The previous four articles in this series dealt with designing resilience into your environment, monitoring and responding to events and recovering from business service being disrupted by an incident. In this final article, we discuss organisational structures that will help you achieve and sustain resilience. Attaining and sustaining operational, including cyber, resilience requires influence and collaboration that crosses company organisational boundaries.
Cyber incident and resilience best practices
Resilience best practice is a business imperative, and it should be managed as one. That means it isn’t the sole responsibility of IT.
Business resilience is becoming a priority that’s increasingly directed from the top. In recent years, threats and demands from malicious actors and unplanned interruptions of business services have spotlighted the increasing vulnerability of, and negative impacts on, organisations when it comes to cyber-incidents.
Such incidents ought to lead to a greater board focus on cyber-resilience, response and recovery. These areas are receiving funding, spawning independent organisations, and seeing implementation of specialised protection and monitoring systems.
What does an operational resilience program office do?
An outage is an outage, whether the result of malware, human error, technological failure or natural disaster. Businesses would do well to think about setting up an operational resilience program office, encompassing preparation, protection and practice for all aspects of operational resilience (including cyber-resilience). This should be established and headed by a C-level executive – perhaps the CISO, but with an expanded mission.
Under the direction of a Chief Resilience Officer, an operational resilience program office coordinates efforts across departments to establish resilient business and IT services capable of:
An operational resilience program office is the resilience champion for the entire organisation, providing an end-to-end cross-organisation focus on resilience. It is responsible for:
Effect resilience behavior across the organisation
The above list can represent high-value, high-priority activities for the company, given the excessive costs, widespread effects – not least of which is bad publicity – and increasing incidence of outages. The Chief Resilience Officer role links the executive management resilience directives to the parts of the businesses responsible for cyber-resilience systems. The operational resilience program office lets you manage and co-ordinate the adoption of effective resilience behaviour across the organisation.
Kyndryl’s role
Kyndryl understands the importance of security and resilience. We have more than 30 years of designing, building, managing and recovering IT operating environments, including from the latest types of threats and multi-stage attacks. Our more than 7,500 skilled cyber-security and resilience employees have addressed resilience, response and recovery issues through preparation, protection and recovery activities for many customers. We stand ready to assist you to be resilient to “cyber-geddon.”
Bob Pitcole - Executive Consultant, Kyndryl Security & Resiliency Servces
© 2024, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543