drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

A Roadmap from Business Continuity to Operational Resilience

Business Continuity ManagementResilience Strategy & Program Maturity

Business continuity (BC) and disaster recovery (DR) services are among the most critical services in financial institutions. Of course, these services are also important for any organization, but large-scale cuts are unthinkable in an organization such as financial institutions which have a serious impact on the economy market. For this reason, such organizations make very serious investments in the field of continuity, take all kinds of actions, and carry out operations with very experienced teams to ensure the continuity of the organization.

This becomes even more important if the financial institution where you manage business continuity is also one of the largest in the country and a partnership with the state. In the event of a serious problem, not only the financial institution partners but also the politicians of the country will be asked to account for it, and it will be necessary to give an account to citizens.

Also, consider the example organization's headquarters and data center are in a city at severe earthquake risk. On top of that, I would like to state the risk has increased incrementally, as the city is on a fault line where a serious earthquake is expected in the near future.

With this short example, I tried to provide evidence of how much an organization's risk can increase due to many different factors.

It may seem interesting at first to say, but BC/DR is not enough to manage such a high level of risk. Don't worry, I will now explain the acceptable and valid reasons for this.

First, BC/DR usually takes reactive action after a disaster occurs. Today, no organization will tolerate such a situation in the unbearable lightness of competition. Secondly, an organization at such a risk is expected to be prepared and resilient. In other words, to act reactively in all matters related to a disaster which may occur. The solution to this is the concept of operational resilience.

The fact the organization is equipped with measures to implement operational resilience means it has taken serious precautions against all kinds of risks, has taken action, created awareness, and conveyed all these to all its stakeholders.

Can we not take sufficient precautions with BC/DR processes? The biggest difference, as we mentioned above, in resilience is proactive, while the BC/DR duo is more reactive; that is, it mainly focuses on issues after the disaster. Yes, there are preparations for before, like emergency plans, but these are not operational preparations, they are plans to prevent confusion for the aftermath. We need to be more vigilant, cautious, prepared, in short resilient, so we can be affected by the potential disaster in the least possible way.

It would not be right to limit operational resilience to only physical disasters such as earthquakes and floods. The word "resilient" also means to be durable for all conditions and situations. In fact, we have experienced the biggest example of this with the pandemic. In a time when we are experiencing massive closures, organizations which established the resilience methodology survived this period very easily. They quickly put their work-from-home structure into practice and continued to employ all their employees under safe conditions, without having to close. Fortunately, some that were not prepared for this situation were able to survive this process with temporary closures or serious damage.

Apart from the pandemic, events such as cyberattacks, new regulations, and laws (which require rapid adaptation) are among the critical elements to affect the continuity of your organization, depending on resilience. While a bank which has suffered a serious disaster tries to prevent the loss of customers, an upstate factory affected by a forest fire will focus on establishing a safer, more sustainable work environment for its workers.

What can we do to provide operational resilience? Let's talk briefly about preparation and maturity. Here, we accept your BC/DR structure is managed smoothly with a very good methodology; everything from business impact analysis to disaster plans, from trained expert teams to disaster tests, is well planned and operated. If these structures do not exist, or if they are not built and operated properly, it is necessary to establish this first and consider operational resilience as a second step. The BC/DR structure must be set up first.

What should be done to manage this process? The path from BC/DR to operational resilience is a little bit about how seriously you take this job and how serious you want to take measures. As I mentioned earlier, you will need to increase precautions when faced with the possibility of serious risks and high potential disasters.

However, if we are talking about, for example, the headquarters or data center of an organization with no threat of earthquakes or floods, actions to be taken regarding these issues will be reduced accordingly.

Let's assume you have been running basic business continuity methodology for years. From here, you may seek additional domains on the way to operational resilience. These domains were created with a very broad perspective and offer a solution to addresses the widest range of events and risks.

When you take a look at Figure-1, I'm sure you noticed that business continuity, disaster recovery, and crisis management are represented as domains here. This situation shows us that operational resilience deals with the issue of continuity in a broader framework, and it is necessary to take action and communicate methodologically in very different areas.

