Showing posts with label Risks. Show all posts
Showing posts with label Risks. Show all posts

Wednesday, August 17, 2011

Four steps to identifying and managing project risks

Some IT consultants overlook risk identification and management, especially on small engagements. Brad Egeland says this oversight could cost you future business.

I’ve run some projects as an internal PM and others as a consultant brought in to either lead a team or perform the work myself.

The way you run engagements will differ somewhat based on your incoming status (employee vs. consultant) and the size of the effort (long-term software implementation vs. short-term consulting gig to implement new processes).

There can also be differences in how you put together the upfront formal planning documents, and the way you formalize and document requirements.

One variable that remains constant regardless of whether you’re an internal or an external project lead is the task of risk identification and risk management. I’ll address the topic of risk below from a consultant’s perspective.

Step one: Identify risks

You’re coming in cold and don’t know the potential risks of the organizational infrastructure, procedures, and personnel. Be careful not to make assumptions before you have all of the facts; otherwise, you can wind up adding more risk.

Even if it’s a one-on-one engagement with the CIO or project sponsor, it’s critical that you run through a risk identification process during a detailed risk planning session.

(The CIO is your best source of initial information.) The onus is on you to ask good questions, because you’re the expert on consulting engagements and can warn the client about the common pitfalls they might encounter. You’re coming in cold and don’t know the potential risks of the organizational infrastructure, procedures, and personnel.

Be careful not to make assumptions before you have all of the facts; otherwise, you can wind up adding more risk.

Step two: Talk to SMEs and users

The next step is to meet with subject matter experts and end users (if these are different people) and any other personnel who will interact with the solution to a significant degree. These individuals can be good resources when you’re trying to identify potential risks.

Step three: Devise risk strategies

You need to work with the project sponsor, the SMEs, and users to determine and document the best strategy to mitigate or even avoid these risks if they arise.

Even if you can’t formulate a detailed risk response to each item, it will still be helpful to identify a strategy to keep in mind as you continue to track these risks.

Step four: Manage risk and provide regular status updates

I’m a proponent of managing consulting engagements on an ongoing basis like you would on a formal long-term project.

I encourage you to conduct weekly status meetings with the client, during which you should provide a revised task schedule and status report. Your risk list should be part of every weekly status report during.

Conclusion

We may not always conduct smaller consulting engagements with the same formality as we would $2 million dollar projects for Fortune 500 companies, but the need to identify and manage risks is still there.

It’s worth the time and effort because mitigating even one risk could mean the difference between success and failure and might land you future business with the client.

Wednesday, August 10, 2011

‪Delivery Exalogic - Qualogy, The Netherlands‬‏ - YouTube



Some excellent lessons to be learned about how to install a new server into a modern building. The task was accomplished with the usual lack of concern for high risk points and health & safety by the Dutch team. Does fortune favour the brave or is Lady Luck a fickle mistress?

Well done to the team in accomplishing this task and continued success through good Project and Risk management practices for the future, and less reliance on luck.

Saturday, November 28, 2009

EU Security Agency Highlights Cloud Computing Risks

Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).
Comments By Mikael Ricknäs

Fri, November 20, 2009 — IDG News Service — Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

The agency highlighted those problems as having the most serious consequences and being among the most likely for companies using cloud computing services, according to ENISA.

ENISA examined the assets that companies put at risk when they turn to cloud computing, including customer data and their own reputation; the vulnerabilities that exist in cloud computing systems; the risks to which those vulnerabilities expose businesses, and the probabilities that those risks will occur.

When moving to cloud-based computing services, companies have to hand over control to the cloud provider on a number of issues, which may affect security negatively. For example, the provider's terms of use may not allow port scans, vulnerability assessment and penetration testing. At the same time, service level agreements (SLAs) may not include those services. The result is a gap in defenses, ENISA said in the report.

Compliance could also prove to be a big problem if the provider can't offer the right levels of certification or the certification scheme hasn't been adapted for cloud services, the report said.

One of the advantages of cloud services is that data can be stored in multiple locations, which could save the day in the event of an incident in one of the data centers. However, it could also be a big risk if the data centers are located in countries with a shaky legal system, according to the report.

Other areas of concern are vendor lock-in, failure of mechanisms separating different companies, management interfaces that get accessed by hackers, data not deleted properly and malicious insiders.

To minimize these risks the report proposes a list of questions that a company needs to ask potential cloud providers. For example, what guarantees does the provider offer that customer resources are fully isolated, what security education program does it run for staff, what measures are taken to ensure third-party service levels are met, and so on.

In the end a good contract can lessen the risks, according to the report. Companies should especially pay attention to their rights and obligations related to data transfers, access to data by law enforcement and notifications of breaches in security, it said.

ENISA's report isn't all doom and gloom, though. Using cloud computing services can result in more robust, scalable and cost-effective defenses against certain kinds of attack, according to the report. For example, the ability to dynamically allocate resources could provide better protection against DDoS (distributed denial-of-service) attacks, ENISA said.

