SlideShare uma empresa Scribd logo
1 de 29
Baixar para ler offline
Are You & Your Facility Ready?
What’s New in Business Continuity, Personal Resiliency & Preparedness




     Mike Thomson
     Manager, Client Services & Business Continuity Programs
     ImpactReady @ ImpactWeather, Inc.

     Anthony Pizzitola, CFM, CBCP, MBCI
    Facilities & Disaster Recovery Manager
    Goode Company
First, what are we solving for ?
•Business Continuity Management is defined as a holistic management
process that identifies potential impacts that threaten an organization and
provides a framework for building resilience with the capability for an
effective response that safeguards the interests of its key stakeholders,
reputation and value creating activities.

•The primary objective of Business Continuity Management is to allow the
Executive to continue to manage business operations under adverse
conditions, by the introduction of appropriate resilience strategies,
recovery objectives, business continuity, operational risk management
considerations and crisis management plans.
                                         Disaster Recovery Institute International
Business Continuity Helps Manage Risk in Many Ways

        Cash & Credit                 Business Continuity
        Management                         Planning
                                   Intellectual


                                                                      • Protects 85% of the business
                       Financial   Property,
                       Capacity    Processes &
                                   Vital Records*



 Physical
 Security
            Property, Facilities
            and Infrastructure
                                          Life Safety   Emergency
                                                         Response
                                                                      • Nearly 170% return on investment
              Adherence to
                                         Business
                                           Risk or
                                                                      • Non-compliant companies paid $9.4M in
              Regulations               Interruption

      Corporate
      Governance
                             Operations             Enterprise Risk
                                                                      fines, penalties & lost revenue
                                                                      • Compliant companies paid $3.5M
                                                    Management
                               Work
                             Planning

                   2
How are the Threats Identified to Prepare and
                Prevent a Disaster?
•Don’t just visit the site, inspect the site!
•Collaborate with your colleagues and vendor base to ID the top 10 threats
in each category.
     ID regional natural threats, have a backup plan.
     ID manmade threats, launch control measures.
     ID technological threats, have a backup plan.
•Is lack of compliance with OSHA and ADA a threat? Yes!
•Is lack of Preventive & Predictive Maintenance a threat? Yes, just wait until
Friday afternoon or Saturday evening.
•Prepare a plan based on the above, implement controls , inspect and test!
Continuity Planning and Response Move in a Cycle
                           Assess
                               Normal
                         Business Operations


                              Security

                             Fire   Flood
                Resume       Regulatory        Respond
                     Terrorism       Pandemic
                          Storm      ???


                   Recover                Manage
Develop A Disaster Preparation, Response and
               Recovery Plan
•How So? Start by Identifying the Threats, their Probability and their
Impacts to the Organization. How can the threats be controlled.
•What are the threats?
    Natural
    Manmade
    Technological
•Lack of preparation and a plan can threaten your career!
•Lack of preparation and a plan is a call for the lawyers!
Businesses Will Use Their Continuity Plans Regularly
Business Preparedness Involves
     Five Important Steps
1.   Develop a Program (for what you will do
     in an emergency)
2.   Have Back-ups (for critical people,
     equipments and supplies)
3.   Practice Your Plan (at least once each
     year)
4.   Be Informed (about what might happen)

5.   Get Involved (in preparing with your
     community)
You Need Six Essential Tools in Your
     Preparedness Program
   1.   Severe Weather Alerts
   2.   Emergency Notification System
   3.   Incident Management Program
   4.   ePlan Documentation
   5.   Situational Awareness Monitoring
   6.   Personal Preparedness/Resiliency
Weather Disasters at Highest Levels Ever Recorded
                                                                   Billions




                                                    Source: NOAA




     Total economic damage = $52B, Most $1B+ Disaster Ever
#1 – Essential Tool
Severe Weather Services
Forecasting, Monitoring and Alerting

       Tropical storm & hurricane analysis

       Severe weather analysis

       24/7 alerting (including “all clear”)

       Domestic and International coverage

       Web-based weather briefings for key personnel

       24/7 access to meteorologists for additional
       consultation and pre-scheduled conference calls


Consulting and Support Programs

       Corporate Business Continuity & Emergency Preparedness:
       consulting services and training programs

       Personal Preparedness: Seminars, Webinars, and Personal
       Preparedness tools
Capability               Resident Meteorologist   National Weather Service   Web-based Weather Services     Dedicated Weather Service

      Available 24x7x365                      No                       Yes                 Limited, w/Advertisements              Yes

   Domestic & International                   No                       No                           Limited                       Yes

All Weather Services – Severe,                                                                                                    Yes
                                             Yes                       No                             No
       Tropical, Marine

