Showing posts with label COOP. Show all posts
Showing posts with label COOP. Show all posts

Monday, August 30, 2021

Enterprise Risk Management, Business Continuity, COOP

The person you called
Is on vacation
No one can help you

I SEEM TO BE GETTING A LOT of “Sorry, the only person who can help you/answer the question is (pick one) on vacation, out of the office, in a meeting. Call back when the person returns and can take your call.”

I get this from banks.

I get this from health care organizations.

I even get this from hospitals.

 

IT SEEMS TO MY EDWARD BEAR mind that if a position is critical sufficient to staff it, it should be considered critical enough to have someone trained to “fill in” if the person normally in the position is absent.

This is especially true if the position is “client facing.”

Except for (U.S.) presidents and their vice presidents, most executives are smart enough to have someone able to fill in when they are unavailable.

    Presidents, at least up through FDR’s reign, made a point to keep their vice presidents in the dark as much as possible.

Perhaps it is lack of confidence in themselves that keeps some critical personnel from training a stand-in.

Perhaps the critical person feels he or she is invincible; that they will live forever.

Fred Rose and Hank Williams were on the mark when they wrote "I'll Never Get Out of This World Alive" https://tinyurl.com/mzjj6kz9

Even sans the Grim Reaper at the door, people are absent. People go on vacations. They tend to others. They are promoted. They are transferred.

”Things” happen. ”Things” change.

Admittedly, not everyone is able or ready to “step into another’s shoes.”

But, I suspect, with encouragement and training, most people can be confident that they can fill in for another “in a pinch.”

Besides, it seems to me it is just good business sense to have someone who can step in as needed.

I once worked for a PBX manufacturer. The company moved across town and the new switchboard was temporally unattended.

Having once used a plug board (think Lily Tomlin (right) as Ernestine the Telephone Operator) I rashly manned the switchboard (console). Not my job, but I wrote the operator’s manual so I figured I could “get by.” I did (but was relieved to be relieved).

Granted, my stint on the switchboard was not planned, but I was capable.

If anyone thinks a receptionist job is less important than, say, a general manager, let them call into a business when the receptionist is on a break.

One ringy dingy, two ringy-dangies . . .

The responsibilities are different, but I suggest that the receptionist’s job is at least as important to the organization’s success as the GM’s.

Filling in for an absent coworker is not something normally to be “thrust” upon a person.

In other words, it is something that should be planned and implemented in stages, before the task needs to be performed.

Likewise, several people can — perhaps should — be trained to “assume the position” when it become necessary.

In the military, they call it “cross-training,” being able to function in another job.

Perhaps, as with this scrivener, not as well as the regular receptionists answering calls, but “good enough” to keep from losing a customer for lack of a response.

C-levels who are afraid to train someone to confidently fill in for a brief period need to be replaced; they are a detriment to the organization.

As an Enterprise Risk Management practitioner, I know I’m right.

I also know that people who fear for their jobs are people who ignore my warnings and admonishments.

 


 

 

 

PLAGIARISM is the act of appropriating the literary composition of another, or parts or passages of his writings, or the ideas or language of the same, and passing them off as the product of one’s own mind.

Truth is an absolute defense to defamation. Defamation is a false statement of fact. If the statement was accurate, then by definition it wasn’t defamatory.

Web sites (URLs) beginning https://tinyurl.com/ are generated by the free Tiny URL utility and reduce lengthy URLs to manageable size.

 

 

 

 

Comment on Out of office

Sunday, May 27, 2018

Risk Management, Business Continuity, COOP

Why reluctance
To create
New password?

I HAVE A NUMBER OF PASSWORDS, A/K/A PASS CODES.

I change them at least monthly; some after they are used three times (or once a month, whichever comes first).

I once worked for a defense contractor that insisted on new passwords every 90 days; I thought that was 60 days too much. (The employer refused to implement enterprise risk management practices; I was almost fired for suggesting it.)

Some security people recommend having an easy to remember password, such as a phrase. It might be easy to remember something similar to “The quick brown fox jumps over the lazy dog" but that presents several problems.

First, many organizations, including (unfortunately) some financial institutions, limit passwords to 14 characters. “The quick brown fox...” exceeds that limit.

Second, many organizations insist that the password includes CAPITALS, lowercase, and digits (0-9). This seems to be a fairly common practice.

Third, some organizations demand that the password contain a “special character” such as #, &, !, @

There are lists of password options NOT to use: names of relatives and pet, zip codes and phone numbers, dates of birth are a few discouraged passwords.

PC Tools “Password Utilities” has been creating passwords for me for many years.

