SlideShare ist ein Scribd-Unternehmen logo
1 von 25
Building organizational resilience amidst global uncertainty:
An overview of business continuity and crisis management for today’s global leaders
Bryan Strawser, MBCP, MBCI, CISSP, CEM
Principal Consultant & CEO
Data Breaches
Company Impacted People
Sony Pictures 6,000
Sally Beauty 25,000
Neiman Marcus 1,100,000
Michaels Stores 3,000,000
Community Health Systems 4,500,000
PF Chang’s 7,000,000
Home Depot 56,000,000
Target 70,000,000
JP Morgan 76,000,000
Anthem 80,000,000 (still being evaluated)
eBay 145,000,000
7
The Last 24 Months
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Global Standards
Business Continuity
• ISO 22301 (formerly BS25999)
• NFPA 1600
• ASIS Business Continuity Management Standard
• ASIS SPC.1: Organizational Resilience
US Government
• Federal Continuity Directives (FCD 1 / FCD 2)
• Continuity Guidance Circulators (CGC 1 / CGC 2)
8
Business Continuity and Emergency Management
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
• Formerly BS25999
• Adopted globally in 2012
• Intersects with other ISO
Standards
– Ex: ISO 27001
• Establish and maintain a
Business Continuity
Management System
• Accreditation
• Certification
– Implementer / Lead
– Auditor / Lead
9
ISO 22301:2012
Societal Security – Business Continuity Management Systems
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Professional Certifications
Business Continuity
• Disaster Recovery Institute International
– Associate Business Continuity Professional (ABCP)
– Certified Business Continuity Professional (CBCP)
– Master Business Continuity Professional (MBCP)
• Business Continuity Institute
– Member, Business Continuity Institute (MBCI)
– Fellow, Business Continuity Institute (FBCI)
Emergency Management
• International Association of Emergency Managers
– Associate Emergency Manager (AEM)
– Certified Emergency Manager (CEM)
10
Business Continuity and Emergency Management
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Business Continuity Regulations
United States
• Federal Financial Institutions Examination Council (FFIEC)
• Securities and Exchange Commission (SEC)
• Financial Industry Regulatory Authority (FINRA)
• Payment Card Industry Standard (PCI)
11
We’re from the government, we’re here to help…
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
12
Business Continuity Lifecycle
ISO 22301 Business Continuity Management Lifecycle
Business Impact
Analysis & Risk
Assessment
Develop BC
Strategies
Establish &
Implement BC
Procedures
Exercise,
Testing,
Maturing
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
13
Business Impact Analysis & Risk Assessment
Identifying critical business functions & their risks
Business Impact Analysis
• What are the critical business
functions at my company?
• How long can they be disrupted?
• How quickly can they be recovered
today?
• What is the impact from that
disruption to my business?
• BIA Methods
Risk Assessment
• What are the risks to these
functions?
• What are our top enterprise risks?
• Risk Assessment Methods
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Specific actions to manage
your risks and address your
opportunities
• Prepare your business for
disruption
• Develop Business
Continuity Plans
• Implement Business
Continuity Solutions
14
Develop BC Strategies
How can I recover my critical functions in the time period needed?
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Core Components of a BC Plan
• Roles & Responsibilities
• Activation process
• Managing the immediate
consequences
• Communication plan
• Recover prioritized activities
• Media response
• Process for standing down
15
Develop BC Strategies
Business Continuity Plans
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
16
Establish & Implement BC Procedures
What processes will I follow in a disruption?
Specific defined processes for
Business Continuity
Examples:
• Emergency preparedness
• Governance
• Activation
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
• All plans should be exercisesd
at least annually:
– Notification
– Table Top
– Recovery
– Fully integrated
• Disaster Recovery
– Testing DR plans and strategies
• Defined process for capturing
lessons learned and applying
to plans and strategies
17
Exercise, Testing, & Maturing
How will I exercise and test my plans? Based on those results, how will I improve?
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Awareness
Executive Leaders & Board Members
• An understanding of risk across the organization
• Broad, strategic overview of the program
• Clear understanding of decision making rights and their roles
• Metrics & program maturity
Typical Employee
• Emergency procedures
• High-level understanding of business continuity
Critical Function Leaders
• Understanding of how function connects to the broader business strategically
• Can describe dependencies on technologies and other functions
• Takes ownership of planning process for critical function
• Fully understands business continuity & disaster recovery plans for function
18
Connecting to Security Education and Awareness
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Crisis Management
The active management of a disruption or escalating situation
Items to consider:
• Clear roles and responsibilities
• Decision making rights pre-defined
• Single source of truth for executive & board communication
• Communication products / messages
• Cross-functional coordination
19
A Component of Business Continuity Management
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Crisis Management
Green
Team
Yellow
Team
Red
Team
20
A Simple Framework Example
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
• “Disaster Recovery”
generally pertains to the
recoverability of IT systems
– Applications
– Infrastructure
• Must be closely linked to
business continuity
capability
• Should heavily utilize the
BIA findings to influence a
tiered recovery strategy
21
Disaster Recovery
Business Continuity for IT Systems
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
• 2013 Target Corporation
HQ Flood
• Primarily impacted non-
critical teams
• Flexibility in planning and
crisis management
framework enabled
response despite lack of
function specific plans
• Lessons Learned
22
Case Study
When a drip becomes a flood…
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Advice on Building a BC Program
• Keep things simple
• Establish clear governance up-front
• Pick a standard to guide your implementation
• Select the leader of the program carefully
– Professional certifications / subject matter expertise
– Presence / Communication skills
• Understand local, regional, country level risk
• Bring in experts where needed to augment
• This is not rocket science!
23
Practical tips for success
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Contact Information
Contact Bryan:
Bryan Strawser
Principal Consultant & CEO
Phone: +1-612-235-6435
E-Mail: bryan@bryghtpath.com
Twitter: @bryanstrawser
Learn more about our services and how we
can help you:
Website: www.bryghtpath.com
Twitter: @bryghtpath
Facebook: facebook.com/bryghtpathllc
24
Bryghtpath LLC
Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
Our Consulting Services Include:
Business Continuity
Crisis / Emergency Management
Enterprise Risk Management
Exercise Design & Facilitation
Global Intelligence & Security
ISO Training & Certification
Travel Risk & Security
Building organizational resilience amidst global uncertainty:
An overview of business continuity and crisis management for today’s global leaders
Bryan Strawser, MBCP, MBCI, CISSP, CEM
Principal Consultant & CEO

