Service Continuity: Complex interplay between risk, resilience, crisis, security & management
Expectations and demands of 'service continuity' remains a complex interplay between contributing factors such as risk, resilience, crisis, security and management.
That is, distinct from the introspective, dispassionate concepts of 'business as usual' (BAU), service continuity remains customer/client centric, viewing the need to keep services and supply maintained...regardless of what is happening or how you would typically/routinely conduct business. Especially when there is nothing 'usual' about what is occurring, has happened or required to change.
In other words, BAU is about you and your business, when customers/consumers don't really care. The priority is on what the customer/consumer needs...service, hence the emphasis on continuity in the wake of delay, disruptions, risk, etc.
"Service continuity, as a concept, emphasises that organisational assets, soft and hard, remains to the end of satisfying customers and maintaining the explicit and implicit service level agreement between supplier and client." - (Elliot, et al., 2010)
The question for most traditional business continuity plans/management strategies is... what about service?
Exclusive focus on business continuity process, information and the appearance of preparedness can routinely displace the realities of what makes money, reputations, relationships and profits.....service!!
Moreover, fragmented (and routinely competing personalities, structures and agendas) between risk, crisis, security and 'resilience' further undermine and diverge from 'service' in lieu or power, prominence, funding and appearance.
As a result, customers, regulators and media are quick to criticise and critique most highly visible business disruptions because business continuity has in fact not been orientated around non-stop service, merely auditable and 'appealing' narratives, plans and attestation claims or 'continuity', which quickly fails in light of threats, hazards, dangers and failures.
Of course, 'act of god', unforeseeable, unprecedented, once on one hundred/thousand years and many other verbal defences, holding statements and neutralising statements are then paraded out in an attempt to divert attention and blame, which most professionals and experts know to be a failure of service continuity consideration and preparedness.
Subsequently, gateway factors such as risk, crisis and security remain underdeveloped and therefore negating any expectation of ever achieving resilience or resourcefulness over time.
Business continuity management is more than static plans, standards and digestible frameworks.
Dynamic, disparate relationships and interactions influence any premise of continuity and require constant nurturing, monitoring, management and cultivation.
These networks, stakeholders, relationships, confidence, preparedness and reliability require much more than a simple graphic.
Moreover, the influence and interplay when one or more changes or updates must be analysed in its entirety, not in isolation or as a single unit.
Source: (Smith and Brooks, 2013)
In sum, service continuity requires consistent, collective consideration and evaluation of multiple disciplines, systems and functions such as security, crisis, business continuity, safety and even management...inclusive of multiple layers of providers and partners, beyond just third-party headlines and placeholders.
Recommended by LinkedIn
Inadequate, disparate or incomplete consideration of each and all of these factors will not produce nor assure resilience, regardless of top-down narratives, proclamations and assertions.
This appears to be a persistent, difficult lesson for some organisations and industries to learn or comprehend in recent years, especially when one or more disruptive or widespread events influences their operations, people and supply lines.
In short, service continuity is the desire, demand and requirement of most businesses, governments and systems.
They don't care if your business is running, profitable, aware or concerned if your business is acting as 'usual' or not.
Moreover, they typically get angry, vocal or take action when deceived or lied to when a company can't deliver on the promise, honour an agreement or deceive as to why they aren't getting what they paid for, need or received in the past.
Tony Ridley, MSc CSyP MSyI M.ISRM
Security, Risk & Management Sciences
Bibliography:
ANSI/ASIS/ORM.1-2017, Security and Resilience in Organizations and their Supply Chains Standard, ASIS International, 2017
ANSI/ASIS/BCM.1-2021, Business Continuity Management Guideline, ASIS International, 2021
Elliot, D., Swartz, E. and Herbane, B. (2010) Business continuity management: a crisis management approach, 2nd ed, Routledge, pp. 124-216
ISO 22313, Societal security — Business continuity management systems — Guidance
ISO/TS 22330, Security and resilience — Business continuity management systems — Guidelines for people aspects of business continuity
ISO/TS 22331, Security and resilience — Business continuity management systems — Guidelines for business continuity strategy
ISO 28000, Specification for security management systems for the supply chain
ISO 22300 Security and resilience - Vocabulary
ISO/TS 22332 Security and resilience - Business continuity management systems - Guidelines for developing business continuity plans and procedures
Smith, C. and Brooks, D. (2013) Security Science: The theory and practice of security, Elsevier, p.203-223