SlideShare a Scribd company logo
1 of 29
Presenter:
Ms Rinske Geerlings
MD, Founder and
Principal Consultant/
Trainer @ Business As
Usual
Risk Consultant of the
Year 2017 (RMIA)
Outstanding Security
Consultant of the Year
2019 (OSPAs Finalist)
Business Continuity Planning (BCP) – Virtual seminar
Using lessons learned from Covid-19 to
improve your future ‘business as usual’
Interactive session
Using lessons learned from Covid-19 to improve
your future ‘business as usual’
First question:
Who has been
capturing lessons
learned and
future
improvements,
whilst the
lockdown was
ongoing?
Using lessons learned to achieve an improved ‘business as usual’
1. Innovations
 Brainstorm with your team about new service
offerings and methods you could choose during
future disruptions (e.g. online, from different
location, using different production facilities
or supply chains)
 Review responses from your customers,
suppliers and other stakeholders to any new
products/methods you’ve developed since
COVID-19
 Identify potential improvements to productivity/efficiency, e.g. reduction in staff
travel, less need for specific office space, change in office layout, more automation,
different staff shifts, cheaper/better ways to outsource or (on the contrary) bring
activities in-house
Case studies
Question
“Which tools have you implemented to optimise your remote work
technology (e.g. network connectivity at home, device security, phone
diversion procedures, etc) and which can you retain to work more effectively
in your new ”business as usual?”
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a strategy to ensure staff comfort
and productivity during disruptions
 Make sure managers are available in case
staff need extra support
 Build stock and a fast roll-out process for
any tools that staff may need in order to
work during a disruption, e.g. two-way
radios, spare laptops, spare mobile handsets,
pre-loaded SIM cards, mobile internet modems, headsets, phone diversion
procedures, remote voice mail set-up instructions etc
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a template for centralised
communication via email/SMS/other tool,
in order to ensure all staff are headed in
the same direction during incidents
 Explore the best practices regarding holding
daily ‘huddles’ with staff during disruptions,
in case you are unable to all work from the
same location
 Discuss how these can be applied during business as usual
Question
“How are you staying
productive during a disruption,
if you are unable to sit
together with colleagues?
What are your key challenges
in this context?”
Using lessons learned to achieve an improved ‘business as usual’
3. External collaboration
 Identify which tools your suppliers,
clients and other counterparts preferred
during the lockdown (e.g. in the event of
Internet downtime, mobile network
outages or work from home situations)
 Implement and test related collaboration
tools and arrange for licensing,
installation and staff training so you are
ready to seamlessly keep sales/orders
and customer support going
Question
“If Internet and mobile telephony
were to go down for 1-2 days,
what does your BCP say?”
4. The actual transition to ‘the new normal’
 Move back by department, office/floor,
business process or technology used?
 Properly identify if return-to-work on certain
days of the week by certain staff actually
achieves the intended benefits (and doesn’t
complicate things)
 Ensure appropriate stages for facilities, HR
and IT to manage the transition including
proper testing
Using lessons learned to achieve an improved ‘business as usual’
Using lessons learned to improve your new ‘business as usual’
5. Better risk management
Revisit information sharing policies/controls in the event of a disruption, e.g.
 Secure network connectivity (incl WPS2 protection)
 Remote access software (e.g. VPN) including licences
 Patching of operating systems and ensure endpoint security (e.g. malware/virus
scanners)
 Provide regular reminders about information security to staff
 Conduct an ISO 27001 gap analysis
Revisit your Business Continuity Plan (BCP)
 Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain
disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT
system failure)
 Regularly walk-through/test your disruption scenarios
 Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and
regular ‘mini invocations’
 Less is more – Reduce document volume and make it easy to maintain
 Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and
gaming techniques including ‘red teaming’
 Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’
 Global best practice: For proper BCP as with DR, Risk Management and Security),
apply up-to-date principles/strategies (and standards!)
Making Business Continuity plans that actually work when you
need them most
• Philosophy of resilient networks
• What is different ?
• How do they work ?
• Why is it better than classic networks ?
• And all of your questions !
The topic of 2day
How to create resilience ?
We work in silos
BCP
How to create resilience ?
Multi silos in organisations
BCP
How to create resilience ?
Multi organisations in networks
BCP
BCP
BCP
BCP
BCP
BCP
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
What is resilience in this context ?
€ €
products/
services
products/
services
Take a simple chain
Examples of non resilience in chains:
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
‘Me, myself and I’ control =
the answer to all mishaps
8020
Increased risk at
customer level,
lower resilience
We need another direction !
Classic reaction to build resilience:
Risk
Costs
Quality
Profit
Statement:
The better you are, the
simpler the world, the
more resilient you are
energy,
costs,
risks
# learning cycles
complex
simple
Based on Resource Based View, Barney, 1991, and all later versions
New reaction to build resilience:
Add ‘expertise’ thinking:
Customer
100 % value
integrator
These networks are faster, cheaper, better (Q)
Based on Wouter Beelaerts, 2010
18 %
18 %
13 %
9 %
18 %
13 %
Profit = up
10 %
Resilience = up
Change the network for resilience:
utilise expertise
Next step: embrace dependency:
Resilient Customer
value
integrator
Resilience =
further up
Results in the integrator being a
resilience hub:
Resilient Supplier
value
goods & services
information & money
Remarkable results:
• speed to market: up
• total cost: down
• network profit: up
• network agility: up
• network resilience: up
Building the
resilient network
Conclusion:
classic networks F, C, B networks
embrace
dependency
Resilient
Customer
value
integrat
or
Resilient
Supplier
value
the resilient network
 Start talking about dependency with your network partners
 Add the outcome to your BCP !
Simple to start:
ISO 22301
Training Courses
• ISO 22301 Introduction
1 Day Course
• ISO 22301 Foundation
2 Days Course
• ISO 22301 Lead Implementer
5 Days Course
• ISO 22301 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
22301
www.pecb.com/events
THANK YOU
?
rinske@businessasusual.com.au
santema@scenter.nl
linkedin.com/in/businessasusual/
linkedin.com/in/siccosantema
www.businessasusual.com.au
www.scenter.nl