Weitere ähnliche Inhalte

Was ist angesagt?

The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...BCM Institute
 
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...BCM Institute
 
Globals - Too Big to Govern?
Globals - Too Big to Govern?Globals - Too Big to Govern?
Globals - Too Big to Govern?Resolver Inc.
 
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...BCM Institute
 
Bci NeBe conf 2017 thought provoking - you cant manage crisis on your own v...
Bci NeBe conf 2017   thought provoking - you cant manage crisis on your own v...Bci NeBe conf 2017   thought provoking - you cant manage crisis on your own v...
Bci NeBe conf 2017 thought provoking - you cant manage crisis on your own v...TheBCI
 
Flaws in M&A Workshop
Flaws in M&A WorkshopFlaws in M&A Workshop
Flaws in M&A WorkshopSheena Tooke
 
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...BCM Institute
 
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...PECB
 
Social Collaboration - A path to business value
Social Collaboration - A path to business valueSocial Collaboration - A path to business value
Social Collaboration - A path to business valueSIKM
 
ACHIEVING RESPONSIBLE SUPPLY CHAINS
ACHIEVING RESPONSIBLE SUPPLY CHAINSACHIEVING RESPONSIBLE SUPPLY CHAINS
ACHIEVING RESPONSIBLE SUPPLY CHAINSRCS Global
 
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...BCM Institute
 
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sd
Bci NeBe conf 2017   keynote - making sense of resilience - james crask - sdBci NeBe conf 2017   keynote - making sense of resilience - james crask - sd
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sdTheBCI
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...TheBCI
 
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...BCM Institute
 
Bci NeBe conf 2017 thought provoking - results of bci siemens survey on meg...
Bci NeBe conf 2017   thought provoking - results of bci siemens survey on meg...Bci NeBe conf 2017   thought provoking - results of bci siemens survey on meg...
Bci NeBe conf 2017 thought provoking - results of bci siemens survey on meg...TheBCI
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceResolver Inc.
 
Risk Managing Change
Risk Managing ChangeRisk Managing Change
Risk Managing ChangeSimonWills15
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core ConsultingCORE Consulting
 

Was ist angesagt? (20)

The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
 
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
 
Globals - Too Big to Govern?
Globals - Too Big to Govern?Globals - Too Big to Govern?
Globals - Too Big to Govern?
 
