SlideShare a Scribd company logo
1 of 29
Presenter:
Ms Rinske Geerlings
MD, Founder and
Principal Consultant/
Trainer @ Business As
Usual
Risk Consultant of the
Year 2017 (RMIA)
Outstanding Security
Consultant of the Year
2019 (OSPAs Finalist)
Business Continuity Planning (BCP) – Virtual seminar
Using lessons learned from Covid-19 to
improve your future ‘business as usual’
Interactive session
Using lessons learned from Covid-19 to improve
your future ‘business as usual’
First question:
Who has been
capturing lessons
learned and
future
improvements,
whilst the
lockdown was
ongoing?
Using lessons learned to achieve an improved ‘business as usual’
1. Innovations
 Brainstorm with your team about new service
offerings and methods you could choose during
future disruptions (e.g. online, from different
location, using different production facilities
or supply chains)
 Review responses from your customers,
suppliers and other stakeholders to any new
products/methods you’ve developed since
COVID-19
 Identify potential improvements to productivity/efficiency, e.g. reduction in staff
travel, less need for specific office space, change in office layout, more automation,
different staff shifts, cheaper/better ways to outsource or (on the contrary) bring
activities in-house
Case studies
Question
“Which tools have you implemented to optimise your remote work
technology (e.g. network connectivity at home, device security, phone
diversion procedures, etc) and which can you retain to work more effectively
in your new ”business as usual?”
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a strategy to ensure staff comfort
and productivity during disruptions
 Make sure managers are available in case
staff need extra support
 Build stock and a fast roll-out process for
any tools that staff may need in order to
work during a disruption, e.g. two-way
radios, spare laptops, spare mobile handsets,
pre-loaded SIM cards, mobile internet modems, headsets, phone diversion
procedures, remote voice mail set-up instructions etc
Using lessons learned to achieve an improved ‘business as usual’
2. Internal work practices
 Develop a template for centralised
communication via email/SMS/other tool,
in order to ensure all staff are headed in
the same direction during incidents
 Explore the best practices regarding holding
daily ‘huddles’ with staff during disruptions,
in case you are unable to all work from the
same location
 Discuss how these can be applied during business as usual
Question
“How are you staying
productive during a disruption,
if you are unable to sit
together with colleagues?
What are your key challenges
in this context?”
Using lessons learned to achieve an improved ‘business as usual’
3. External collaboration
 Identify which tools your suppliers,
clients and other counterparts preferred
during the lockdown (e.g. in the event of
Internet downtime, mobile network
outages or work from home situations)
 Implement and test related collaboration
tools and arrange for licensing,
installation and staff training so you are
ready to seamlessly keep sales/orders
and customer support going
Question
“If Internet and mobile telephony
were to go down for 1-2 days,
what does your BCP say?”
4. The actual transition to ‘the new normal’
 Move back by department, office/floor,
business process or technology used?
 Properly identify if return-to-work on certain
days of the week by certain staff actually
achieves the intended benefits (and doesn’t
complicate things)
 Ensure appropriate stages for facilities, HR
and IT to manage the transition including
proper testing
Using lessons learned to achieve an improved ‘business as usual’
Using lessons learned to improve your new ‘business as usual’
5. Better risk management
Revisit information sharing policies/controls in the event of a disruption, e.g.
 Secure network connectivity (incl WPS2 protection)
 Remote access software (e.g. VPN) including licences
 Patching of operating systems and ensure endpoint security (e.g. malware/virus
scanners)
 Provide regular reminders about information security to staff
 Conduct an ISO 27001 gap analysis
Revisit your Business Continuity Plan (BCP)
 Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain
disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT
system failure)
 Regularly walk-through/test your disruption scenarios
 Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and
regular ‘mini invocations’
 Less is more – Reduce document volume and make it easy to maintain
 Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and
gaming techniques including ‘red teaming’
 Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’
 Global best practice: For proper BCP as with DR, Risk Management and Security),
apply up-to-date principles/strategies (and standards!)
Making Business Continuity plans that actually work when you
need them most
• Philosophy of resilient networks
• What is different ?
• How do they work ?
• Why is it better than classic networks ?
• And all of your questions !
The topic of 2day
How to create resilience ?
We work in silos
BCP
How to create resilience ?
Multi silos in organisations
BCP
How to create resilience ?
Multi organisations in networks
BCP
BCP
BCP
BCP
BCP
BCP
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
What is resilience in this context ?
€ €
products/
services
products/
services
Take a simple chain
Examples of non resilience in chains:
Customer
100 % value
Suppliers
60 % value
OEM
40 % value
‘Me, myself and I’ control =
the answer to all mishaps
8020
Increased risk at
customer level,
lower resilience
We need another direction !
Classic reaction to build resilience:
Risk
Costs
Quality
Profit
Statement:
The better you are, the
simpler the world, the
more resilient you are
energy,
costs,
risks
# learning cycles
complex
simple
Based on Resource Based View, Barney, 1991, and all later versions
New reaction to build resilience:
Add ‘expertise’ thinking:
Customer
100 % value
integrator
These networks are faster, cheaper, better (Q)
Based on Wouter Beelaerts, 2010
18 %
18 %
13 %
9 %
18 %
13 %
Profit = up
10 %
Resilience = up
Change the network for resilience:
utilise expertise
Next step: embrace dependency:
Resilient Customer
value
integrator
Resilience =
further up
Results in the integrator being a
resilience hub:
Resilient Supplier
value
goods & services
information & money
Remarkable results:
• speed to market: up
• total cost: down
• network profit: up
• network agility: up
• network resilience: up
Building the
resilient network
Conclusion:
classic networks F, C, B networks
embrace
dependency
Resilient
Customer
value
integrat
or
Resilient
Supplier
value
the resilient network
 Start talking about dependency with your network partners
 Add the outcome to your BCP !
Simple to start:
ISO 22301
Training Courses
• ISO 22301 Introduction
1 Day Course
• ISO 22301 Foundation
2 Days Course
• ISO 22301 Lead Implementer
5 Days Course
• ISO 22301 Lead Auditor
5 Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
22301
www.pecb.com/events
THANK YOU
?
rinske@businessasusual.com.au
santema@scenter.nl
linkedin.com/in/businessasusual/
linkedin.com/in/siccosantema
www.businessasusual.com.au
www.scenter.nl