Customized Alerts & Forecasts                Yes                       No                             No                          Yes

      Any Time, Live Help                   Limited                    No                             No                          Yes

 Meteorologist Needed On-Site              Possible                    No                             No                          Yes

  Imbedded “Calls to Action”                 Yes                       No                             No                          Yes

Integrated Business Continuity                                                                                                    Yes
                                              No                       No                             No
           Services

Certified Crisis Experts On-call            Limited                    No                             No                          Yes

Branded, Direct Access Website             Possible                    Yes                            No                          Yes

All-Hazards Data Feeds/Alerting               No                       No                             No                          Yes

    “Single Pane of Glass”                    No                       No                             No                          Yes

       All Clear Notices                    Limited                    No                             No                          Yes

   Video Production Studio                    No                       No                             No                          Yes

    Crisis Webconferences                  Possible                    No                             No                          Yes

Daily Branded Weather Videos                  No                       No                             No                          Yes

Site-specific, All-Hazard Trigger                                                                                                 Yes
                                           Possible                    No                             No
             Reports

Best Practice Web & Seminars                  No                       No                             No                          Yes

    Delivery to Any Device                   Yes                       No                             No                          Yes
#2 – Essential Tool
                       Emergency Notification System




“Manually dialed telephone call trees are no longer acceptable for emergency notification. Effective
incident management requires automation to ensure business continuity.” -Gartner, Inc.
#3 – Essential Tool
Incident Management Program
                       Incident
                       Detected                         Incident Management Team
                                                            (IMT) Member Aware




                                                         Incident Commander (IC)
               Site Back to                                    *Division VP
                  Normal                                *Manager of Administration
                                                                  Notified

                                                   No
                                         Minor                                                Major
                                         < 8 hrs                                             > 8 hrs
                Standard
                                                                  Initial Incident                          IMT
                Operating
                                                                   Assessment                            Assembled
               Procedures




                                                                                                              Incident
                                                                                                              Briefing




                                                                                                          Impact
                                                                                                        Assessment
  Yes                                                   < 8 hrs




                                                                                                         > 8 hrs
                                                                                                          Incident
                                                                                                        Assessment
                                                            Resume
                                                            Normal
                                                           Operations

                                                                                                            Incident
              Yes                                                                                         Objectives                  No
                                Need to                    Critique IMT                                 - Develop IAP
                              Update Plan                   Response                                       - SITREP


            Plan
                              No




        Maintenance
                                                            Report to
        and Update                                                                                                        Alternate
                                                           Executive                        Recovery
                                                                                                        Demobilization    Operating
                                                           Oversight                 Yes   Procedures
                                                                                                                         Procedures
                                                           Committee
                                   End




                                                                                                        Site Back to
    *Foreseen Events                                                                                       Normal
#4 – Essential Tool
                   ePlan Documentation
•   Repository for all IM, BC, ER and DR plans
•   Component of comprehensive Business Continuity effort
•   Modules for both planning and incident management
•   Linked with emergency notification system
•   NIMS Compliant
#5 – Essential Tool
                      Situational Awareness Monitoring




–   Crisis management is moving from offices or command rooms to sophisticated mobile and online environments…

–   Breaking threats in dozens of risk categories now delivered as targeted alerts, anytime, anywhere…
#6 – Essential Tool
         Personal Preparedness
Most individuals, and thus their employers, are unprepared
                       for a disaster




                                        Source: American Red Cross



       “Only 7% of Americans have taken the
       necessary steps to prepare for disasters”
#6 – Essential Tool
            Personal Preparedness
Most individuals, and thus their employers, are
           unprepared for a disaster




 “75% of company plans do not support employee resiliency”
                         Source: Forrester Research
# 6 – Essential Tool
                                Employee Education Works
• Annual Preparedness Programs
• Speakers, Demos, Handouts
• Company Intranet Campaigns
• Home, Office Videos & Checklists
• Contact Info Updates

      Ready Today = Ready in Crisis

                                                                                    • Cost effective, 100x ROI
                                                                                    • Save $2,800 per employee
                                                                                    • Overcame Complacency
                                                                                    • Mitigated Damages, Impact
                                                                                    • Less Time Responding
               © Personal Recovery Concepts, All rights reserved                    • More Effective Action
You Need To Be Prepared for Many Reasons
• Protection (people, reputation, resources)
• Legal (regulatory compliance, litigation)
• Financial (more revenue, reduced costs)
• Decision-making (one source, more confidence)
• Good Business (stakeholders, market share)
Contingency Planning in
 Many Areas is Highly
      Regulated
  •   Required to have an “all
      hazards” plan