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
 
Bci NeBe conf 2017 thought provoking - you cant manage crisis on your own v...
Bci NeBe conf 2017   thought provoking - you cant manage crisis on your own v...Bci NeBe conf 2017   thought provoking - you cant manage crisis on your own v...
Bci NeBe conf 2017 thought provoking - you cant manage crisis on your own v...
 
Flaws in M&A Workshop
Flaws in M&A WorkshopFlaws in M&A Workshop
Flaws in M&A Workshop
 
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
 
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
 
Social Collaboration - A path to business value
Social Collaboration - A path to business valueSocial Collaboration - A path to business value
Social Collaboration - A path to business value
 
ACHIEVING RESPONSIBLE SUPPLY CHAINS
ACHIEVING RESPONSIBLE SUPPLY CHAINSACHIEVING RESPONSIBLE SUPPLY CHAINS
ACHIEVING RESPONSIBLE SUPPLY CHAINS
 
Michigan Bankers Association Best 2014 enterprise risk management ppt
Michigan Bankers Association Best 2014 enterprise risk management pptMichigan Bankers Association Best 2014 enterprise risk management ppt
Michigan Bankers Association Best 2014 enterprise risk management ppt
 
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
 
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sd
Bci NeBe conf 2017   keynote - making sense of resilience - james crask - sdBci NeBe conf 2017   keynote - making sense of resilience - james crask - sd
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sd
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
 
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
 
Bci NeBe conf 2017 thought provoking - results of bci siemens survey on meg...
Bci NeBe conf 2017   thought provoking - results of bci siemens survey on meg...Bci NeBe conf 2017   thought provoking - results of bci siemens survey on meg...
Bci NeBe conf 2017 thought provoking - results of bci siemens survey on meg...
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Risk Managing Change
Risk Managing ChangeRisk Managing Change
Risk Managing Change
 
Pursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management GuidelinesPursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management Guidelines
 
Risk management models - Core Consulting
Risk management models - Core ConsultingRisk management models - Core Consulting
Risk management models - Core Consulting
 

Andere mochten auch

Organizational change for sustainability
Organizational change for sustainabilityOrganizational change for sustainability
Organizational change for sustainabilityJustin Yuen
 
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...Value of Integrating Air Regulatory Compliance and Air Pollution Control with...
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...Antea Group
 
Resilience presentation
Resilience presentationResilience presentation
Resilience presentationJoe Krause
 
CCTV Camera Presentation
CCTV Camera PresentationCCTV Camera Presentation
CCTV Camera PresentationBasith JM
 

Andere mochten auch (7)

Organizational change for sustainability
Organizational change for sustainabilityOrganizational change for sustainability
Organizational change for sustainability
 
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...Value of Integrating Air Regulatory Compliance and Air Pollution Control with...
Value of Integrating Air Regulatory Compliance and Air Pollution Control with...
 
Nurses day may 2016
Nurses day may 2016Nurses day may 2016
Nurses day may 2016
 
Resilience presentation
Resilience presentationResilience presentation
Resilience presentation
 
CCTV Camera Presentation
CCTV Camera PresentationCCTV Camera Presentation
CCTV Camera Presentation
 
Cctv presentation
Cctv presentationCctv presentation
Cctv presentation
 
PPT FOR SECURITY
PPT FOR SECURITYPPT FOR SECURITY
PPT FOR SECURITY
 

Ähnlich wie Building Organizational Resilience Presentation - ISSA Special Interest Group in Security Education and Awareness - March 18, 2015 - Bryan Strawser

A Program Management Approach to Business Continuity
A Program Management Approach to Business ContinuityA Program Management Approach to Business Continuity
A Program Management Approach to Business ContinuityBryghtpath LLC
 
WorldAtWorkConfernce_USBank_OS FINAL (no notes)
WorldAtWorkConfernce_USBank_OS FINAL (no notes)WorldAtWorkConfernce_USBank_OS FINAL (no notes)
WorldAtWorkConfernce_USBank_OS FINAL (no notes)Laura Roach
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a CareerBonnie Canal
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementECC International
 
Critical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance ImplementationsCritical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance ImplementationsRachid Meziani, PhD, CGEIT, PMP
 
ThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle ManagementThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle ManagementThinkGRC
 
The secret of a successful Crisis Management & Continuity Plan
The secret of a successful Crisis Management & Continuity PlanThe secret of a successful Crisis Management & Continuity Plan
The secret of a successful Crisis Management & Continuity PlanPECB
 
Resus Advisory Profile - Resilience services Nov 15
Resus Advisory Profile - Resilience services Nov 15Resus Advisory Profile - Resilience services Nov 15
Resus Advisory Profile - Resilience services Nov 15David John Bollaert
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectContinuity and Resilience
 
Globalization: Becoming a Global Business Continuity Leader
Globalization:  Becoming a Global Business Continuity LeaderGlobalization:  Becoming a Global Business Continuity Leader
Globalization: Becoming a Global Business Continuity LeaderBryghtpath LLC
 
Change Management Takes Change Management Webinar
Change Management Takes Change Management WebinarChange Management Takes Change Management Webinar
Change Management Takes Change Management WebinarTim Creasey
 
Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Continuity and Resilience
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectCORE Consulting
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT Continuity and Resilience
 
IT Governance Presentation by omaha 2008
IT Governance Presentation by  omaha 2008IT Governance Presentation by  omaha 2008
IT Governance Presentation by omaha 2008ssusera19f45
 
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...Biswadeep Ghosh Hazra
 
BCM Webinar presentation
BCM Webinar presentationBCM Webinar presentation
BCM Webinar presentationPrime Infoserv
 
360s Gone Wrong: How to Make Them More Effective
360s Gone Wrong: How to Make Them More Effective360s Gone Wrong: How to Make Them More Effective
360s Gone Wrong: How to Make Them More EffectiveQualtrics
 

Ähnlich wie Building Organizational Resilience Presentation - ISSA Special Interest Group in Security Education and Awareness - March 18, 2015 - Bryan Strawser (20)

A Program Management Approach to Business Continuity
A Program Management Approach to Business ContinuityA Program Management Approach to Business Continuity
A Program Management Approach to Business Continuity
 
WorldAtWorkConfernce_USBank_OS FINAL (no notes)
WorldAtWorkConfernce_USBank_OS FINAL (no notes)WorldAtWorkConfernce_USBank_OS FINAL (no notes)
WorldAtWorkConfernce_USBank_OS FINAL (no notes)
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a Career
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Critical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance ImplementationsCritical Success Factors (CSFs) for Effective IT Governance Implementations
Critical Success Factors (CSFs) for Effective IT Governance Implementations
 
ThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle ManagementThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle Management
 
The secret of a successful Crisis Management & Continuity Plan
The secret of a successful Crisis Management & Continuity PlanThe secret of a successful Crisis Management & Continuity Plan
The secret of a successful Crisis Management & Continuity Plan
 
Resus Advisory Profile - Resilience services Nov 15
Resus Advisory Profile - Resilience services Nov 15Resus Advisory Profile - Resilience services Nov 15
Resus Advisory Profile - Resilience services Nov 15
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR Project
 
Globalization: Becoming a Global Business Continuity Leader
Globalization:  Becoming a Global Business Continuity LeaderGlobalization:  Becoming a Global Business Continuity Leader
Globalization: Becoming a Global Business Continuity Leader
 
Change Management Takes Change Management Webinar
Change Management Takes Change Management WebinarChange Management Takes Change Management Webinar
Change Management Takes Change Management Webinar
 
Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR project
 
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
 
IT Governance Presentation by omaha 2008
IT Governance Presentation by  omaha 2008IT Governance Presentation by  omaha 2008
IT Governance Presentation by omaha 2008
 
Chris Gould - BCM case
Chris Gould - BCM caseChris Gould - BCM case
Chris Gould - BCM case
 
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...
[Project] FRAMEWORK FOR SUPPORTING “BUSINESS PROCESS REENGINEERING “-BASED BU...
 
