Improving Operational Resilience by Enabling Resilience Leaders
Synopsis
This paper looks at operational resilience from the perspective of resilience leaders, the people ultimately tasked with shaping and maintaining resilient organisations.
As we shall see, delivering on this mandate is a challenging task and, here we seek to understand and address those challenges.
This will help resilience leaders to achieve their objectives and feed through into improved organisational performance.
1. Resilience for our times
Events of the last 5 years have severely tested the resilience of businesses and public administrations. The Covid 19 pandemic, extreme weather events, geopolitical tensions and cybersecurity attacks have caused catastrophic human impact and USD Trillions of economic damage.
Figure 1 summarises the impacts, short-term responses and longer-term strategic responses that are now being taken in response to events that have tested resilience almost to breaking point.
The impacts of these recent events is still ongoing, most noticeably in degraded public services and economic malaise and there appears to be a significant possibility of similar disruptions in the near future.
Figure 1: Recent events that have tested the resilience of businesses and public administrations
| Resilience – stress events (2019 – 2024) | Impact | Short-Term Response | Longer-Term Strategic Response |
|---|---|---|---|
| COVID-19 Pandemic (2019-2020) USD Trillions |
|
|
|
| Cybersecurity Attacks (Ongoing) USD Hundreds of Billions |
|
|
|
| Climate Change and Extreme Weather Events (Ongoing) USD Trillions |
|
|
|
| Geopolitical Tensions and Trade Wars (Ongoing) USD Trillions |
|
|
|
While Figure 1 summarises global events, every organisation faces additional risks that are specific to that organisation, its sector or region and which could disrupt its operations and jeopardise achievement of objectives.
Risk, by definition is uncertain and it is impossible to avoid most risks - meaning that organisations must instead focus on maintaining resilience to potentially disruptive events.
'Resilience' is a word of our times with Control Risks' Global Resilience Report finding that 97% of organizations were conscious of the word 'resilience' (up from 70% in 2020).
2. What is resilience?
ISO standard 22316:2017 defines organisational resilience as "the ability of an organisation to absorb and adapt in a constantly changing environment to meet its objectives and prosper."
Key elements of the ISO definition of resilience include:
- Ability to absorb and adapt: Organisations must be able to withstand disruptions and adjust their operations to changing circumstances.
- Meeting objectives: Resilience is not just about surviving but also thriving and achieving organisational goals.
- Prospering: Resilient organisations are able to capitalise on opportunities and improve their performance over time.
The definition emphasises the importance of proactive planning, preparedness, and adaptability in ensuring organisational resilience.
3. The role of resilience leaders
While accountability for organisational resilience lies with the Board as part of its governance remit, responsibility is usually passed to a Head of Resilience or other resilience leader.
The objectives, key tasks and challenges faced by resilience leaders will vary depending on individual, regional and sectoral circumstances. The following sub-sections illustrate example objectives for resilience leaders.
3.1 Enhance organisational resilience to minimise disruptions
Objectives:
- Protect revenue streams: Ensure that the organisation can continue to generate revenue during and after disruptions.
- Safeguard brand reputation: Maintain the organisation's reputation in the face of challenges.
- Minimise operational downtime: Reduce the duration of disruptions and quickly restore normal operations.
Key tasks
- Maintain a comprehensive risk assessment
- Develop a resilience strategy
- Implement risk mitigation and response measures
Challenges
- Limited resources
- Resistance to change
- Lack of senior management support
3.2 Improve operational efficiency
Objectives:
- Optimise resource allocation: Ensure that resources are used effectively and efficiently in resilience planning and response.
- Enhance risk management processes: Implement continuous improvement in risk identification, assessment, and mitigation.
- Foster a culture of resilience: Create a workplace where employees are empowered to contribute to resilience efforts.
Key tasks
- Optimise resource allocation
- Streamline processes
- Foster a culture of continuous improvement
Challenges
- Data limitations
- Complexity of operations
- Siloed decision-making
3.3 Drive innovation and adaptability
Objectives:
- Promote a culture of innovation: Encourage a mindset of continuous improvement and adaptation to changing circumstances.
- Foster a learning organization: Leverage lessons from disruptions to improve future resilience.
- Capitalise on opportunities: Seek out new opportunities that may arise from disruptions.
Key tasks
- Identify emerging trends and technologies
- Foster a culture of experimentation
- Allocate resources for innovation
Challenges
- Organizational inertia
- Risk aversion
- Lack of funding for innovation
3.4 Strengthen stakeholder relationships
Objectives:
- Build trust with stakeholders: Foster strong relationships with customers, employees, investors, and other stakeholders.
- Enhance communication and transparency: Provide clear and timely information about resilience efforts and incident response.
- Manage stakeholder expectations: Set realistic expectations and address concerns proactively.
Key tasks
- Build relationships with key stakeholders
- Develop effective communication plans
- Address stakeholder concerns proactively
Challenges
- Misaligned priorities
- Communication challenges
- Differing expectations
3.5 Ensure regulatory compliance
Objectives:
- Adhere to industry standards and regulations: Comply with relevant laws and regulations related to resilience.
- Demonstrate compliance to stakeholders: Provide evidence of compliance to regulators, investors, and other stakeholders.
Key tasks
- Stay informed about relevant regulations
- Conduct regular compliance audits
- Provide compliance training
Challenges
- Changing regulations
- Complexity of compliance requirements
- Resource constraints
4. Addressing the challenges of resilience leaders
Sections 3.1 – 3.5 describe some of the challenges faced by resilience leaders. In Acuity's experience, these are common with those of other risk and assurance leaders, including Chief Information Security Officers (CISO), Enterprise Risk Managers and Heads of Compliance.