More Related Content

What's hot

Jack Welch _ People & Organisations
Jack Welch _ People & OrganisationsJack Welch _ People & Organisations
Jack Welch _ People & OrganisationsFiona O'Driscoll
 
Case Studies Analysis Framework
Case Studies Analysis FrameworkCase Studies Analysis Framework
Case Studies Analysis FrameworkDr. Rana Singh
 
20 Quotes to Challenge Convention on The Future of Work
20 Quotes to Challenge Convention on The Future of Work20 Quotes to Challenge Convention on The Future of Work
20 Quotes to Challenge Convention on The Future of WorkJacob Morgan
 
Innovation and entrepreneurship
Innovation and entrepreneurship Innovation and entrepreneurship
Innovation and entrepreneurship Bhaumik Patel
 
Ob1 unit 3 chapter - 8 - personality
Ob1   unit 3 chapter - 8 - personalityOb1   unit 3 chapter - 8 - personality
Ob1 unit 3 chapter - 8 - personalityDr S Gokula Krishnan
 
Imp1..Chapter 03 Competitive Environment Mcq
Imp1..Chapter 03 Competitive  Environment  McqImp1..Chapter 03 Competitive  Environment  Mcq
Imp1..Chapter 03 Competitive Environment McqAshar Azam
 
Clayton Christensen Innovative Prescription
Clayton Christensen Innovative PrescriptionClayton Christensen Innovative Prescription
Clayton Christensen Innovative PrescriptionLucien Engelen
 
porter Five force analysis
porter Five force analysisporter Five force analysis
porter Five force analysisManish Chaurasia
 
What is strategy by Porter
What is strategy by PorterWhat is strategy by Porter
What is strategy by Porternileshroll
 