More Related Content

What's hot

IDEO - Case Study Presentation
IDEO - Case Study PresentationIDEO - Case Study Presentation
IDEO - Case Study PresentationNeel Kapoor
 
Leading digital summary
Leading digital summaryLeading digital summary
Leading digital summaryGMR Group
 
The Dabbawala System: On Time Delivery, Every Time.
The Dabbawala System: On Time Delivery, Every Time.The Dabbawala System: On Time Delivery, Every Time.
The Dabbawala System: On Time Delivery, Every Time.Varun Jaggi
 
Employment activities at nestle
Employment  activities at nestleEmployment  activities at nestle
Employment activities at nestlemarium shabbir
 
Aravind Eye Hospital - Case Study Analysis IMTG
Aravind Eye Hospital - Case Study Analysis IMTGAravind Eye Hospital - Case Study Analysis IMTG
Aravind Eye Hospital - Case Study Analysis IMTGHarinder Pelia
 
UPS case study analysis
UPS case study analysisUPS case study analysis
UPS case study analysisr-dilara
 
Value chain nestle analysis
Value chain nestle analysisValue chain nestle analysis
Value chain nestle analysisMohammad Alfian
 
Mumbai Dabbawala Casestudy Presentation
Mumbai Dabbawala Casestudy PresentationMumbai Dabbawala Casestudy Presentation
Mumbai Dabbawala Casestudy PresentationSuyash Jain
 
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...Stefan F. Dieffenbacher
 
leadership style INDRA NOOYI
leadership style INDRA NOOYIleadership style INDRA NOOYI
leadership style INDRA NOOYIAnkit
 
Online maid services Business Plan
Online maid services Business PlanOnline maid services Business Plan
Online maid services Business PlanShri Hari Agrawal
 
01 nestle sales and distribution
01 nestle sales and distribution01 nestle sales and distribution
01 nestle sales and distributionSelvakani Nadar
 
Colgate palmolive ppt
Colgate palmolive pptColgate palmolive ppt
Colgate palmolive pptShweta Sharma
 
Mumbai dabbawala’s
Mumbai dabbawala’sMumbai dabbawala’s
Mumbai dabbawala’sIego Kamduk
 
Nestle Commpany Overview
Nestle Commpany OverviewNestle Commpany Overview
Nestle Commpany OverviewNasir Ali
 

What's hot (20)

IDEO - Case Study Presentation
IDEO - Case Study PresentationIDEO - Case Study Presentation
IDEO - Case Study Presentation
 
Nestle Selling Process
Nestle Selling ProcessNestle Selling Process
Nestle Selling Process
 
Overview of Nestle products
Overview of Nestle productsOverview of Nestle products
Overview of Nestle products
 
Leading digital summary
Leading digital summaryLeading digital summary
Leading digital summary
 
The Dabbawala System: On Time Delivery, Every Time.
The Dabbawala System: On Time Delivery, Every Time.The Dabbawala System: On Time Delivery, Every Time.
The Dabbawala System: On Time Delivery, Every Time.
 