There are other password generators for various platforms (Windows, Linux, Mac, Unix). I found “Password Utilities” years ago and it still does the job, simply and quickly. Moreover, it is free.

It is challenging to remember a password such as FJZ%q9c9b2&=n#%aZxXsJ$9r52b2j8nf.

I don’t try.

I have a password protected file that stores my current passwords. The password for THAT file IS something I CAN easily remember. It helps that the password file has an “innocent” name and it buried under several sub-directories (folders within folders). That password ALSO is frequently changed.

Most of my accounts allow me to “cut-n-paste” my new passwords, so changing a password is nearly painless.

A few, primarily financial organizations, make me key in each character. It’s slow, but I tell myself it is for my protection. One organization not only requires that I manually key (vs. cut-n-paste) the new password, but it then insists I enter its own code, sent via phone, to activate the new password. (This company also has a really good enterprise risk management plan, one reason I like this organization.)

One advantage of a password generator is that some organizations prohibit use of the same password within “n” months.

For me, remembering to change my passwords is easy. I change passwords on the same day I do maintenance on the air handler. (One cup of white vinegar followed by two cups of very hot water into the evaporation drain, and inspect/change the air filter. Once-a-month, every month.) I have a reminder set up so I don’t forget.

I confess there are days I really do not want to change all my passwords, but it is a “must do.”

If I share my passwords with anyone (e.g., my computer guru) I change the passwords as soon as he departs.

Changing passwords does not need to be painful.


PLAGIARISM is the act of appropriating the literary composition of another, or parts or passages of his writings, or the ideas or language of the same, and passing them off as the product of one’s own mind.

Truth is an absolute defense to defamation. Defamation is a false statement of fact. If the statement was accurate, then by definition it wasn’t defamatory.

Comments on Passwords

Monday, June 22, 2015

ERM-BC-COOP:

Workers' compensation
Risk Management topic?

 

I followed a link from AdvisenFPN to an EHS article titled Affordable Care Act: Should You Treat Worker’s Comp Claims Like Crime Scenes?

At first blush, it would seem workers' comp falls outside the bailiwick of the Enterprise Risk Management practitioner.

But maybe not.

ACTUALLY WE SHOULD BE LOOKING at Workers' Compensation abuses

The EHS leed paragraph reads:

    An unintended consequence of the Affordable Care Act is that it’s making workers’ compensation a more-attractive option for employees who are injured while off the job.

The article , by David R. Leng (CPCU, CIC, CBWA, CRM, CWCA), continues on the EHS website - and others, see End of File (EOF):

    Workers’ compensation fraud has been around, one way or another, since the first slacker hurled a spear at a woolly mammoth and then complained to the tribe leader he couldn’t go out on the next hunt because he hurt his back, when in reality he just wanted to hang around the cave, painting on the walls.

    A “free” vacation long has been a motivation of workers’ compensation fraud, as is monetary rewards. But the Affordable Care Act (a.k.a. ACA, a.k.a. Obamacare) has dumped millions of additional bodies into the healthcare system, putting a significant strain on everyone’s budget.

As usual, the "bottom line" is how much someone - employee or employer - will have to pay, or, to put it another way, how much will the medical providers be able to charge?

Author Leng suggests that even though Obamacare may seem to be "cheap" coverage, the frequently high deductibles prevent many people from using the no longer affordable coverage. The fall-back is to claim the malady is work-related so the employer has to foot the bill.

Medicos also more inclined to welcome workers' comp claims since their payment is higher than under Obamacare.

The article goes on to list seven (7) ways that can be used to determine if the injury-causing incident actually happened on the job or was "brought to work" by the injured employee.

So what are the threats the Risk Management practitioner needs to consider?

    Increased workers' comp costs

    Lost productivity

    Visits from federal or state OHSA and similar organizations

It may not seem like a major issue compared to, say, an earthquake, but consider increased workers' comp costs and lost productivity in the same vein as a trickle of water over the years on limestone. It takes its toll.

 

EOF:

Yellow Factory
Workers' Compensation Institute


Tuesday, May 5, 2015

ERM-BC-COOP:

PwC (finally?) realizes
Vendors are a real risk

 

MY FAVORITE SOURCE of links to risk articles, Advisen FPN, pointed me to a PwC puff piece (it came via PR Newswire) titled Growing Use of Vendors Intensifies Risk of Business Interruption, According to PwC US.