Friday, September 4, 2009

Managing an Aging Workforce: How to Fight the Risks

The workforce is aging fast, and stakeholders — companies, governments, and others — have a narrow window of time to adapt.

So says the World Economic Forum, which Wednesday issued an 80-page report outlining strategic options to address how stakeholders can strengthen financial sustainability, quality of retirement, and health-care provisioning in a rapidly aging world.

The report emphasizes that companies and governments must work cooperatively for meaningful action to occur — a dubious scenario in today's light, with the two sides rarely in agreement on how health care and retirement should be paid for. For CFOs, however, the concern is whether retirement and health-care funding should be a priority right now.

After all, despite a tone of urgency in the report, it discusses demographic changes in terms of decades, not years. For example, it includes a chart showing that the percentage of gross domestic product devoted to retirement and health care will grow from 7% to 13% — between 2000 and 2050.

Indeed, even John Betts — a partner at consulting firm Mercer, a WEF member that helped create the document — concedes to CFO.com that any corporate actions to address the aging workforce won't necessarily bear fruit for some time. "There is an issue about hard-nosed CFOs saying, 'How's it going to affect my profits next year?'" he says. "Probably the answer at the moment is that, well, it won't."

That's the kind of attitude that must undergo a fundamental shift, the report argues — and not only because of the specter of runaway costs. Just as important, the WEF says, is an opportunity to counter the dour fact that many people will have to work later into life as retirement grows less financially attainable. The challenge will be to turn that reality into something very positive for the bottom line. "There is potential to create a 'new age of age,' in which growing old is no longer synonymous with declining health, [but rather] experience is valued as much as youth, the 'silver economy' is vibrant, and the 'wellderly' are active and valued in society."

That's an ambitious goal. But the report, which was two years in the making, has plenty of suggestions for how stakeholder can help facilitate the paradigm shift.

Be Well
Employers, for example, should put less focus on approaching health care tactically with programs that address health issues as they arise, and begin thinking strategically by promoting healthy behaviors. For example, they should provide practical incentives for employees to engage in physical activity, subsidize healthy eating options in workplace dining facilities and vending machines, and ensure that working practices and environments are conducive to long-term health.

Many employers, of course, have taken steps in those directions, although the report clearly implies that more should be done.

In any case, employers want to know what kind of return such investments will produce. In a Web conference yesterday, Mercer partner Christine Owen claimed that on average, wellness initiatives will produce an eventual return of at least three or four to one; that is, $3 to $4 worth of increased productivity and reduced health-care costs for each dollar spent. The return is even greater in emerging countries, where less-cynical employees with limited access to health care may be more willing to participate in wellness programs, she added.

Owen did not detail how that calculation was made. But she painted a grim picture of a future in which the health issues applicable to an older workforce have been dealt with inadequately. "Failure to address this issue sooner rather than later may mean that the gap [between health-care needs and provisions] becomes just too big to bridge," she said. "That could have as big an impact on the economy as the current economic crisis — and I can predict for certain that it will last a good deal longer."

Employers also can improve health care by supporting pay-for-performance programs for health-care providers and building quality measurement into health-plan contracts. They could even investigate the feasibility of extending coverage to include offshore providers, taking into account the risks of legal liability and employee attitudes, the WEF report says.

Into the Sunset
Companies also should step up their efforts on financial education and retirement-planning advice for workers, the report says. They should provide more and better education programs, targeted communications that take into account an individual employee's level of financial literacy, and access to cost-effective planning advice by selecting advisers or subsidizing the cost.

But while it's easy to understand how changing health-care behaviors could hit the bottom line, it's less clear how improved retirement planning would affect corporate performance. Traditionally a good pension plan was a key recruiting tool, but that purpose "is less compelling now than it was," says Betts.

That's because as the number of defined-benefit plans shrinks and existing ones increasingly become unavailable to new employees, younger workers' expectations have changed, he notes. They're more likely to be satisfied with a defined-contribution plan in which the employer merely matches some portion of their own contributions. That makes using pension plans to recruit new talent more difficult.

But Betts predicts that a new trend, in which a few countries have mandated minimum levels of employer retirement provisions, will spread. "Our feeling is that with the aging trend, you're going to see governments moving more into that mode," he says.

That should provide companies with a new incentive to make sure their investments in retirement programs are not wasted. "Calculations show that the outcome of a pension to an employee compared to the money put in can vary by a factor of at least two, depending on how it's been managed," says Betts. "Companies won't want to be hit with the issue of people saying, 'You gave me this pension and now I can't afford to retire.'"

To that end, companies should introduce automatic enrollment programs with higher default contribution rates and automatic increases with age, the WEF report says. It also suggests that companies provide more information to employees nearing retirement on reverse mortgages, which allow them to draw down the equity in their home without selling the real estate.

The report also offers ideas for how pension sponsors can improve their plans' performance. These include introducing target-date funds and appointing professional trustees to plan boards. And they should encourage fiduciaries to investigate the longevity-hedging products currently available for employer-sponsored plans, and facilitate the purchase of annuities by retiring employees.