  •   Weather is leading hazard
      causing business interruption

  •   Plan must follow a Standard

  •   All standards include
      preparedness of the
      workforce that the plan relies
      upon before, during and after
      a continuity event

  •   PS-Prep will translate that
      requirement to any private
      sector company
PS-Prep will Impact Every Private Sector Company
Title IX, PL 110-53 (Private Sector Preparedness Act)
•   Outgrowth of 9/11 Commission Report
•   Independent certification of private sector emergency preparedness (including
    disaster/emergency management & business continuity)
•   Administer outside government by third parties
•   Give special consideration to small businesses (15 USC 632)
•   Based on standards (3 already approved)




                                         •    FEMA Administrator is responsible
                                         •    DHS is encouraging multiple standards
                                         •    Initial certifications will be “conformity or non-conformity” based
                                         •    Process slowed by change of administrations
                                         •    Integrate, recognize & credit existing industry efforts, standards,
                                              best practices and reporting
Should Vendors Comply with PS-Prep?
•If business units are prepared, their supply chain should be equally
prepared.
•A resilient supply chain is prepared for natural disasters, business
interruptions and terrorism.
•Preparedness guarantees quality products with on-time deliveries to
business units.
•You can’t do business with an empty wagon.
•The purpose of PS-Prep is to enhance nationwide resilience against
all hazards and to support business preparedness.
Some Benefits of Preparedness May Not be Obvious
                              Minimizing Impact of
                              Business Disruptions


             Insurance                               Supply Chain Resiliency
              Benefits

          Rating Agency
                                                     Corporate Governance
        Acknowledgement

             Mitigating                              Reputational and other
            Legal Liability                                 Benefits
             Post-Event




                 Greater Preparedness
                 Greater Preparedness
90% of Requirements Are
 Common in All Standards
1.   Policy statement
2.   Management commitment
3.   Risk identification, assessment &
     analysis
4.   Protect proprietary & confidential
     information
5.   Incident management procedures &
     controls
6.   Data control & backup (documents &
     information)
7.   Continuity of critical operations
8.   Exercises & testing
9.   Independent audits
Plan, Do, Check, Act        First (or Next) Steps to Take to
                                   Mitigate Your Risks
                       1. Assess your current level of emergency
                               preparedness against industry best practices
                               (report & gap analysis)
                       2. Select a standard to use (e.g. FFEIC, OCC, ASIS,
                               etc)
                       3. Supplement and/or improve your existing
                               preparedness processes, plans & activities to
                               meet intent of desired standard(s)
                       4. Contract with accredited certification body for
                               formal assessment and certification
                       5. Conduct on-going surveillance and continual
                               improvement processes
Someone Will Ask for Your Business Preparedness Plan




              • Regulatory Auditors
              • Customers
              • Strategic Partners
              • Suppliers & Vendors
              • Fire & Law Enforcement
Preparedness Increases Revenue and Reduces Costs


                        • Oxford University study
                        • Everyone loses value after crisis
                        • Effective crisis response recovers
                        quicker
                        • 22% higher market cap 8 months after
                        crisis
                        • Cost of downtime = $84,000 -$90,000
                        per hour
Q&A
                                   Have questions??

                                          CONTACT
Mike Thomson                                              Anthony Pizzitola
Manager, Client Services & Business Continuity Programs   Facilities & Disaster Recovery Manager
ImpactReady @ ImpactWeather, Inc.                         Goode Company
877-792-3220                                              713-667-9001
mthomson@impactweather.com                                apizzitola@goodecompany.com

Mais conteúdo relacionado

Destaque

Test greek
Test greekTest greek
Test greekbymafe
 
Diocese of Exeter Guidelines on Communion before confirmation
Diocese of Exeter Guidelines on Communion before confirmationDiocese of Exeter Guidelines on Communion before confirmation
Diocese of Exeter Guidelines on Communion before confirmationKatherine Lyddon
 
Building a state omk program 2011
Building a state omk program 2011Building a state omk program 2011
Building a state omk program 2011Georgene Bender
 
Introduction to Inbound Marketing
Introduction to Inbound MarketingIntroduction to Inbound Marketing
Introduction to Inbound MarketingMohamed Refaei
 
Presentation 'Employing a children's worker'
Presentation 'Employing a children's worker'Presentation 'Employing a children's worker'
Presentation 'Employing a children's worker'Katherine Lyddon
 
Welcome to Community Church Toddlers
Welcome to Community Church ToddlersWelcome to Community Church Toddlers
Welcome to Community Church ToddlersKatherine Lyddon
 
