Lootok

Menu

What's new?

The future of resiliency is not resiliency

Zona Walton [ADP - Global Business Resiliency] and I spoke at a private conference last month. The title of our session was The Future of Resiliency. We explored the idea that the future of resiliency isn’t resiliency; that is, it will be something else.

Lootok future of resiliency
The future of resiliency is not resiliency.

Read Post

Lootok presented at Continuity Insights 2016

Last week, Lootok presented with Matt Jarm from Mars Inc. about supply chain resiliency at the New York Continuity Insights Conference.

In our session, we covered the critical aspects of rolling out and maintaining a global supply chain operational risk – business continuity program.  Supply chain leaders are naturally gifted at managing risk, as it is part of their daily lives. But, supply chains are naturally dynamic (i.e., disruptive), which makes many of our traditional operational risk – business continuity techniques ineffective. Supply chain leaders need risk management techniques and tools to help them make decisions, solve problems, and communicate in complex environments.

Learning objectives covered:

  • Common pitfalls (i.e. too fast, too big) of risk and resiliency supply chain rollouts.
  • The necessary methodologies, tools, and roadmaps to be successful in today’s complex, nonlinear, supply-chain environments.

Download full presentation

Supply Chain Resilincy Lootok Continuity Insights 2016
Download full presentation

Read Post

Lootok presents at the Enterprise Risk Management Summit

Join me at the Enterprise Risk Management Summit in Las Vegas on November 2, 2016!

I will be speaking with Andrew Miller from ADP about linking reputation management, business continuity and crisis planning to strengthen risk resilience.

Where: Rio All-Suite Hotel & Casino in Las Vegas
When: November 2, 2016, 9:00am
What: Linking reputation management, business continuity and crisis planning to strengthen risk resilience

ERM conference 2016
We look forward to seeing you in Las Vegas!

Read Post

Risk Management’s Sweet Spot

Chris de Wolfe, global director of risk management at Mars Inc., shares his challenges of getting the global risk management program at Mars up and running.

“The CRM group had a lot to offer but was severely underutilized, which led to high insurance premiums, a high risk profile, and a significantly reduced resiliency and recovery capability,” Chris said.

Reflecting on how Mars as a business became a major success, de Wolfe decided that he needed to market and promote his own department in the same way. Partnering with Lootok, a risk management consultancy firm, he developed a strategy to engage with the employees in a fun yet educational way. He devised a 5- to 10-year plan, broken into 12- to 18-month strategies and individual project plans by mapping out all of the products and services that risk management offers. He conducted a perception survey and drew up a program based on the ABCs of risk management.

“The ABCs allowed people to understand that risk management not only provides insurance, but it also ensures that the business continues,” said de Wolfe.

Sean Murphy, CEO and founder of Lootok, said of de Wolfe:

“I’ve known Chris for 10 years and what differentiates him is that he treats his program as a business. He had a good program before but he wasn’t satisfied with it so he completely revamped it and is now reaping the benefits.”

Read full article

Read Post

Can a crisis make you a celebrity?

Picture of man speaking to the press
Ready or not.  Say, “Cheese!”

While artists, athletes, and performers struggle to make their mark in the public eye with a memorable act or viral moment, a different type of celebrity has been emerging on the scene - the spokesperson for a crisis.

Here’s a quick exercise to highlight the point:

Jeffrey Boyd, Lew Frankfort, and Stephen Hemsley. Do these names sound familiar?
If not, don’t feel bad. They are the CEO’s of Priceline.com, Coach, and UnitedHealth Group, respectively.

Now, how about the names Tim Cook and James Comey?
We can immediately recall them as the CEO of Apple and the FBI Director, respectively, feuding over a locked iPhone involving a federal investigation of the San Bernardino shooting.

The media diligently covered Cook and Comey’s debate for more than three months. During that time, both men emerged as stars in a cast of characters ranging from lawyers, judges, politicians, and even presidential candidates. The media and public tuned in to hear their perspectives on data privacy, security, technology, civil rights, and terrorism.

Read Post

Lootok’s 8Rs™ of Resiliency: easy and effective model to communicate, employ, and remember

When working with the masses [end-users; not experts in risk management, business continuity, crisis management], I find it beneficial to present clear, concise, and concrete packaged solutions. People need guidance and structure to help them think through problems and build effective plans. This is one of the reasons Lootok created the 8Rs™ of Resiliency. The goal the 8Rs is to reduce uncertainty, simplify complexity, structure thinking and dialogue, build common ground, and establish preparatory activities. The 8Rs facilitates planning with a plan as the end deliverable (i.e., plans are the byproduct of planning). The 8Rs are designed to provide people with a set of options they can employ to continue operations under various threats and timelines. The 8Rs™ of Resiliency comprises of the following:

  1. Relocate - physical moving assets (e.g., people, technology, equipment) to another location
  2. Reassign – transferring processes (i.e., work) to another location
  3. Repair / Replace – capabilities in place to fix the problem at time of event
  4. Reinforce – fortify, strengthen, assets to tolerate greater impacts and occurrences
  5. Replicate – simultaneous production (i.e., processes, technology, work) at two locations [duplication]; active-active
  6. Redundancy - extra capacity and inventory
  7. Risk Transfer – shift risk to other entities through insurance, contracts, and risk pooling
  8. Relinquish – do nothing [e.g., too cost prohibitive]; risk acceptance strategy
Lootok's 8Rs™
Lootok’s 8Rs™

Read Post

Should global organizations have a global security operations center (GSOC)?