BCM Webinar presentation
BCM Webinar presentationBCM Webinar presentation
BCM Webinar presentation
 
360s Gone Wrong: How to Make Them More Effective
360s Gone Wrong: How to Make Them More Effective360s Gone Wrong: How to Make Them More Effective
360s Gone Wrong: How to Make Them More Effective
 

Mehr von Bryghtpath LLC

Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017
Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017
Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017Bryghtpath LLC
 
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLC
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLCLeading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLC
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLCBryghtpath LLC
 
Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...Bryghtpath LLC
 
How to turn an incident into an opportunity for your business through effecti...
How to turn an incident into an opportunity for your business through effecti...How to turn an incident into an opportunity for your business through effecti...
How to turn an incident into an opportunity for your business through effecti...Bryghtpath LLC
 
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...Bryghtpath LLC
 
Business Continuity & Crisis Management in the Cyberbreach Age
Business Continuity & Crisis Management in the Cyberbreach AgeBusiness Continuity & Crisis Management in the Cyberbreach Age
Business Continuity & Crisis Management in the Cyberbreach AgeBryghtpath LLC
 
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...Bryghtpath LLC
 
ISO 21500: Generating Business Value through Strong Project Management
ISO 21500:  Generating Business Value through Strong Project ManagementISO 21500:  Generating Business Value through Strong Project Management
ISO 21500: Generating Business Value through Strong Project ManagementBryghtpath LLC
 

Mehr von Bryghtpath LLC (8)

Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017
Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017
Bryghtpath LLC - Leading in an Active Shooter Situation - July 2017
 
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLC
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLCLeading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLC
Leading in an Active Shooter Situation by Bryan Strawser of Bryghtpath LLC
 
Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...
 
How to turn an incident into an opportunity for your business through effecti...
How to turn an incident into an opportunity for your business through effecti...How to turn an incident into an opportunity for your business through effecti...
How to turn an incident into an opportunity for your business through effecti...
 
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...
Rethinking Business Continuity: Applying ISO 22301 to improve resiliency, man...
 
Business Continuity & Crisis Management in the Cyberbreach Age
Business Continuity & Crisis Management in the Cyberbreach AgeBusiness Continuity & Crisis Management in the Cyberbreach Age
Business Continuity & Crisis Management in the Cyberbreach Age
 
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...
When the $!@# hits the Fan - Bryan Strawser - Bryghtpath LLC - for PMI Minnes...
 
ISO 21500: Generating Business Value through Strong Project Management
ISO 21500:  Generating Business Value through Strong Project ManagementISO 21500:  Generating Business Value through Strong Project Management
ISO 21500: Generating Business Value through Strong Project Management
 

Kürzlich hochgeladen

Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxSocio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxtrishalcan8
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewasmakika9823
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 

Kürzlich hochgeladen (20)

Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxSocio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 

Building Organizational Resilience Presentation - ISSA Special Interest Group in Security Education and Awareness - March 18, 2015 - Bryan Strawser