Ura 1989 japanese
Ura 1989 japaneseUra 1989 japanese
Ura 1989 japaneseguestc9a2ad
 
Wilson's Associate Systems Main
Wilson's Associate Systems Main Wilson's Associate Systems Main
Wilson's Associate Systems Main wilson103566
 
Principios Básicos de Análisis Numérico para Analítica Web
Principios Básicos de Análisis Numérico para Analítica WebPrincipios Básicos de Análisis Numérico para Analítica Web
Principios Básicos de Análisis Numérico para Analítica WebDiego Colagrosso
 
Ideas for 4-H Leader Awards
Ideas for 4-H Leader AwardsIdeas for 4-H Leader Awards
Ideas for 4-H Leader AwardsGeorgene Bender
 
το+πέτριν..
το+πέτριν..το+πέτριν..
το+πέτριν..bymafe
 
Iraqguests 2011 (2) package
Iraqguests 2011 (2) packageIraqguests 2011 (2) package
Iraqguests 2011 (2) packageGeorgene Bender
 
设计部第三课
设计部第三课设计部第三课
设计部第三课jianfeng
 
οι+ευχές+..
οι+ευχές+..οι+ευχές+..
οι+ευχές+..bymafe
 
Joakim Jardenberg presentation
Joakim Jardenberg presentationJoakim Jardenberg presentation
Joakim Jardenberg presentationDina El-sofy
 
Μάθημα πληροφορικής
Μάθημα πληροφορικήςΜάθημα πληροφορικής
Μάθημα πληροφορικήςbymafe
 
In Spirit and in Truth Diocese of Chichester
In Spirit and in Truth Diocese of ChichesterIn Spirit and in Truth Diocese of Chichester
In Spirit and in Truth Diocese of ChichesterKatherine Lyddon
 
Arkas nuia
Arkas   nuiaArkas   nuia
Arkas nuiabymafe
 
M & M RecognitionL Let's Make it Meaningful & Memorable
M & M RecognitionL Let's Make it Meaningful & MemorableM & M RecognitionL Let's Make it Meaningful & Memorable
M & M RecognitionL Let's Make it Meaningful & MemorableGeorgene Bender
 

Destaque (20)

Test greek
Test greekTest greek
Test greek
 
Diocese of Exeter Guidelines on Communion before confirmation
Diocese of Exeter Guidelines on Communion before confirmationDiocese of Exeter Guidelines on Communion before confirmation
Diocese of Exeter Guidelines on Communion before confirmation
 
Building a state omk program 2011
Building a state omk program 2011Building a state omk program 2011
Building a state omk program 2011
 
Vuoi stare online?
Vuoi stare online?Vuoi stare online?
Vuoi stare online?
 
Introduction to Inbound Marketing
Introduction to Inbound MarketingIntroduction to Inbound Marketing
Introduction to Inbound Marketing
 
Presentation 'Employing a children's worker'
Presentation 'Employing a children's worker'Presentation 'Employing a children's worker'
Presentation 'Employing a children's worker'
 
Welcome to Community Church Toddlers
Welcome to Community Church ToddlersWelcome to Community Church Toddlers
Welcome to Community Church Toddlers
 
Ura 1989 japanese
Ura 1989 japaneseUra 1989 japanese
Ura 1989 japanese
 
Wilson's Associate Systems Main
Wilson's Associate Systems Main Wilson's Associate Systems Main
Wilson's Associate Systems Main
 
Principios Básicos de Análisis Numérico para Analítica Web
Principios Básicos de Análisis Numérico para Analítica WebPrincipios Básicos de Análisis Numérico para Analítica Web
Principios Básicos de Análisis Numérico para Analítica Web
 
Ideas for 4-H Leader Awards
Ideas for 4-H Leader AwardsIdeas for 4-H Leader Awards
Ideas for 4-H Leader Awards
 
το+πέτριν..
το+πέτριν..το+πέτριν..
το+πέτριν..
 
Iraqguests 2011 (2) package
Iraqguests 2011 (2) packageIraqguests 2011 (2) package
Iraqguests 2011 (2) package
 
设计部第三课
设计部第三课设计部第三课
设计部第三课
 
οι+ευχές+..
οι+ευχές+..οι+ευχές+..
οι+ευχές+..
 