Innovative Leadership
Innovative LeadershipInnovative Leadership
Innovative LeadershipElijah Ezendu
 
Strategy Development
Strategy DevelopmentStrategy Development
Strategy DevelopmentPaul Schumann
 
IBM: Case Analysis
IBM: Case AnalysisIBM: Case Analysis
IBM: Case AnalysisUrmi Arora
 

What's hot (20)

Porter’s Five Forces Templates
Porter’s Five Forces TemplatesPorter’s Five Forces Templates
Porter’s Five Forces Templates
 
Jack Welch _ People & Organisations
Jack Welch _ People & OrganisationsJack Welch _ People & Organisations
Jack Welch _ People & Organisations
 
Blue Ocean Strategy
Blue Ocean StrategyBlue Ocean Strategy
Blue Ocean Strategy
 
Case Studies Analysis Framework
Case Studies Analysis FrameworkCase Studies Analysis Framework
Case Studies Analysis Framework
 
20 Quotes to Challenge Convention on The Future of Work
20 Quotes to Challenge Convention on The Future of Work20 Quotes to Challenge Convention on The Future of Work
20 Quotes to Challenge Convention on The Future of Work
 
Innovation and entrepreneurship
Innovation and entrepreneurship Innovation and entrepreneurship
Innovation and entrepreneurship
 
Ob1 unit 3 chapter - 8 - personality
Ob1   unit 3 chapter - 8 - personalityOb1   unit 3 chapter - 8 - personality
Ob1 unit 3 chapter - 8 - personality
 
Strategy
StrategyStrategy
Strategy
 
Imp1..Chapter 03 Competitive Environment Mcq
Imp1..Chapter 03 Competitive  Environment  McqImp1..Chapter 03 Competitive  Environment  Mcq
Imp1..Chapter 03 Competitive Environment Mcq
 
Clayton Christensen Innovative Prescription
Clayton Christensen Innovative PrescriptionClayton Christensen Innovative Prescription
Clayton Christensen Innovative Prescription
 
Creating Shared Value
Creating Shared ValueCreating Shared Value
Creating Shared Value
 
porter Five force analysis
porter Five force analysisporter Five force analysis
porter Five force analysis
 
What is strategy by Porter
What is strategy by PorterWhat is strategy by Porter
What is strategy by Porter
 
Blue Ocean Strategy
Blue Ocean Strategy  Blue Ocean Strategy
Blue Ocean Strategy
 
Innovative Leadership
Innovative LeadershipInnovative Leadership
Innovative Leadership
 
Strategy Development
Strategy DevelopmentStrategy Development
Strategy Development
 
IBM: Case Analysis
IBM: Case AnalysisIBM: Case Analysis
IBM: Case Analysis
 
Danaher's Instruments of Change
Danaher's Instruments of ChangeDanaher's Instruments of Change
Danaher's Instruments of Change
 
Disruptive Innovation
Disruptive InnovationDisruptive Innovation
Disruptive Innovation
 
UPS HR and facts
UPS  HR and factsUPS  HR and facts
UPS HR and facts
 

Similar to Moving to a New "Business as Usual" after COVID-19

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17jekroggel
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Videoguy
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...360 BSI
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplacePaperjam_redaction
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Net at Work
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetAshley Deuble
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)AdaCore
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attranhcrowley
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations managementsmumbahelp
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profilescottsdale
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profilescottsdale
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07Enthiosys Inc
 

Similar to Moving to a New "Business as Usual" after COVID-19 (20)

Prima 10 wolf-6-17
Prima 10 wolf-6-17Prima 10 wolf-6-17
Prima 10 wolf-6-17
 
Stabilizing Revenue
Stabilizing RevenueStabilizing Revenue
Stabilizing Revenue
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for Unify and Simplify Better Collaboration for
Unify and Simplify Better Collaboration for
 
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
Business Continuity, Disaster Recovery Planning & Leadership, 16 - 19 Februar...
 