PwC, a/k/a PricewaterhouseCoopers LLP, tells us that

    As businesses increasingly rely on external parties for critical services, they become more vulnerable to business interruptions. This is especially true when such businesses know little about their third party vendors' resiliency and recovery capabilities, according to a new PwC US whitepaper, which examines the effects that vendor resiliency, or lack thereof, can have on an organization's business continuity strategy. Titled, Business continuity beyond company walls: When a crisis hits, will your vendors' resiliency match your own?, the PwC report also notes that risk becomes greater when the organization has a limited understanding of its own business interruption threats, resiliency status and recovery capabilities and strategies.

I wonder if, coming from PwC, that basic information experienced risk management practitioners have been preaching for years - decades - will have some impact.

According to PwC's report,

    (R)eliance on third parties is gaining momentum, and if companies lack insight into their critical vendors' resiliency and recovery capabilities, they run the risk of their own strategic goals being derailed. "Our clients are adjusting to the shift in global economic power and demographic shifts – two of the megatrends we identified – by increasing their use of strategic vendors to accelerate their global growth strategy and decrease time-to-market for their products and services. Along with the increase in strategic vendor reliance comes the need to more formally monitor vendor and other third party risks," said Brian Schwartz, PwC US Risk Assurance, Governance, Risk and Compliance leader.

    In order to protect against business interruption risks, companies should institute a business continuity management program that encompasses vendor risk by incorporating increased resiliency and rapid recovery. PwC outlines five steps to help companies look beyond their own walls and examine interruption risk among the vendors who provide support.

While I would suggest that "reliance on third parties" is not gaining momentum, it is a fact of life for almost every organization; I cannot think of any that survives sans vendors. No man is an island, nor is any organization.

Slowly, slowly business continuity practitioners are learning that limiting their search for risks "inside the building" is hardly sufficient. It could be compared to searching for hametz NB only in the kitchen while ignoring the dining room (and kids rooms).

Business continuity must expand to become true ENTERPRISE Risk Management considering ALL risks from ALL areas - from incoming (raw materials, orders, payments, delivery systems) to outgoing (QA/QC, advertising/PR, delivery systems, customer financial well being,), and the items mentioned here are only the tip of the proverbial iceberg. (Add to that government regulations, taxes, and fees, competition, lenders, investors, and many, many more potential "got'chas.")

Most practitioners have expanded out from behind the locked doors of IT/MIS to try to discover an organization's raison d'etre, but - unfortunately - many still are looking for risks only within the organization.

As PwC now recognizes, as "businesses increasingly rely on external parties for critical services, they become more vulnerable to business interruptions."

'Course you knew that.

 

Note 1 Hametz - leavened food prohibited to Jews during Passover


Monday, August 4, 2014

ERM-BC-COOP

Dealing with the chaos
Around the Mediterranean

 

I have been on both sides of this concern - working in a country that was nearly strangled by a strike by Custom's clerks and working for the same company elsewhere trying to convince prospective clients that we could meet their service requirements "no matter what."


Civil war in Syria.

Political conflict in Turkey.

Iran - enough said.

Ukraine and Russia.

Turmoil in on the European side.

Remnants of the "Arab Spring."

Israel and the terrorists to the south and the north.

And a few more "to be named later."

If your organization buys products or services from anywhere around the Med you can plan on interruptions of product or service.

The Internet and common carriers are not immune as nations close their borders or are quarantined.

 


Mediterranean and surrounding states

 

Assume - always a dangerous thing to do - that your organization must have a product or service from an area of contention.

Your customers are concerned that your source may be prevented from delivering a product or service they expect due to contract. It is a justifiable concern. How can your organization assure them that it has a risk management plan to protect your clients' interests?

 

Hardware Products

Assuring sufficient hardware products is (relatively) easy.

If the product is electronic, you should know the MTBF* of all critical components in the product. Given the MTBF plus the sales projection it would be relatively easy to "guesstimate" how much product and how many spares need to be warehoused in-country. If your organization is selling very large items - aircraft, ships, and other things that cannot easily be folded and shelved - finding a suitable place to warehouse the product can be a problem, but it is a surmountable problem.

 

Software Products

Products delivered by Internet - software applications, bug fixes, upgrades and the like - also are subject to delivery interruption. The Internet is a "pipe" with government "valves" that can restrict both incoming and outgoing data.

A Guardian article headed Internet censorship listed: how does each country compare? includes a table from the OpenNet Initiative listing countries and how each rates regarding (1) Political Filtering, (2) Social Filtering, (3) Internet Tools Filtering, and (4) Conflict/Security Filtering.

Of the 74 nations listed, only 40 had no Internet restrictions while 5 had "substantial" political filtering. ONI's options were, by severity:

  • Substantial

  • Selective

  • Pervasive

  • No evidence

USA Today identifies its Top 10 Internet-censored countries.