Digital Transformation: Step-by-step Implementation Guide
Digital Transformation: Step-by-step Implementation GuideDigital Transformation: Step-by-step Implementation Guide
Digital Transformation: Step-by-step Implementation Guide
 
Employment activities at nestle
Employment  activities at nestleEmployment  activities at nestle
Employment activities at nestle
 
Aravind Eye Hospital - Case Study Analysis IMTG
Aravind Eye Hospital - Case Study Analysis IMTGAravind Eye Hospital - Case Study Analysis IMTG
Aravind Eye Hospital - Case Study Analysis IMTG
 
Dabbawala's
Dabbawala'sDabbawala's
Dabbawala's
 
UPS case study analysis
UPS case study analysisUPS case study analysis
UPS case study analysis
 
Value chain nestle analysis
Value chain nestle analysisValue chain nestle analysis
Value chain nestle analysis
 
Mumbai Dabbawala Casestudy Presentation
Mumbai Dabbawala Casestudy PresentationMumbai Dabbawala Casestudy Presentation
Mumbai Dabbawala Casestudy Presentation
 
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...
Keynote: The User Experience Strategy behind one of Europe’s largest Digital ...
 
leadership style INDRA NOOYI
leadership style INDRA NOOYIleadership style INDRA NOOYI
leadership style INDRA NOOYI
 
Online maid services Business Plan
Online maid services Business PlanOnline maid services Business Plan
Online maid services Business Plan
 
[Slides] Digital Transformation, with Brian Solis
[Slides] Digital Transformation, with Brian Solis[Slides] Digital Transformation, with Brian Solis
[Slides] Digital Transformation, with Brian Solis
 
01 nestle sales and distribution
01 nestle sales and distribution01 nestle sales and distribution
01 nestle sales and distribution
 
Colgate palmolive ppt
Colgate palmolive pptColgate palmolive ppt
Colgate palmolive ppt
 
Mumbai dabbawala’s
Mumbai dabbawala’sMumbai dabbawala’s
Mumbai dabbawala’s
 
Nestle Commpany Overview
Nestle Commpany OverviewNestle Commpany Overview
Nestle Commpany Overview
 

Similar to Moving to a New "Business as Usual" after COVID-19

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17jekroggel
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...360 BSI
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplacePaperjam_redaction
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Net at Work
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetAshley Deuble
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)AdaCore
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attranhcrowley
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations managementsmumbahelp
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profilescottsdale
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profilescottsdale
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 

Similar to Moving to a New "Business as Usual" after COVID-19 (20)

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17
 
Stabilizing Revenue
Stabilizing RevenueStabilizing Revenue
Stabilizing Revenue
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplace
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budget
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft Services
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attr
 
resume_alcantara
resume_alcantararesume_alcantara
resume_alcantara
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations management
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profile
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profile
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactPECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Recently uploaded

Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Jisc
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Pooja Bhuva
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.MaryamAhmad92
 
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptxCOMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptxannathomasp01
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsMebane Rash
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxPooja Bhuva
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jisc
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxDr. Sarita Anand
 
How to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptxHow to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptxCeline George
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17Celine George
 
How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17Celine George
 
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...Amil baba
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxJisc
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxRamakrishna Reddy Bijjam
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17Celine George
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsKarakKing
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxJisc
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 

Recently uploaded (20)

Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.
 
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptxCOMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan Fellows
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
How to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptxHow to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptx
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17
 
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docx
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 