It days 2015 digital transformation and workplace
It days 2015   digital transformation and workplaceIt days 2015   digital transformation and workplace
It days 2015 digital transformation and workplace
 
Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!Endpoint Security & Why It Matters!
Endpoint Security & Why It Matters!
 
Creating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budgetCreating a compliance assessment program on a tight budget
Creating a compliance assessment program on a tight budget
 
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOsKaseya: Making Operational IT Strategic: Special Edition for Education CIOs
Kaseya: Making Operational IT Strategic: Special Edition for Education CIOs
 
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
 
SLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft ServicesSLBdiensten XP sessie: presentatie Microsoft Services
SLBdiensten XP sessie: presentatie Microsoft Services
 
Post 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attrPost 11. Long term GoalThe Group’s goal is to offer attr
Post 11. Long term GoalThe Group’s goal is to offer attr
 
resume_alcantara
resume_alcantararesume_alcantara
resume_alcantara
 
Bba501 & production and operations management
Bba501 & production and operations managementBba501 & production and operations management
Bba501 & production and operations management
 
Blaine Kriebel Professional Profile
Blaine Kriebel   Professional ProfileBlaine Kriebel   Professional Profile
Blaine Kriebel Professional Profile
 
Blaine kriebel professional profile
Blaine kriebel   professional profileBlaine kriebel   professional profile
Blaine kriebel professional profile
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 
Better Software Keynote The Complete Developer 07
Better Software Keynote  The Complete Developer 07Better Software Keynote  The Complete Developer 07
Better Software Keynote The Complete Developer 07
 

More from PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

More from PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxlancelewisportillo
 
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxBIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxSayali Powar
 
Narcotic and Non Narcotic Analgesic..pdf
Narcotic and Non Narcotic Analgesic..pdfNarcotic and Non Narcotic Analgesic..pdf
Narcotic and Non Narcotic Analgesic..pdfPrerana Jadhav
 
4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptxmary850239
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Projectjordimapav
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITW
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITWQ-Factor HISPOL Quiz-6th April 2024, Quiz Club NITW
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITWQuiz Club NITW
 
CHEST Proprioceptive neuromuscular facilitation.pptx
CHEST Proprioceptive neuromuscular facilitation.pptxCHEST Proprioceptive neuromuscular facilitation.pptx
CHEST Proprioceptive neuromuscular facilitation.pptxAneriPatwari
 
How to Make a Duplicate of Your Odoo 17 Database
How to Make a Duplicate of Your Odoo 17 DatabaseHow to Make a Duplicate of Your Odoo 17 Database
How to Make a Duplicate of Your Odoo 17 DatabaseCeline George
 
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnv
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnvESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnv
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnvRicaMaeCastro1
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Celine George
 
MS4 level being good citizen -imperative- (1) (1).pdf
MS4 level   being good citizen -imperative- (1) (1).pdfMS4 level   being good citizen -imperative- (1) (1).pdf
MS4 level being good citizen -imperative- (1) (1).pdfMr Bounab Samir
 
Reading and Writing Skills 11 quarter 4 melc 1
Reading and Writing Skills 11 quarter 4 melc 1Reading and Writing Skills 11 quarter 4 melc 1
Reading and Writing Skills 11 quarter 4 melc 1GloryAnnCastre1
 
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...DhatriParmar
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptxmary850239
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management SystemChristalin Nelson
 
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQ-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQuiz Club NITW
 
4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptxmary850239
 

Recently uploaded (20)

Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
 
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxBIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
 
Narcotic and Non Narcotic Analgesic..pdf
Narcotic and Non Narcotic Analgesic..pdfNarcotic and Non Narcotic Analgesic..pdf
Narcotic and Non Narcotic Analgesic..pdf
 
4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Project
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITW
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITWQ-Factor HISPOL Quiz-6th April 2024, Quiz Club NITW
Q-Factor HISPOL Quiz-6th April 2024, Quiz Club NITW
 
CHEST Proprioceptive neuromuscular facilitation.pptx
CHEST Proprioceptive neuromuscular facilitation.pptxCHEST Proprioceptive neuromuscular facilitation.pptx
CHEST Proprioceptive neuromuscular facilitation.pptx
 