Joakim Jardenberg presentation
Joakim Jardenberg presentationJoakim Jardenberg presentation
Joakim Jardenberg presentation
 
Μάθημα πληροφορικής
Μάθημα πληροφορικήςΜάθημα πληροφορικής
Μάθημα πληροφορικής
 
In Spirit and in Truth Diocese of Chichester
In Spirit and in Truth Diocese of ChichesterIn Spirit and in Truth Diocese of Chichester
In Spirit and in Truth Diocese of Chichester
 
Arkas nuia
Arkas   nuiaArkas   nuia
Arkas nuia
 
M & M RecognitionL Let's Make it Meaningful & Memorable
M & M RecognitionL Let's Make it Meaningful & MemorableM & M RecognitionL Let's Make it Meaningful & Memorable
M & M RecognitionL Let's Make it Meaningful & Memorable
 

Semelhante a PRSM Webinar Feb 2012

Security and Business Continuity Working Together
Security and Business Continuity Working TogetherSecurity and Business Continuity Working Together
Security and Business Continuity Working Togethercharliemb2
 
Webinar Crisis Communication & Business Continuity with G4S
Webinar Crisis Communication & Business Continuity with G4SWebinar Crisis Communication & Business Continuity with G4S
Webinar Crisis Communication & Business Continuity with G4SFINN
 
Business Resilience
Business ResilienceBusiness Resilience
Business Resiliencerix57
 
Maritime accident n incident investigation
Maritime accident n incident investigationMaritime accident n incident investigation
Maritime accident n incident investigationCapt Ashok Menon
 
Ceo President Step Sheet
Ceo President Step SheetCeo President Step Sheet
Ceo President Step SheetRob_Daley
 
SagaciousThink Overview
SagaciousThink OverviewSagaciousThink Overview
SagaciousThink OverviewLouAnn Conner
 
Fns Incident Management Powered By En Case
Fns Incident Management Powered By En CaseFns Incident Management Powered By En Case
Fns Incident Management Powered By En Casetbeckwith
 
Incident Response in the age of Nation State Cyber Attacks
Incident Response in the age of Nation State Cyber AttacksIncident Response in the age of Nation State Cyber Attacks
Incident Response in the age of Nation State Cyber AttacksResilient Systems
 
IMI business continuity presentation
IMI business continuity presentationIMI business continuity presentation
IMI business continuity presentationBrian Andrews
 
Using the CAPA process to prevent problems and mitigate risks in the life-sci...
Using the CAPA process to prevent problems and mitigate risks in the life-sci...Using the CAPA process to prevent problems and mitigate risks in the life-sci...
Using the CAPA process to prevent problems and mitigate risks in the life-sci...Seuss+
 
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye, Inc.
 
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...Jesse Andrew
 
Upselling and upgrading webinar presentation
Upselling and upgrading webinar presentationUpselling and upgrading webinar presentation
Upselling and upgrading webinar presentationStuart Selbst Consulting
 
10 Questions Every Company Should Be Asking Itself About its Business Resilience
10 Questions Every Company Should Be Asking Itself About its Business Resilience10 Questions Every Company Should Be Asking Itself About its Business Resilience
10 Questions Every Company Should Be Asking Itself About its Business ResilienceMichael Bowers
 
Risk or Opportunity – There are 2 Sides to Every Coin
Risk or Opportunity – There are 2 Sides to Every CoinRisk or Opportunity – There are 2 Sides to Every Coin
Risk or Opportunity – There are 2 Sides to Every CoinPECB
 
A brief overview of operational risk
A brief overview of operational riskA brief overview of operational risk
A brief overview of operational riskDiane Christina
 
Pert 2 crisis management
Pert 2  crisis managementPert 2  crisis management
Pert 2 crisis managementsutawidjaya_69
 

Semelhante a PRSM Webinar Feb 2012 (20)

Security and Business Continuity Working Together
Security and Business Continuity Working TogetherSecurity and Business Continuity Working Together
Security and Business Continuity Working Together
 
Webinar Crisis Communication & Business Continuity with G4S
Webinar Crisis Communication & Business Continuity with G4SWebinar Crisis Communication & Business Continuity with G4S
Webinar Crisis Communication & Business Continuity with G4S
 
Business Resilience
Business ResilienceBusiness Resilience
Business Resilience
 
Maritime accident n incident investigation
Maritime accident n incident investigationMaritime accident n incident investigation
Maritime accident n incident investigation
 
Ceo President Step Sheet
Ceo President Step SheetCeo President Step Sheet
Ceo President Step Sheet
 
SagaciousThink Overview
SagaciousThink OverviewSagaciousThink Overview
SagaciousThink Overview
 
Fns Incident Management Powered By En Case
Fns Incident Management Powered By En CaseFns Incident Management Powered By En Case
Fns Incident Management Powered By En Case
 
Incident Response in the age of Nation State Cyber Attacks
Incident Response in the age of Nation State Cyber AttacksIncident Response in the age of Nation State Cyber Attacks
Incident Response in the age of Nation State Cyber Attacks
 
IMI business continuity presentation
IMI business continuity presentationIMI business continuity presentation
IMI business continuity presentation
 
Using the CAPA process to prevent problems and mitigate risks in the life-sci...
Using the CAPA process to prevent problems and mitigate risks in the life-sci...Using the CAPA process to prevent problems and mitigate risks in the life-sci...
Using the CAPA process to prevent problems and mitigate risks in the life-sci...
 
