Showing posts with label Operational. Show all posts
Showing posts with label Operational. Show all posts

Tuesday, March 20, 2012

PwC report identifies a ‘fundamental shift in risk management’

Economic turmoil, political upheavals and natural disasters, all combined with advancing globalization and rapid technology progress, are creating a new era of risk for businesses and causing a fundamental shift in risk management practices, according to a new PwC US 2012 annual report.

Entitled ‘Risk in Review’ the report is based on a survey of more than 1,000 executives and risk management leaders.

"2011 marked a year of reckoning, and many companies are still struggling to create an effective approach to managing the ever-widening risk landscape. Businesses are scrambling to fix weak links in their systems stemming from non-traditional risks such as social media and digital technology, to dealing with the realities of operating in today's global marketplace," said Dean Simone, leader of PwC's US Risk Assurance practice.

"In this new risk era, corporate boards and senior management have a crucial role to play to ensure they set the right culture and align their strategy to risk imperatives."

According to the report, forward-looking companies are responding by shifting their risk management focus in several fundamental ways: from internal to external, from operational to strategic and from bottom-up to top-down.

To better prepare themselves to deal with unexpected events for the upcoming year and beyond, companies installed new risk management organizational structures, have put in place a new breed of risk management leadership and have adopted innovative techniques such as scenario analysis and predictive indicators.

To address changing risk landscape, PwC recommends the following risk management approaches for 2012:

Increasing cross-communication: Place greater emphasis on communications and data sharing in 2012 and take steps to improve cross-functional and departmental communication.

Improving data quality and reporting: Enhance global economic teams to help improve data quality and put in place improved processes for reporting data. Different business units should meet periodically with different business units to review and exchange information and data as a form of early alert to possible upcoming risks to the business.

Better forecasting and scenario analysis: Leverage more sophisticated tools such as early-warning systems and contingency plans to reconfigure approaches to manage risk (i.e. set up scenario models or Monte Carlo analysis geared to the nuances of the business, run models as events unfold, etc.)

Elevating the chief risk officer (CRO): Put risk management role on the proactive offensive instead of reactive defense by giving CROs more cross-functional access and ability to effect decision-making.

Integrating risk management: Manage risk holistically by continuing to integrate risk management into decision-making processes relating to ‘traditional’ functions (i.e. strategic planning). Don't exclude new areas of risk (i.e. talent management and outsourcing), but address and integrate them into decision-making processes.

Bolstering IT: Address data privacy and security concerns and take stock of where to build better processes, practices, procedures and technical defenses. Shifting technology and heightened competition for new customers in new markets are also exposed to more risks, so it's imperative to study the setbacks and successes of peers who pioneered the use of these new technologies.

Greater board involvement: Understand the risks facing a company and have in-depth discussions with management to make sure those risks are being handled properly. The discussion should also cover potential risks that are not yet on management's radar and what the implications of those emerging risks might be.

To download a full copy of the report visit: http://www.pwc.com/riskinreview

Wednesday, August 11, 2010

Increased worker flexibility not always a good thing

Companies trying to improve efficiency by building more flexibility into their workforce could end up with the company running too lean and drive operational costs up, says a new paper co-published by the University of Toronto’s Rotman School of Management.

“Flexibility is good, but too much of it is dangerous,” says Oded Berman, who holds the Sydney C. Cooper Chair in Business and Technology and is a professor of operations management at the Rotman School.

Workforce flexibility is supposed to improve the match between an organisation’s labour resources and the work required. Using a theoretical staffing model under different demand conditions, the study examined the impact of several forms of worker flexibility, including workers with a multiple skill-set (skill mix), variable start times, part-timers and workers switching from one job to another within a shift.

While most forms of flexibility helped reduced costs under normal demand, the study found higher levels of flexibility meant that insufficient staff levels were in place, to respond to unexpected demands, leading to higher inventory costs.

Variable start times created the most robust flexibility, while part-time workers and job-switching within a shift were definitely not as robust.

“The rule of thumb we’ve suggested is, have flexibility and use it wisely, but set your workforce size and service levels, assuming you don’t have it,” says Prof. Pinker.

Comment
The suggestion is that workforce 'flexibility' models do not operate at an optimum level when tested or put to practical use. This may be because of the immaturity of the process or system used or the motivation of the personnel involved.

The complete study is available at: www.rotman.utoronto.ca/newthinking/flexibility.pdf

Sunday, January 18, 2009

Project failure starts at the begining

We are all familiar with countries, towns and destinations that are difficult to reach, either by road, rail or public transport and yet people exist there and thrive. It is not in another dimension or another planet, where predictable 'difficulties' are numerous e.g. expensive ad hoc rocket ship service, an atmosphere of sulphuric acid, temperature variations in the region of 'scorchingly off-the-scale', etc. No, our difficulties in reaching our earthly destinations are because we do not start from the correct location.

This is a lesson I learned when lost in Dublin and forced to ask for directions. It was made clear to me that to get to point B I should have started at point A and not the point that I was currently at, which was currently unknown and would henceforth be referred to as X. Thus, making the logic more mathematically predictive.