How to Make a Duplicate of Your Odoo 17 Database
How to Make a Duplicate of Your Odoo 17 DatabaseHow to Make a Duplicate of Your Odoo 17 Database
How to Make a Duplicate of Your Odoo 17 Database
 
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnv
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnvESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnv
ESP 4-EDITED.pdfmmcncncncmcmmnmnmncnmncmnnjvnnv
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17
 
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptxINCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
INCLUSIVE EDUCATION PRACTICES FOR TEACHERS AND TRAINERS.pptx
 
Faculty Profile prashantha K EEE dept Sri Sairam college of Engineering
Faculty Profile prashantha K EEE dept Sri Sairam college of EngineeringFaculty Profile prashantha K EEE dept Sri Sairam college of Engineering
Faculty Profile prashantha K EEE dept Sri Sairam college of Engineering
 
MS4 level being good citizen -imperative- (1) (1).pdf
MS4 level   being good citizen -imperative- (1) (1).pdfMS4 level   being good citizen -imperative- (1) (1).pdf
MS4 level being good citizen -imperative- (1) (1).pdf
 
Reading and Writing Skills 11 quarter 4 melc 1
Reading and Writing Skills 11 quarter 4 melc 1Reading and Writing Skills 11 quarter 4 melc 1
Reading and Writing Skills 11 quarter 4 melc 1
 
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...
Beauty Amidst the Bytes_ Unearthing Unexpected Advantages of the Digital Wast...
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management System
 
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQ-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
 
