single approved method, either statutory or otherwise. The Institute of Risk Management (IRM) puts forward ‘A Risk Management Standard’ as opposed to ‘The Risk Management Standard’ or even just ‘Risk Management Standard’.
This standard refers to internally and externally driven risks and suggests a number of specific risks in each of four types (see Figure 1).1
image
Figure 1: Risk types suggested by AIRMIC, Alarm & IRM’s structured approach
The Business Link website refers to the risk types shown in Figure 2:2
image
Figure 2: An alternative approach to risk types suggested by Business Link
Most of these approaches actually concern themselves with threats, which is a useful starting point when thinking about operational risks: the risks that the organisation is prevented from doing what it exists to do. But before looking at the sorts of risk that are relevant to business continuity, it’s worth considering a couple of examples of threat types that transcend both core business and operational risks:

Weather

Exceptional weather conditions can affect companies in a number of ways:
1  It can affect the demand for products or services
In 2010 the UK experienced its coldest December for 120 years, coinciding with expected peak demand in the retail sector. The effect on the ‘high street’ was significant and despite the impending increase in the VAT rate from 17.5% to 20% due on 4 January 2011, retail sales dipped substantially whereas, many might have expected them to increase as shoppers anticipated the post-Christmas VAT increase (Figure 3).
image
Figure 3: UK retail sales index, Nov 2009–Jan 2010.
Source: National Statistics Online
This is an example of a core business risk driven by the environmental threat of extreme weather.
2  It can cause a disruption to the company’s operational capabilities
The same threat presented an operational risk for the Royal College of Nursing’s RCN Direct service based in South Wales, as both its telephone call centre and substantial mailing activities were suspended.3
So a number of retail companies will have recorded extreme or adverse weather conditions as a threat, and, therefore, risk, to core business, whereas other organisations like the RCN would have treated the same threat as a cause of operational disruption and, therefore, an operational risk.

Energy

The supply and price of hydrocarbon fuels used in electricity generation can affect companies in at least two ways:
1  Most companies, especially manufacturers, use electricity. But as the demand for hydrocarbon fuels rises, which then leads to increases in price, so the cost of electricity, which forms part of the cost of manufacturing products, rises also. As a result, some manufacturers may face the risk that they can no longer remain competitive in the market. This is an example of a strategic core business risk.
2  There also exists the risk that, as demand for hydrocarbon fuels increases, the ability of generators to convert those fuels into electricity may become unstable, potentially leading to electrical power cuts and the inability to manufacture products. This is an example of an operational risk with the same root cause as the previous strategic risk, the hydrocarbon fuel market.

Operational risk management

It is for each organisation, when considering all of its risks, to decide which are to be treated as interruption risks and so form the basis of the business continuity arrangements. Clearly no organisation should put contingency arrangements in place for a threat that it does not face, but at the same time it should also be aware that certain threats may result in more than one type of risk.
But there are some risks which may be considered operational that are unlikely to give rise to an actual interruption to, or significant reduction in, operational activities. These may include, for example:
•   health and safety–in terms of accidents and incidents;
•   security–such as the theft or loss of equipment, facilities or information;
•   efficiency or productivity.
Again, it is for each organisation to decide whether it wants a fully integrated ‘enterprise’ level risk management system or a number of independent systems, or frameworks, that deal with specific types of risk. The fully integrated approach may make sense in some respects, but in others it is probably counterintuitive for a system that on the one hand deals with the fast-moving risks of something like foreign exchange trading (including in organisations for whom foreign exchange trading is not core business), and on the other with risks, such as health and safety, employment law or information security.
In a probable majority of organisations, there will already be some existing risk management arrangements in place covering a number of aspects of the organisation, and as business continuity gets onto the corporate agenda it may well be ‘added’ onto the responsibilities of an existing team or manager and so almost by default acquire its own risk framework–if, indeed, risk management is to include any kind of formalised approach.
But the opportunity to integrate disparate risk management activities should not be overlooked. There might well be opportunities to improve the efficiency and effectiveness of risk management, and it is often the case that directors and senior managers acquire a better understanding of the organisation’s overall risk profile if they can see everything in a consistent format. There are also examples of a risk control, or mitigation, measure being put in place for one type of risk that then presents a new, or increased, risk in another category. For example, changing an escape route to reduce a fire-related risk could present a new information security risk.
The introduction of business continuity as a new activity or management discipline is often a catalyst for the organisation dramatically to improve its management of risks, particularly those which have previously been paid little attention and of which the Board has limited awareness.

The risk management process

A fairly common failing on the part of directors is that although they are aware of certain risks and may have decided to tolerate them for the time being, they don’t keep any written record of these risks and, in the event something goes wrong, they cannot then account for the fact that one of these risks materialised and cause some loss or injury. This is an exposure that the majority of directors simply don’t need; ignoring a risk that you could be expected to have known about is not good, but making assessment of a risk and noting that you cannot do anything about it at the moment puts you in a much stronger position if and when called to account for it.
The risk management process is described in some detail in Chapter 7 because it is a key component of a BC management system, but it should be understood that business continuity is a key subset of operational risk, which itself is a key component in enterprise risk management, illustrated in the diagram in Figure 4:
image
Figure 4: Business interruption risks in the context of enterprise risk and activities
Needless to say, the example risks in this diagram are just that; some of the operational risks may represent business interruption risks also, but it is likely to vary between organisations.
A BCM programme is likely to be the most successful if it is not allowed to exist in a ‘silo’, and is seen by everyone in the organisation as a key part of the enterprise (or organisation-wide) risk management process. This is more than likely to bring gains in terms of efficiency, conflict avoidance and reduction in expenditure (or executive time).
 
1 A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO31000 (AIRMIC, Alarm, IRM, 2010).
2 Business Link is the Government-funded business advice agency.
3 RCN website, news section.

CHAPTER 2: WHAT DOES BCM ACTUALLY
ACHIEVE?

The recent economic downturn has taught many in the business continuity world that BCM is treated as a ‘discretionary’ activity by many people running organisations of all types.
Do we now wear seat belts in cars...

Índice

Estilos de citas para Everything you want to know about Business Continuity

APA 6 Citation

Drewitt, T. (2012). Everything you want to know about Business Continuity ([edition unavailable]). IT Governance Ltd. Retrieved from https://www.perlego.com/book/5745/everything-you-want-to-know-about-business-continuity-pdf (Original work published 2012)

Chicago Citation

Drewitt, Tony. (2012) 2012. Everything You Want to Know about Business Continuity. [Edition unavailable]. IT Governance Ltd. https://www.perlego.com/book/5745/everything-you-want-to-know-about-business-continuity-pdf.

Harvard Citation

Drewitt, T. (2012) Everything you want to know about Business Continuity. [edition unavailable]. IT Governance Ltd. Available at: https://www.perlego.com/book/5745/everything-you-want-to-know-about-business-continuity-pdf (Accessed: 14 October 2022).

MLA 7 Citation

Drewitt, Tony. Everything You Want to Know about Business Continuity. [edition unavailable]. IT Governance Ltd, 2012. Web. 14 Oct. 2022.