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
 
Safety Score Card
Safety Score CardSafety Score Card
Safety Score Card
 
The key to improving your availability is fracas
The key to improving your availability is fracasThe key to improving your availability is fracas
The key to improving your availability is fracas
 
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...
10 Critical Aspects of IT Service Continuity to Protect Your Company's Digita...
 
hp 2005 Presentation
hp 2005  Presentationhp 2005  Presentation
hp 2005 Presentation
 
Upselling and upgrading webinar presentation
Upselling and upgrading webinar presentationUpselling and upgrading webinar presentation
Upselling and upgrading webinar presentation
 
10 Questions Every Company Should Be Asking Itself About its Business Resilience
10 Questions Every Company Should Be Asking Itself About its Business Resilience10 Questions Every Company Should Be Asking Itself About its Business Resilience
10 Questions Every Company Should Be Asking Itself About its Business Resilience
 
Risk or Opportunity – There are 2 Sides to Every Coin
Risk or Opportunity – There are 2 Sides to Every CoinRisk or Opportunity – There are 2 Sides to Every Coin
Risk or Opportunity – There are 2 Sides to Every Coin
 
A brief overview of operational risk
A brief overview of operational riskA brief overview of operational risk
A brief overview of operational risk
 
Pert 2 crisis management
Pert 2  crisis managementPert 2  crisis management
Pert 2 crisis management
 

Mais de afpizzitola

Houston Business Journal 7 6 12
Houston Business Journal 7 6 12Houston Business Journal 7 6 12
Houston Business Journal 7 6 12afpizzitola
 
Sustaining Your Business After A Disaster Fmj Jan Feb 2012
Sustaining Your Business After A Disaster   Fmj Jan Feb 2012Sustaining Your Business After A Disaster   Fmj Jan Feb 2012
Sustaining Your Business After A Disaster Fmj Jan Feb 2012afpizzitola
 
Prism March 2011
Prism March 2011Prism March 2011
Prism March 2011afpizzitola
 
Be Prepared Lo Res
Be Prepared Lo ResBe Prepared Lo Res
Be Prepared Lo Resafpizzitola
 

Mais de afpizzitola (8)

Houston Business Journal 7 6 12
Houston Business Journal 7 6 12Houston Business Journal 7 6 12
Houston Business Journal 7 6 12
 
NBiz June 2012
NBiz June 2012NBiz June 2012
NBiz June 2012
 
Sustaining Your Business After A Disaster Fmj Jan Feb 2012
Sustaining Your Business After A Disaster   Fmj Jan Feb 2012Sustaining Your Business After A Disaster   Fmj Jan Feb 2012
Sustaining Your Business After A Disaster Fmj Jan Feb 2012
 