  • 1. Building organizational resilience amidst global uncertainty: An overview of business continuity and crisis management for today’s global leaders Bryan Strawser, MBCP, MBCI, CISSP, CEM Principal Consultant & CEO
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7. Data Breaches Company Impacted People Sony Pictures 6,000 Sally Beauty 25,000 Neiman Marcus 1,100,000 Michaels Stores 3,000,000 Community Health Systems 4,500,000 PF Chang’s 7,000,000 Home Depot 56,000,000 Target 70,000,000 JP Morgan 76,000,000 Anthem 80,000,000 (still being evaluated) eBay 145,000,000 7 The Last 24 Months Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 8. Global Standards Business Continuity • ISO 22301 (formerly BS25999) • NFPA 1600 • ASIS Business Continuity Management Standard • ASIS SPC.1: Organizational Resilience US Government • Federal Continuity Directives (FCD 1 / FCD 2) • Continuity Guidance Circulators (CGC 1 / CGC 2) 8 Business Continuity and Emergency Management Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 9. • Formerly BS25999 • Adopted globally in 2012 • Intersects with other ISO Standards – Ex: ISO 27001 • Establish and maintain a Business Continuity Management System • Accreditation • Certification – Implementer / Lead – Auditor / Lead 9 ISO 22301:2012 Societal Security – Business Continuity Management Systems Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 10. Professional Certifications Business Continuity • Disaster Recovery Institute International – Associate Business Continuity Professional (ABCP) – Certified Business Continuity Professional (CBCP) – Master Business Continuity Professional (MBCP) • Business Continuity Institute – Member, Business Continuity Institute (MBCI) – Fellow, Business Continuity Institute (FBCI) Emergency Management • International Association of Emergency Managers – Associate Emergency Manager (AEM) – Certified Emergency Manager (CEM) 10 Business Continuity and Emergency Management Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 11. Business Continuity Regulations United States • Federal Financial Institutions Examination Council (FFIEC) • Securities and Exchange Commission (SEC) • Financial Industry Regulatory Authority (FINRA) • Payment Card Industry Standard (PCI) 11 We’re from the government, we’re here to help… Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 12. 12 Business Continuity Lifecycle ISO 22301 Business Continuity Management Lifecycle Business Impact Analysis & Risk Assessment Develop BC Strategies Establish & Implement BC Procedures Exercise, Testing, Maturing Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 13. 13 Business Impact Analysis & Risk Assessment Identifying critical business functions & their risks Business Impact Analysis • What are the critical business functions at my company? • How long can they be disrupted? • How quickly can they be recovered today? • What is the impact from that disruption to my business? • BIA Methods Risk Assessment • What are the risks to these functions? • What are our top enterprise risks? • Risk Assessment Methods Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 14. Specific actions to manage your risks and address your opportunities • Prepare your business for disruption • Develop Business Continuity Plans • Implement Business Continuity Solutions 14 Develop BC Strategies How can I recover my critical functions in the time period needed? Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 15. Core Components of a BC Plan • Roles & Responsibilities • Activation process • Managing the immediate consequences • Communication plan • Recover prioritized activities • Media response • Process for standing down 15 Develop BC Strategies Business Continuity Plans Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 16. 16 Establish & Implement BC Procedures What processes will I follow in a disruption? Specific defined processes for Business Continuity Examples: • Emergency preparedness • Governance • Activation Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 17. • All plans should be exercisesd at least annually: – Notification – Table Top – Recovery – Fully integrated • Disaster Recovery – Testing DR plans and strategies • Defined process for capturing lessons learned and applying to plans and strategies 17 Exercise, Testing, & Maturing How will I exercise and test my plans? Based on those results, how will I improve? Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 18. Awareness Executive Leaders & Board Members • An understanding of risk across the organization • Broad, strategic overview of the program • Clear understanding of decision making rights and their roles • Metrics & program maturity Typical Employee • Emergency procedures • High-level understanding of business continuity Critical Function Leaders • Understanding of how function connects to the broader business strategically • Can describe dependencies on technologies and other functions • Takes ownership of planning process for critical function • Fully understands business continuity & disaster recovery plans for function 18 Connecting to Security Education and Awareness Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 19. Crisis Management The active management of a disruption or escalating situation Items to consider: • Clear roles and responsibilities • Decision making rights pre-defined • Single source of truth for executive & board communication • Communication products / messages • Cross-functional coordination 19 A Component of Business Continuity Management Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 20. Crisis Management Green Team Yellow Team Red Team 20 A Simple Framework Example Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 21. • “Disaster Recovery” generally pertains to the recoverability of IT systems – Applications – Infrastructure • Must be closely linked to business continuity capability • Should heavily utilize the BIA findings to influence a tiered recovery strategy 21 Disaster Recovery Business Continuity for IT Systems Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 22. • 2013 Target Corporation HQ Flood • Primarily impacted non- critical teams • Flexibility in planning and crisis management framework enabled response despite lack of function specific plans • Lessons Learned 22 Case Study When a drip becomes a flood… Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 23. Advice on Building a BC Program • Keep things simple • Establish clear governance up-front • Pick a standard to guide your implementation • Select the leader of the program carefully – Professional certifications / subject matter expertise – Presence / Communication skills • Understand local, regional, country level risk • Bring in experts where needed to augment • This is not rocket science! 23 Practical tips for success Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com
  • 24. Contact Information Contact Bryan: Bryan Strawser Principal Consultant & CEO Phone: +1-612-235-6435 E-Mail: bryan@bryghtpath.com Twitter: @bryanstrawser Learn more about our services and how we can help you: Website: www.bryghtpath.com Twitter: @bryghtpath Facebook: facebook.com/bryghtpathllc 24 Bryghtpath LLC Copyright © 2015 by Bryghtpath LLC | bryghtpath.com | +1-612-235-6435 | bryan@bryghtpath.com Our Consulting Services Include: Business Continuity Crisis / Emergency Management Enterprise Risk Management Exercise Design & Facilitation Global Intelligence & Security ISO Training & Certification Travel Risk & Security
  • 25. Building organizational resilience amidst global uncertainty: An overview of business continuity and crisis management for today’s global leaders Bryan Strawser, MBCP, MBCI, CISSP, CEM Principal Consultant & CEO