“How did you go bankrupt?”
“Two ways. Gradually, then suddenly.”

- Ernest Hemingway, The Sun Also Rises

I was working with a head of risk management—the chief risk officer—at a global organization that does not have a GSOC. One night over dinner, I asked him why his organization didn’t have one, and suggested he spearhead the initiative. His response? “I’m not convinced we need one. The organization has always operated without a GSOC, so why start now?” He also said, “The reality is, we’re already doing it here and there. The system works fine. Let people do their thing.” Something that seemed so obvious to me and so unnecessary to him left me on the defensive and him on offense.

The reality is, if you’re a global organization, you need a GSOC—or some version of it. If you don’t have one, you will need to communicate the severity of the situation and get one. Allow me to illustrate the need for such capabilities so you can justify the business case to your leadership and board…

GSOC

Read Post

Lessons learned from Mayo Clinic - risk management is the organization’s immune system

Since starting Lootok, once a year I go to Rochester, Minnesota, my home State, to take my annual executive physical at the Mayo Clinic. It gives me a good reason to get back to Minnesota to visit family and friends, while maximizing my medical checkups. In just two days, more than fifteen doctors evaluate me. Risk management shares many similarities with the medical field, and it’s where you find the best analogies and metaphors. I wanted to share few of the insights I have gleaned over my time at Mayo.

Risk management is analogous to the immune system. It is not a thing or part. It is a system that co-exists within other systems that must properly function with a larger system called the organization | organism. You cannot just fix the immune system, buy it, or expect miraculous resiliency overnight. The immune system must be earned, strengthened and maintained every day. You need healthy habits, positive attitude and healthy living and work environments, proper planning and long-term vision and dedication, so forth. Risk management works the same way. Risk management also has the same challenges as our immune system: we don’t think much about it until something goes wrong.

Immune system
Immune system

Read Post

Business continuity and the Sony data breach

A massive data breach at Sony Pictures Entertainment, which experts believe was targeted by North Korea as retaliation for a film depicting the assassination of its leader Kim Jong Un, has led to an international incident that has gained the attention of business continuity professionals. Even large companies like Sony can sometimes put business continuity planning on the back burner.  BC professionals say that attacks like this can sometimes change their minds.

Read Post

Seven insights from superstorm Sandy: a financial sector retrospective

$18 billion dollars. That’s the number estimated in damages caused by Hurricane Sandy just in the state of New York alone. With the unexpected turns that transpired amidst the super storm, all businesses were reminded of the importance of business resiliency.

Given the vast amount of information presented to-date, it is still very important that the financial sector revisit the surprises from Sandy to ensure that critical financial services are better protected. A team of experienced BCM advisors gathered the recommendations in the accompanying table from industry thought leaders in leading global financial services companies to learn from their perspectives.

Read Post

Carnival Cruise Lines: What they should have done

At first glance, it appears that Carnival Cruise lines was well prepared when one of their ship had an engine fire and subsequently lost power last week. The media, however, tells a different story.  Here are three points that Carnival may have overlooked in their crisis response.

carnival
Carnival cruise

 

Read Post

How Oreo style the spotlight during the Super Bowl, and other lessons for scenario planning

The highest rated Super Bowl in history may go down in the books for the 34-minute power outage that upstaged the million dollar ads. With all the chatter about the blackout, advertisers were concerned about the effect on television ratings, while some brands capitalized on the opportunity to own the conversation through social media. Many are claiming the real winner of Sunday’s game to be Oreo, whose clever blackout tweet got retweeted 10,000 times in less than an hour.

oreo

When it comes to planning, the power outage also demonstrated that organizations must consider not just critical processes and recovery time objectives, but should also anticipate the impact of potential scenarios. Business continuity is about bouncing back, as well as taking advantage of the situations that may present themselves during incidents—particularly in this case, high profile events. Have you considered this when doing business continuity scenarios or exercises?

Read Post

What a crisis requires, beyond a barebones plan

The fact that Tokyo found the nuclear reactors in a worse state than previously announced underscores the need for honest, factual information for public consumption, and the importance of media in delivering this communication. The age where authorities view the public as a panicky wildcard that needs to be soothed, rather than as an equal partner in mitigating and recovering from a disaster, must come to an end – especially in a world where, thanks to the internet and information networks, information is disseminated to a wider audience at a faster rate than history has ever experienced before.

Was the community immediately surrounding Tepco’s reactor integrated in mitigation efforts prior to the incident? Subsequent actions and the announcement of possibly 30 billion dollars in claims indicate the opposite.

Read Post