What to do when such a wide scope comes to the fore? There is no need to panic; the important thing is to create the methodology to make the structures here operate properly. The data content and attributes may be different in the sub-details, but since the content will be very similar even in different organizations, the same structure can be adapted to many organizations with the necessary arrangements. The most important action here is to what extent you want to apply this structure due to the risks you have and with what you aim. If you are aiming for full implementation, then you can prepare a competent, comprehensive team and get started. On the contrary, it is possible to carry out a more limited and target-oriented work with a team of just a few people.

Let’s touch on these domains and the issues which may need to be addressed in detail:

1. Capacity management: determining the resources and capacity which will bring the organization back to life and ensure the smooth running of the operation.

2. Change management: by embedding change management into operational resilience, you can control IT changes to absorb, adapt, and effectively respond.

3. Communications: communication plan should be prepared which may include best-case and worst-case scenarios for optimal operational resilience. This plan can be used for post-crisis communication planning and identifying vulnerabilities. On the other side this plan can be used as a preparedness plan at the same time so it should contain identifying and simulating teams.

4. Continuity management: performing a business impact analysis, removing critical services, and making recovery plans for a disaster situation.

5. Crisis management: creating a 360-degree perspective which will identify the current crisis and share it with all stakeholders.

6. Cybersecurity: making the necessary preparations to be vigilant and responsive to cyberattacks.

7. Dependencies: identifying critical assets and alternatives with dependencies.

8. Governance, audit, compliance: follow-up of standards and continuous monitoring of compliance with them.

9. Human resources: identifying the people who will take action and carry out the basic operation in a crisis.

10. Incident management: taking a proactive action to ensure resilience and planning the necessary actions to reduce risks, especially health and safety.

11. Risk management: planning of actions to identify, monitor, and minimize risks.

12. Service management: assure operational excellence and efficiency.

13. Supply-chain management: identifying and managing critical service providers and ensuring they will provide ongoing support in an emergency.

14. Organizational behavior: extending the operational resilience vision to the organization and testing it with practice.

It is not necessary to include all these domains in the methodology to establish organizational resilience and ensure it functions fully. As I mentioned above, it would be more appropriate to focus on the highest risk of the organization. For a large financial institution with a "high" earthquake risk level, you don't have a chance to focus on a specific domain. In such a case, you will have no solution other than detailing all these domains to the highest possible level and operating them flawlessly.

Considering the size of your organization, the risks it has, the economic, physical, and other conditions it is in, you can remove some domains or group them differently.

Domains which need to be handled in order for an organization with a good infrastructure – taken all precautions against risks, whose business continuity management system works flawlessly, and whose risks are very low – cannot be the same as those of an organization with the opposite processes. At this point, it would be the most appropriate solution to calculate the benefit/loss of operations and make these decisions accordingly.

A small sample can be useful; it may be better for understanding the methodology. If your main concern is unplanned interruptions then you should consider continuity and related subjects like supply-chain management, communications, crisis management, and incident management. On the other side, if your priority is cybersecurity then crisis management, governance, audit, compliance, risk management, and dependencies should be focused.

Although the initial adaptation, implementation, and operation process will be more difficult and time consuming, it is our main goal to increase the resilience of the organization against all kinds of risks. You can accept the application of all these domains at the same time as a general rule.

In this article, I tried to briefly touch on which domains you can extend a very effective and powerful business continuity system to operational resilience by taking additional actions. What is critical here is to determine the main domains. How deep the operations to be carried out here are all about the risks you have and their effective potential.

Now it's your turn. You can immediately discuss the current risks, determine which domains to deal with, and embark on the operational resilience journey.

ABOUT THE AUTHOR

Hakan Kantas

Hakan Kantas is an IT director who has IT experience of more than 30 years in several subjects from IT GRC to operational resilience. Currently he is working in operational resilience, IT continuity management, and disaster recovery technologies and methodologies.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.