4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx
 

Moving to a New "Business as Usual" after COVID-19

  • 1.
  • 2. Presenter: Ms Rinske Geerlings MD, Founder and Principal Consultant/ Trainer @ Business As Usual Risk Consultant of the Year 2017 (RMIA) Outstanding Security Consultant of the Year 2019 (OSPAs Finalist) Business Continuity Planning (BCP) – Virtual seminar Using lessons learned from Covid-19 to improve your future ‘business as usual’ Interactive session
  • 3. Using lessons learned from Covid-19 to improve your future ‘business as usual’ First question: Who has been capturing lessons learned and future improvements, whilst the lockdown was ongoing?
  • 4. Using lessons learned to achieve an improved ‘business as usual’ 1. Innovations  Brainstorm with your team about new service offerings and methods you could choose during future disruptions (e.g. online, from different location, using different production facilities or supply chains)  Review responses from your customers, suppliers and other stakeholders to any new products/methods you’ve developed since COVID-19  Identify potential improvements to productivity/efficiency, e.g. reduction in staff travel, less need for specific office space, change in office layout, more automation, different staff shifts, cheaper/better ways to outsource or (on the contrary) bring activities in-house
  • 6. Question “Which tools have you implemented to optimise your remote work technology (e.g. network connectivity at home, device security, phone diversion procedures, etc) and which can you retain to work more effectively in your new ”business as usual?”
  • 7. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a strategy to ensure staff comfort and productivity during disruptions  Make sure managers are available in case staff need extra support  Build stock and a fast roll-out process for any tools that staff may need in order to work during a disruption, e.g. two-way radios, spare laptops, spare mobile handsets, pre-loaded SIM cards, mobile internet modems, headsets, phone diversion procedures, remote voice mail set-up instructions etc
  • 8. Using lessons learned to achieve an improved ‘business as usual’ 2. Internal work practices  Develop a template for centralised communication via email/SMS/other tool, in order to ensure all staff are headed in the same direction during incidents  Explore the best practices regarding holding daily ‘huddles’ with staff during disruptions, in case you are unable to all work from the same location  Discuss how these can be applied during business as usual
  • 9. Question “How are you staying productive during a disruption, if you are unable to sit together with colleagues? What are your key challenges in this context?”
  • 10. Using lessons learned to achieve an improved ‘business as usual’ 3. External collaboration  Identify which tools your suppliers, clients and other counterparts preferred during the lockdown (e.g. in the event of Internet downtime, mobile network outages or work from home situations)  Implement and test related collaboration tools and arrange for licensing, installation and staff training so you are ready to seamlessly keep sales/orders and customer support going
  • 11. Question “If Internet and mobile telephony were to go down for 1-2 days, what does your BCP say?”
  • 12. 4. The actual transition to ‘the new normal’  Move back by department, office/floor, business process or technology used?  Properly identify if return-to-work on certain days of the week by certain staff actually achieves the intended benefits (and doesn’t complicate things)  Ensure appropriate stages for facilities, HR and IT to manage the transition including proper testing Using lessons learned to achieve an improved ‘business as usual’
  • 13. Using lessons learned to improve your new ‘business as usual’ 5. Better risk management Revisit information sharing policies/controls in the event of a disruption, e.g.  Secure network connectivity (incl WPS2 protection)  Remote access software (e.g. VPN) including licences  Patching of operating systems and ensure endpoint security (e.g. malware/virus scanners)  Provide regular reminders about information security to staff  Conduct an ISO 27001 gap analysis Revisit your Business Continuity Plan (BCP)  Lessons learned about ‘slow onset events’ (e.g. the pandemic, supply chain disruptions) vs ‘immediate impact events’ (e.g. fire, flood, power black-out, IT system failure)  Regularly walk-through/test your disruption scenarios
  • 14.  Practical: Ensure staff are ‘incident-ready’ by means of Quick Reference Cards and regular ‘mini invocations’  Less is more – Reduce document volume and make it easy to maintain  Fun & engaging: Involve staff ‘hands-on’ including use of interactive workshops and gaming techniques including ‘red teaming’  Culture: Ensure there is a comfort amongst staff that making mistakes is ‘OK’  Global best practice: For proper BCP as with DR, Risk Management and Security), apply up-to-date principles/strategies (and standards!) Making Business Continuity plans that actually work when you need them most
  • 15. • Philosophy of resilient networks • What is different ? • How do they work ? • Why is it better than classic networks ? • And all of your questions ! The topic of 2day
  • 16. How to create resilience ? We work in silos BCP
  • 17. How to create resilience ? Multi silos in organisations BCP
  • 18. How to create resilience ? Multi organisations in networks BCP BCP BCP BCP BCP BCP
  • 19. Customer 100 % value Suppliers 60 % value OEM 40 % value What is resilience in this context ? € € products/ services products/ services Take a simple chain
  • 20. Examples of non resilience in chains:
  • 21. Customer 100 % value Suppliers 60 % value OEM 40 % value ‘Me, myself and I’ control = the answer to all mishaps 8020 Increased risk at customer level, lower resilience We need another direction ! Classic reaction to build resilience:
  • 22. Risk Costs Quality Profit Statement: The better you are, the simpler the world, the more resilient you are energy, costs, risks # learning cycles complex simple Based on Resource Based View, Barney, 1991, and all later versions New reaction to build resilience: Add ‘expertise’ thinking:
  • 23. Customer 100 % value integrator These networks are faster, cheaper, better (Q) Based on Wouter Beelaerts, 2010 18 % 18 % 13 % 9 % 18 % 13 % Profit = up 10 % Resilience = up Change the network for resilience: utilise expertise
  • 24. Next step: embrace dependency:
  • 25. Resilient Customer value integrator Resilience = further up Results in the integrator being a resilience hub: Resilient Supplier value goods & services information & money Remarkable results: • speed to market: up • total cost: down • network profit: up • network agility: up • network resilience: up
  • 26. Building the resilient network Conclusion: classic networks F, C, B networks embrace dependency Resilient Customer value integrat or Resilient Supplier value the resilient network
  • 27.  Start talking about dependency with your network partners  Add the outcome to your BCP ! Simple to start:
  • 28. ISO 22301 Training Courses • ISO 22301 Introduction 1 Day Course • ISO 22301 Foundation 2 Days Course • ISO 22301 Lead Implementer 5 Days Course • ISO 22301 Lead Auditor 5 Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 22301 www.pecb.com/events