Moving to a New "Business as Usual" after COVID-19

  • 1.
  • 2. Presenter: Ms Rinske Geerlings MD, Founder and Principal Consultant/ Trainer @ Business As Usual Risk Consultant of the Year 2017 (RMIA) Outstanding Security Consultant of the Year 2019 (OSPAs Finalist) Business Continuity Planning (BCP) – Virtual seminar Using lessons learned from Covid-19 to improve your future ‘business as usual’ Interactive session
  • 3. Using lessons learned from Covid-19 to improve your future ‘business as usual’ First question: Who has been capturing lessons learned and future improvements, whilst the lockdown was ongoing?
  • 4. Using lessons learned to achieve an improved ‘business as usual’ 1. Innovations  Brainstorm with your team about new service offerings and methods you could choose during future disruptions (e.g. online, from different location, using different production facilities or supply chains)  Review responses from your customers, suppliers and other stakeholders to any new products/methods you’ve developed since COVID-19  Identify potential improvements to productivity/efficiency, e.g. reduction in staff travel, less need for specific office space, change in office layout, more automation, different staff shifts, cheaper/better ways to outsource or (on the contrary) bring activities in-house
  • 6. Question “Which tools have you implemented to optimise your remote work technology (e.g. network connectivity at home, device security, phone diversion procedures, etc) and which can you retain to work more effectively in your new ”business as usual?”
  • 7. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a strategy to ensure staff comfort and productivity during disruptions  Make sure managers are available in case staff need extra support  Build stock and a fast roll-out process for any tools that staff may need in order to work during a disruption, e.g. two-way radios, spare laptops, spare mobile handsets, pre-loaded SIM cards, mobile internet modems, headsets, phone diversion procedures, remote voice mail set-up instructions etc
  • 8. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a template for centralised communication via email/SMS/other tool, in order to ensure all staff are headed in the same direction during incidents  Explore the best practices regarding holding daily ‘huddles’ with staff during disruptions, in case you are unable to all work from the same location  Discuss how these can be applied during business as usual
  • 9. Question “How are you staying productive during a disruption, if you are unable to sit together with colleagues? What are your key challenges in this context?”
  • 10. Using lessons learned to achieve an improved ‘business as usual’ 3. External collaboration  Identify which tools your suppliers, clients and other counterparts preferred during the lockdown (e.g. in the event of Internet downtime, mobile network outages or work from home situations)  Implement and test related collaboration tools and arrange for licensing, installation and staff training so you are ready to seamlessly keep sales/orders and customer support going
  • 11. Question “If Internet and mobile telephony were to go down for 1-2 days, what does your BCP say?”
  • 12. 4. The actual transition to ‘the new normal’  Move back by department, office/floor, business process or technology used?  Properly identify if return-to-work on certain days of the week by certain staff actually achieves the intended benefits (and doesn’t complicate things)  Ensure appropriate stages for facilities, HR and IT to manage the transition including proper testing Using lessons learned to achieve an improved ‘business as usual’
  • 13. Using lessons learned to improve your new ‘business as usual’ 5. Better risk management Revisit information sharing policies/controls in the event of a disruption, e.g.  Secure network connectivity (incl WPS2 protection)  Remote access software (e.g. VPN) including licences  Patching of operating systems and ensure endpoint security (e.g. malware/virus scanners)  Provide regular reminders about information security to staff  Conduct an ISO 27001 gap analysis Revisit your Business Continuity Plan (BCP)  Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT system failure)  Regularly walk-through/test your disruption scenarios
  • 14.  Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and regular ‘mini invocations’  Less is more – Reduce document volume and make it easy to maintain  Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and gaming techniques including ‘red teaming’  Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’  Global best practice: For proper BCP as with DR, Risk Management and Security), apply up-to-date principles/strategies (and standards!) Making Business Continuity plans that actually work when you need them most
  • 15. • Philosophy of resilient networks • What is different ? • How do they work ? • Why is it better than classic networks ? • And all of your questions ! The topic of 2day
  • 16. How to create resilience ? We work in silos BCP
  • 17. How to create resilience ? Multi silos in organisations BCP
  • 18. How to create resilience ? Multi organisations in networks BCP BCP BCP BCP BCP BCP
  • 19. Customer 100 % value Suppliers 60 % value OEM 40 % value What is resilience in this context ? € € products/ services products/ services Take a simple chain
  • 20. Examples of non resilience in chains:
  • 21. Customer 100 % value Suppliers 60 % value OEM 40 % value ‘Me, myself and I’ control = the answer to all mishaps 8020 Increased risk at customer level, lower resilience We need another direction ! Classic reaction to build resilience:
  • 22. Risk Costs Quality Profit Statement: The better you are, the simpler the world, the more resilient you are energy, costs, risks # learning cycles complex simple Based on Resource Based View, Barney, 1991, and all later versions New reaction to build resilience: Add ‘expertise’ thinking:
  • 23. Customer 100 % value integrator These networks are faster, cheaper, better (Q) Based on Wouter Beelaerts, 2010 18 % 18 % 13 % 9 % 18 % 13 % Profit = up 10 % Resilience = up Change the network for resilience: utilise expertise
  • 24. Next step: embrace dependency:
  • 25. Resilient Customer value integrator Resilience = further up Results in the integrator being a resilience hub: Resilient Supplier value goods & services information & money Remarkable results: • speed to market: up • total cost: down • network profit: up • network agility: up • network resilience: up
  • 26. Building the resilient network Conclusion: classic networks F, C, B networks embrace dependency Resilient Customer value integrat or Resilient Supplier value the resilient network
  • 27.  Start talking about dependency with your network partners  Add the outcome to your BCP ! Simple to start:
  • 28. ISO 22301 Training Courses • ISO 22301 Introduction 1 Day Course • ISO 22301 Foundation 2 Days Course • ISO 22301 Lead Implementer 5 Days Course • ISO 22301 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 22301 www.pecb.com/events