 

Service

Just as a nation can close off Internet flow - or have it closed off by cyber-criminals attacking servers in the victim nation - it also can close its borders to two-way traffic - or, as with cyber-crime, be isolated by its neighbors' closed borders.

In either situation, your organization needs to plan ahead and, while travel is possible, either

  1. Send its personnel to the vendor or

  2. Have vendor trainers come to your organization

to train to a level sufficient to meet client requirements.

In truth, this is no different than if the vendor's site is isolated due to a localized epidemic or any other "natural" cause.

Technical manuals are helpful, but having "factory-trained" personnel with hands-on experience always trumps a manual - paper or digital. That should <

be understood to mean technical documentation - with any updates - is not necessary; it is most assuredly necessary.

I have been a technical writer and a trainer. I remain a reader of manuals and other instruction materials.

Don't forget "the usual suspects"

When reviewing the threats to an international supply chain - be the product or service physical or software - remember all the "routine" supply chain gremlins, including but not limited to

  • Competition
  • Customer fickleness
  • Point-to-point transportation (sea, air, rail, roadway)
  • Work (in)actions
  • Theft
  • Vendor failure (temporary or permanent)

 

* MTBF: Mean Time Before Failure

Wednesday, July 31, 2013

ERM-BC-COOP:

Disease spreading
At speed of flight

Polio, not bird flu


Updated on 1 August 2013 at end of entry

Israel has recently reported several cases of polio.

Since Israel inoculates all children and new immigrants with anti-polio vaccine, the appearance of polio should tell risk management practitioners two things:

    One: In order to eradicate a contagious disease, the effort must be worldwide

    Two: Communicable diseases can – and are – spread at the speed of flight.

According to Israeli sources ( http://www.israelnationalnews.com/News/News.aspx/), “The strain of polio virus recently discovered in southern Israel is exactly the same kind as the type of virus that is prevalent in Pakistan, and which existed exclusively in Pakistan until recently, reports the Pakistan-based publication Dawn.

“Dr. Nima Abid, a representative of the World Health Organization (WHO) in Pakistan, told Dawn that the virus was "definitely" from Pakistan, since “The virus genotype (genetic make-up) is the same as prevalent in Pakistan and this is what the research has indicated."

“The samples of the virus strain were found in sewage in Cairo, in December last year.

There had been no cases of polio in Egypt for five years previously, and the disease had been eradicated in Israel much before that, said the WHO official.”

Polio is not the only easily transmitted disease that requires international cooperation to eliminate.

Add to polio small pox and tuberculosis.

Although none is as “sexy” as bird flu, nor do they get the media attention; unlike bid flu, polio and small pox are preventable and TB can be mitigated through prophylaxis. (The TB vaccine is rarely used in the US although in countries bordering areas known for TB, the vaccine is routinely administered.)

The “bottom line” for risk management practitioners is three-pronged:

    One: Be aware of communicable diseases around the world, particularly where your services or products are used.

    Two: Push for policies and procedures that require employees, from Very Senior Executives to the lowest go-fer, to take advantage of all the available preventive medicines for any disease known to be in a destination country – and all stops in between.

    Three: Push for policies and procedures requiring all visitors who are from, or who recently have visited, countries known to host contagious diseases to prove they are protected from the contagious maladies.

A good place to start checking on what is going on in any particular country is the Centers for Disease Control and Prevention (CDC) at http://wwwnc.cdc.gov/travel. The World Health Organization (WHO) page at http://www.who.int/csr/outbreaknetwork/en/ also is helpful, but a bit more cumbersome in locating general country-specific information.

Because very few flights or cruises are non-stop, make certain to consider the possible intermediate stops. This will not provide 100 percent protection since many countries' foreigners-in-transit areas are shared with travelers from around the world.

The best protection is preventive medicine for all travelers and for those people at home who normally interact with foreign visitors.

The time between infection and the onset of symptoms may include the times the carrier is most contagious. The old saw, "An ounce of prevention" is true for all things risk management, and very true for preventive medicine.

Added 1 August 2013

The World Health Organization (WHO) warned Wednesday (31 July 2013) that there was a medium to high likelihood that the polio virus found in Israel will spread overseas. The organization also issued a stark travel advisory warning tourists to make sure they were properly vaccinated before visiting Israel.

The polio virus is found mostly in Afghanistan, Nigeria, Pakistan and the Horn of Africa. The polio strain discovered in southern Israel several weeks ago is believed to be identical to the strain prevalent in Pakistan.

If I wrote it, you may quote it.