The start point and the end point, part of the defining structure of a project and thus lifting it away from the realms of a simple action or activity, are critical in the initiation and definition of the project and the associated project plan. You will never reach the end destination if the start is left to serendipitous happenstances.

  • Plan the beginning of your project meticulously
  • Involve as many of the stakeholders as possible
  • Hold a workshop with all the allocated resources
  • Seek out Subject Matter Experts (SMEs)
  • Do your research, technical, business, historical, etc
  • Assess the Risks (qualitative and quantitative) and
  • Look where you are going

The dark matter of Projects failing

IT projects suffer from a similar force to that of the astronomically evasive 'dark matter'. A force that is not so much negative in its manifestation as it is in its effect, especially on other matter. It has an ability to occupy space without contributing anything, interacting with 'light matter' only to drain its energy and restrict its ability to move freely.

'Dark matter', and its ability to absorb and retain energy without contribution, is a universal anomaly for physicists. A puzzle yet to be solved. A question unanswered but not for project managers and team leaders. We know this effect and understand the consequences very well. It is a similar force to the one that will cause your project to fail. It is your greatest adversary. Its invisible. It can be detected but not controlled, without the right tools and level of experience.

Corporate Defense Domain

The Corporate Defense Domain is a convenient way of describing the sum total of numerous secure approaches, tools, processes, etc. that incorporates the entire environment security of an organisation, from end to end or perimeter to perimeter.

The concept of Corporate Defensive Domain is an aid to perception evolving from a vision of Physical Risk through IT Risk, Operational Risk to Governance, Compliance, Legal and Reputation Risks.

Corporate defense
Corporate security is purely defensive. There is no moral imperative that allows positive attacking action against threats and those that attempt to, or unequivocally, inflict damage on your organisation. Some but not all, of these attacks can be very determined and sophisticated because they are goverment funded and are either commercially or politically motivated. Most are just motivated individuals that can be classed as intellectual vandals.

As with all the good guys, you must work within the framework of the law and this only allows vigilance, defensive action, and possibly post-event retribution and compensation. The subsequent capture and imprisonment of a perpetrator may become a public spectacle. An apparent show of the success of your strategy and hopefully it will act as an example to others but in reality it is of limited effect and brings little solace to the organisation.

Showing your hand
There is also a view that public trials act as a learning curve for other attackers. The attacker creates an action on your perimeter and you display a measured reaction. Thus revealing some of your defensive strategy, processes and tools.

Security realms
There are many realms that exist in the land of security e.g. physical, electronic, virtual, etc. and there are many ways to look at and examine security. It can be viewed as a) a physical obstacle b) a process inflicted on reluctant personnel without explanation or c) an acceptable mindset that is instilled in the environment with the full involvement of the personnel. This latter approach should produce the best results, giving staff a sense of involvement, empathy and a real feeling for the potential consequences.

Secure personnel
It is critically important that your staff buy into securing the corporate domain because they are typically, the weakest link in the security of organisations.

Staff issues
  • They are not so easily or reliably programmed,
  • They don't always retain or apply knowledge appropriately,
  • They are swayed and diverted by social engineering techniques,
  • They have good and bad days,
  • Their attention is inconsistent, etc.
  • Their human!
Threats & Vulnerabilities
There are many ways to examine Threats and Vulnerabilities in an organisation e.g. by geographical location, business type, resources used, historical or political instability, etc. Do you know and understand what criteria and imperatives are being used to drive changes in your defenses? Are they appropriate, operationally maintainable or cost effective.

Analyse the Risk

Organisations are are driven to respond to threats and are compelled to adopt more and more complex defense strategies to address and defend their security needs. Security policies and strategies dictate that a full gambit of approaches should be adopted, from standard process implementation to strict and intricate application frameworks but this has an operational and business cost implication.

The questions that are not always being asked are;
  • What is the real cost of defending your business?
  • How much are you likely to lose?
  • Where will the danger come from and in what form?
  • How will it impact us?
  • What is our response capability?
  • What is the overall Risk profile?
Feal the fear and hold your ground
With the constant threat of intrusion and compromise, regular and detailed testing and re-examination of all your defenses are necessary but before you can realistically and effectively apply what you have learned, you need to conduct a detailed analysis and assessment of the Risks, the potential business impact and your response options .

7 Points to build stronger, more secure Corporate Defenses
  • Create executive level authority and responsibility for Corporate Defense, policy and implementation
  • Assess your strengths and weaknesses using mature Risk management methodology
  • Examine the interdependencies between your tools, processes and defensive positions. Strengthen the perimeters and communications
  • Map and review your Corporate Defense Domain strategy, continuously, in a structured and determined manner.
  • Determine, test and examine areas of Convergence, for overlap and gaps. Establish strong boundary defenses and stringent hand-over criteria
  • Develop a single hardened core entity, an authoritative cross functional discipline, incorporating Governance, Compliance and Risk
  • Lock the perimeter gatesways, give the spare keys to your organisation to the central hardened core and prepare yourself for the next attack