Psprep New
Psprep NewPsprep New
Psprep New
 
Sept 11
Sept 11Sept 11
Sept 11
 
Prism March 2011
Prism March 2011Prism March 2011
Prism March 2011
 
101
101101
101
 
Be Prepared Lo Res
Be Prepared Lo ResBe Prepared Lo Res
Be Prepared Lo Res
 

PRSM Webinar Feb 2012

  • 1. Are You & Your Facility Ready? What’s New in Business Continuity, Personal Resiliency & Preparedness Mike Thomson Manager, Client Services & Business Continuity Programs ImpactReady @ ImpactWeather, Inc. Anthony Pizzitola, CFM, CBCP, MBCI Facilities & Disaster Recovery Manager Goode Company
  • 2. First, what are we solving for ? •Business Continuity Management is defined as a holistic management process that identifies potential impacts that threaten an organization and provides a framework for building resilience with the capability for an effective response that safeguards the interests of its key stakeholders, reputation and value creating activities. •The primary objective of Business Continuity Management is to allow the Executive to continue to manage business operations under adverse conditions, by the introduction of appropriate resilience strategies, recovery objectives, business continuity, operational risk management considerations and crisis management plans. Disaster Recovery Institute International
  • 3. Business Continuity Helps Manage Risk in Many Ways Cash & Credit Business Continuity Management Planning Intellectual • Protects 85% of the business Financial Property, Capacity Processes & Vital Records* Physical Security Property, Facilities and Infrastructure Life Safety Emergency Response • Nearly 170% return on investment Adherence to Business Risk or • Non-compliant companies paid $9.4M in Regulations Interruption Corporate Governance Operations Enterprise Risk fines, penalties & lost revenue • Compliant companies paid $3.5M Management Work Planning 2
  • 4. How are the Threats Identified to Prepare and Prevent a Disaster? •Don’t just visit the site, inspect the site! •Collaborate with your colleagues and vendor base to ID the top 10 threats in each category. ID regional natural threats, have a backup plan. ID manmade threats, launch control measures. ID technological threats, have a backup plan. •Is lack of compliance with OSHA and ADA a threat? Yes! •Is lack of Preventive & Predictive Maintenance a threat? Yes, just wait until Friday afternoon or Saturday evening. •Prepare a plan based on the above, implement controls , inspect and test!
  • 5. Continuity Planning and Response Move in a Cycle Assess Normal Business Operations Security Fire Flood Resume Regulatory Respond Terrorism Pandemic Storm ??? Recover Manage
  • 6. Develop A Disaster Preparation, Response and Recovery Plan •How So? Start by Identifying the Threats, their Probability and their Impacts to the Organization. How can the threats be controlled. •What are the threats? Natural Manmade Technological •Lack of preparation and a plan can threaten your career! •Lack of preparation and a plan is a call for the lawyers!
  • 7. Businesses Will Use Their Continuity Plans Regularly
  • 8. Business Preparedness Involves Five Important Steps 1. Develop a Program (for what you will do in an emergency) 2. Have Back-ups (for critical people, equipments and supplies) 3. Practice Your Plan (at least once each year) 4. Be Informed (about what might happen) 5. Get Involved (in preparing with your community)
  • 9. You Need Six Essential Tools in Your Preparedness Program 1. Severe Weather Alerts 2. Emergency Notification System 3. Incident Management Program 4. ePlan Documentation 5. Situational Awareness Monitoring 6. Personal Preparedness/Resiliency
  • 10. Weather Disasters at Highest Levels Ever Recorded Billions Source: NOAA Total economic damage = $52B, Most $1B+ Disaster Ever
  • 11. #1 – Essential Tool Severe Weather Services Forecasting, Monitoring and Alerting Tropical storm & hurricane analysis Severe weather analysis 24/7 alerting (including “all clear”) Domestic and International coverage Web-based weather briefings for key personnel 24/7 access to meteorologists for additional consultation and pre-scheduled conference calls Consulting and Support Programs Corporate Business Continuity & Emergency Preparedness: consulting services and training programs Personal Preparedness: Seminars, Webinars, and Personal Preparedness tools
  • 12. Capability Resident Meteorologist National Weather Service Web-based Weather Services Dedicated Weather Service Available 24x7x365 No Yes Limited, w/Advertisements Yes Domestic & International No No Limited Yes All Weather Services – Severe, Yes Yes No No Tropical, Marine Customized Alerts & Forecasts Yes No No Yes Any Time, Live Help Limited No No Yes Meteorologist Needed On-Site Possible No No Yes Imbedded “Calls to Action” Yes No No Yes Integrated Business Continuity Yes No No No Services Certified Crisis Experts On-call Limited No No Yes Branded, Direct Access Website Possible Yes No Yes All-Hazards Data Feeds/Alerting No No No Yes “Single Pane of Glass” No No No Yes All Clear Notices Limited No No Yes Video Production Studio No No No Yes Crisis Webconferences Possible No No Yes Daily Branded Weather Videos No No No Yes Site-specific, All-Hazard Trigger Yes Possible No No Reports Best Practice Web & Seminars No No No Yes Delivery to Any Device Yes No No Yes
  • 13. #2 – Essential Tool Emergency Notification System “Manually dialed telephone call trees are no longer acceptable for emergency notification. Effective incident management requires automation to ensure business continuity.” -Gartner, Inc.