At the top level, problems stem from the nature of risk and assurance roles – they require difficult judgements on where and how much to invest to mitigate risks that are difficult to assess and may never occur. And all the while that risks don't materialise; resilience can be viewed by the business as an overhead putting a drag on performance rather than enabling it.
This can, at times result in the resilience leaders being marginalised by senior colleagues, further limiting their ability to perform their difficult roles.
It takes an enlightened and strong Board sponsor to back resilience leaders and a confident, charismatic and well-prepared resilience leader to deliver against their objectives and retain the confidence of the Board.
The challenges for resilience leaders in achieving their objectives, and therefore the areas in which they should focus attention fall into six categories:
- Data and Decision making. Insufficient or inaccurate data
- Change management. Continual change, e.g. to regulations and new threats
- Resource management. Insufficient or unproductive budget, skills or personnel
- Communication. Difficulty in communicating effectively with stakeholders
- Preparedness. Being unprepared and unable to respond effectively to unexpected events
- Culture & Behavior. Lack of support from the Board or other stakeholders.
These are described individually below, cross-referred to the resilience objectives that they support, together with requirements for automation.
4.1 Data and decision-making
Resilience leaders need to be able to answer the broad questions:
- Where are we exposed to disruptions that could cause a material impact on business goals – is it in certain products or services, regions, suppliers, technologies etc.?
- To what extent are we resilient to those disruptions?
- Do we have assurance through review, audit, testing etc.?
- What improvement programs and actions are required or underway?
Data is key to being informed, making the right decisions on resilience and building the business case for investments. Gaining visibility of the required data and how it correlates across a large and complex organisation is a significant challenge.
For example, answering the above questions requires up-to-date visibility and understanding of:
- The products and services most responsible for delivering business goals, linked to
- critical enabling processes and inter-dependencies, linked to
- minimum viable performance metrics, and
- minimum infrastructure, services, suppliers and human resources
- Existing and potential threats that could cause material disruption to critical products, services and processes, linked to
- vulnerabilities, such as single points of failure or over-dependence on suppliers, and
- mitigations that enable resilience or recovery of critical products, services and processes, and
- assessment of the current implementation status and effectiveness of the mitigations
- Taking account of all of the above, an assessment of the risk of material disruption to critical products, services and processes, linked to
- decisions on whether the risk can be accepted, and if not
- the actions and investment in mitigations required to reduce the risk to an acceptable level
- a set of priorities for testing and audit
- Incident management, crisis management and business continuity plans to guide responses in the event that threats materialize, linked to
- results of assurance reviews, audits and tests, linked to
- actions and investment required to address findings
- Incidents or near misses that have occurred with an assessment of whether threats, vulnerabilities, mitigations, risk acceptance decisions and plans need to be updated, linked to
- actions to implement the decisions
- Assessments of compliance with regulations, linked to
- actions to address non-compliance.
This, inexhaustive list illustrates the potential complexity of capturing, maintaining and cross-relating the data required to enable resilience leaders to make informed decisions and achieve their objectives.
Resilience leaders should develop a 'resilience data model' which maps resilience data and provides appropriate controlled access to authorised users.
A further challenge will be to maintain the data model as changes occur, which is the subject of section 4.2.
Objectives supported
The data model underpins achievement of all objectives:
- Enhance organisational resilience to minimise disruptions
- Improve operational efficiency
- Drive innovation and adaptability
- Strengthen stakeholder relationships
- Ensure regulatory compliance
Automation requirements
A set of integrated capabilities is required
- Data model providing data visibility and sharing
- Threat, vulnerability and risk assessment
- Supply chain risk management
- Compliance management
- Crisis management and business continuity planning
- Process automation
- Review and audit planning
- Collaboration
- Reporting
4.2 Change management
The modern organisation is defined by change and its ability to respond to change. Products, services, processes and structures, including digital services and technology, supply chains, threats, vulnerabilities, risks and regulations change - all the time.
Unless resilience leaders have sight of changes and act upon them, the data model will rapidly become out of date and leaders will lose the insights necessary for them to achieve objectives. For example, changes in digital infrastructure or the supply chain that introduce new vulnerabilities.
Resilience leaders should implement processes to capture change and ensure that their data model and associated automation is designed to update automatically in real-time and alert the resilience team to significant implications of change.
Change management is as fundamental to achieving objectives as the data model itself.
Objectives supported
- Enhance organisational resilience to minimise disruptions
- Improve operational efficiency
- Drive innovation and adaptability
- Strengthen stakeholder relationships
- Ensure regulatory compliance
Automation requirements
- Integrations with systems that can notify or initiate change, e.g. threat horizon scanning, technology change systems, supplier databases
- Real-time data model updating and alerting
7. How can Acuity help?
Acuity Risk Management provides a single, holistic GRC platform (STREAM®) with related services to enable organisations to improve performance and achieve their resilience and other risk and assurance objectives.
STREAM® is unique in that it provides full risk and assurance functionality, including all of the capabilities listed in section 5, yet is ultra–configurable and extendable via the user interface to address our customer's specific objectives and requirements within days to just a few weeks.
Our implementation and configuration services provide fast customisation, integration, deployment and onboarding so you can see immediate value and performance improvements.
To discuss how Acuity can improve the performance of your resilience team and enable resilience leaders to achieve their objectives please contact us.