  • 14. #3 – Essential Tool Incident Management Program Incident Detected Incident Management Team (IMT) Member Aware Incident Commander (IC) Site Back to *Division VP Normal *Manager of Administration Notified No Minor Major < 8 hrs > 8 hrs Standard Initial Incident IMT Operating Assessment Assembled Procedures Incident Briefing Impact Assessment Yes < 8 hrs > 8 hrs Incident Assessment Resume Normal Operations Incident Yes Objectives No Need to Critique IMT - Develop IAP Update Plan Response - SITREP Plan No Maintenance Report to and Update Alternate Executive Recovery Demobilization Operating Oversight Yes Procedures Procedures Committee End Site Back to *Foreseen Events Normal
  • 15. #4 – Essential Tool ePlan Documentation • Repository for all IM, BC, ER and DR plans • Component of comprehensive Business Continuity effort • Modules for both planning and incident management • Linked with emergency notification system • NIMS Compliant
  • 16. #5 – Essential Tool Situational Awareness Monitoring – Crisis management is moving from offices or command rooms to sophisticated mobile and online environments… – Breaking threats in dozens of risk categories now delivered as targeted alerts, anytime, anywhere…
  • 17. #6 – Essential Tool Personal Preparedness Most individuals, and thus their employers, are unprepared for a disaster Source: American Red Cross “Only 7% of Americans have taken the necessary steps to prepare for disasters”
  • 18. #6 – Essential Tool Personal Preparedness Most individuals, and thus their employers, are unprepared for a disaster “75% of company plans do not support employee resiliency” Source: Forrester Research
  • 19. # 6 – Essential Tool Employee Education Works • Annual Preparedness Programs • Speakers, Demos, Handouts • Company Intranet Campaigns • Home, Office Videos & Checklists • Contact Info Updates Ready Today = Ready in Crisis • Cost effective, 100x ROI • Save $2,800 per employee • Overcame Complacency • Mitigated Damages, Impact • Less Time Responding © Personal Recovery Concepts, All rights reserved • More Effective Action
  • 20. You Need To Be Prepared for Many Reasons • Protection (people, reputation, resources) • Legal (regulatory compliance, litigation) • Financial (more revenue, reduced costs) • Decision-making (one source, more confidence) • Good Business (stakeholders, market share)
  • 21. Contingency Planning in Many Areas is Highly Regulated • Required to have an “all hazards” plan • Weather is leading hazard causing business interruption • Plan must follow a Standard • All standards include preparedness of the workforce that the plan relies upon before, during and after a continuity event • PS-Prep will translate that requirement to any private sector company
  • 22. PS-Prep will Impact Every Private Sector Company Title IX, PL 110-53 (Private Sector Preparedness Act) • Outgrowth of 9/11 Commission Report • Independent certification of private sector emergency preparedness (including disaster/emergency management & business continuity) • Administer outside government by third parties • Give special consideration to small businesses (15 USC 632) • Based on standards (3 already approved) • FEMA Administrator is responsible • DHS is encouraging multiple standards • Initial certifications will be “conformity or non-conformity” based • Process slowed by change of administrations • Integrate, recognize & credit existing industry efforts, standards, best practices and reporting
  • 23. Should Vendors Comply with PS-Prep? •If business units are prepared, their supply chain should be equally prepared. •A resilient supply chain is prepared for natural disasters, business interruptions and terrorism. •Preparedness guarantees quality products with on-time deliveries to business units. •You can’t do business with an empty wagon. •The purpose of PS-Prep is to enhance nationwide resilience against all hazards and to support business preparedness.
  • 24. Some Benefits of Preparedness May Not be Obvious Minimizing Impact of Business Disruptions Insurance Supply Chain Resiliency Benefits Rating Agency Corporate Governance Acknowledgement Mitigating Reputational and other Legal Liability Benefits Post-Event Greater Preparedness Greater Preparedness
  • 25. 90% of Requirements Are Common in All Standards 1. Policy statement 2. Management commitment 3. Risk identification, assessment & analysis 4. Protect proprietary & confidential information 5. Incident management procedures & controls 6. Data control & backup (documents & information) 7. Continuity of critical operations 8. Exercises & testing 9. Independent audits
  • 26. Plan, Do, Check, Act First (or Next) Steps to Take to Mitigate Your Risks 1. Assess your current level of emergency preparedness against industry best practices (report & gap analysis) 2. Select a standard to use (e.g. FFEIC, OCC, ASIS, etc) 3. Supplement and/or improve your existing preparedness processes, plans & activities to meet intent of desired standard(s) 4. Contract with accredited certification body for formal assessment and certification 5. Conduct on-going surveillance and continual improvement processes
  • 27. Someone Will Ask for Your Business Preparedness Plan • Regulatory Auditors • Customers • Strategic Partners • Suppliers & Vendors • Fire & Law Enforcement
  • 28. Preparedness Increases Revenue and Reduces Costs • Oxford University study • Everyone loses value after crisis • Effective crisis response recovers quicker • 22% higher market cap 8 months after crisis • Cost of downtime = $84,000 -$90,000 per hour
  • 29. Q&A Have questions?? CONTACT Mike Thomson Anthony Pizzitola Manager, Client Services & Business Continuity Programs Facilities & Disaster Recovery Manager ImpactReady @ ImpactWeather, Inc. Goode Company 877-792-3220 713-667-9001 mthomson@impactweather.com apizzitola@goodecompany.com