Showing posts with label Business Resilience. Show all posts
Showing posts with label Business Resilience. Show all posts

Sunday, July 26, 2026

Trust Decisions: Future Risk Architecture...

Leadership within the enterprise requires "Trust Decisions" that they can count on.  Operational Risk Officers have a fiduciary duty to provide top executives with the confidence that the data and information they provide is trusted.

So how do you assist any corporate leader, who has the responsibility and accountability to the Board of Directors to make informed and sound decisions?  The answer is, that it depends on how willing the CxO's in the enterprise are to engineer a "Trust Decision" model and framework for the business.

The truth is, most executive managers have their own way of doing this.  The process that the CEO makes decisions, is quite different from how the CFO makes decisions and the COO may have a documented and tested way to make their decisions.  The point is, that major "Trust Decisions" for the good and welfare of the enterprise are being made by people who are each doing it differently.  These human decision makers are relying on a number of ways to get to the final answer.  The decisions from leadership are not as trusted and reliable as they could be.

As an Operational Risk executive charged with making timely and correct decisions you have no choice but to have the tools and the trusted sources to enhance your situational awareness.  The safety and security of the facility, information or peoples lives are at stake.  That is why you test and continually improve the process so your analytics dashboard, intelligence feeds and data sensors are all operating with integrity and in real-time.

You are relying on information that changes by the nanosecond and a system designed to provide decision support.  Intelligence-led investigations or reacting to the latest incident requires systems designed and tested to support human "Trust Decisions."  Now back to the executive leadership and their process for decision-making.  What is it?  How does the CEO make the final decisions for the future wealth of the company and it's stakeholders?  Are they trustworthy?

Unless you have seen the "Trust Decision" process and trusted data framework engineered for your enterprise, then probably not.  Think about all of the leadership level projects and how they turned out.  How did executive leadership decide to buy that other company or merge with their favorite supplier?  What process did they use to ensure all of the due diligence data was correct?  Why are the sources of data trusted?

We have the opportunity to improve and to arrive at a point where we make "Trust Decisions" our priority and a prerequisite.  After all, our employees, customers, shareholders and even mankind deserve it.  The challenge begins.

Whenever you encounter your next major business decision with your CxO, ask them how they arrived at the decision.  Ask them to explain the process they used and the sources of trusted data they relied on.  Ask them why they think the architecture of the decision at hand, is the most sound and trusted decision that can be made with the time available.

You are now well on your way to better understanding the power and the future risk architecture of TrustDecisions.

Saturday, May 16, 2026

Liaison Mission: When Will You Introduce Them?

As a current Chief Executive Officer or Commander across some branch or agency, who have you named as a key "Liaison?"  Who is this vital person that you have asked to be your voice, your thinking and your representative to a partner, collaborator or strategic ally?


In Chris Fussell's book One Mission:  How Leaders Build A Team of Teams, the Task Force Liaison is described as follows:


"We clearly share a determined adversary--one that, unlike our organizations, is networked and thus moves with incredible speed. In the Task Force, we are now trying to forge a new type of model based on relationships among individuals and organizations like yours--and we'd like to be more closely connected with your organization. Winning will come from leveraging our mutual strengths, sharing insights and nuanced understanding of the problems and respecting one another's positions.

To help our partnership, we would like to give you one of our best people as a liaison. I expect our liaison to be an asset to you, sharing anything we're doing, providing our most timely intelligence, and seeking out ways that we can help your organization accomplish its goals."

This idea is not a new strategy per se.  Similar derivations of the concept have been utilized for hundreds if not thousands of years.  So why is this so important now, to the current state of global and corporate affairs?


The first reason is that operating at the speed of "iMessaging" social media, will create chasms of misunderstanding.  The simple fact is that information being collected, interpreted and disseminated in your digital-based platforms will most likely have gaps.  The messaging and communications will be hard to decipher by others, who don't know all of the acronyms as just one example.


This is where an embedded "Liaison Officer" or representative can bridge the cultures and the lines of direct messaging.  This is how the speed of the combined network is increased in it's ability to pivot, to adapt and to solve problems, faster and with higher quality than the competition.


The second reason is that a key mission of the nominated Liaison is to establish, maintain and perpetuate trusted relationships.  Otherwise, how can the leaders of your two organizations gain any momentum, in the quality and the speed of the partnership that is desired as a relevant outcome?


Now think about your own organization.  Where do you have a blind spot?  What other entity, team, business unit or agency is now seen as a barrier or competitor?  Are you both after the same customer, the same target or the same outcome?  Is a partnership in place now, to even embed or exchange Liaison personnel?


Believe us when we say that your adversary has already done the same.  They are working together across boundaries to share intelligence, to exchange vital data and to work in tandem to perpetuate their cause, their ideology or their campaign.  They have their own trusted Liaison's working each day, to move faster than you are and to achieve new gains in their mission, while you are worried about the unknowns.


Who is it in your organization that you feel that you can't live without?  The one or two leaders that you rely on each day.  The personality that exhibits the way that "Adam Grant" describes a "Giver" or "Matcher," in the way they operate across the team and within the company.  This may be the best person for you to let go of and to be your next "Liaison" to that vital partner, agency or even country.


Looking across the landscape of America, you will find examples of this idea and methodology that is working.  You will find places across the globe where it is in total failure.  Yet how can you raise the odds, that the likelihood of the person you choose to be embedded with another organization, will indeed succeed?


As a current Team Leader, CEO or Commander, it means you will have to go a step farther.  It means that you will have to take this person side-by-side in many cases, into the same office, SCIF, SOC, NOC or conference room to explain it face-to-face.  Sitting across the table from this partnered organizations top executive, you say it:


"I have carefully selected "Jill or Jack" to be our Liaison with your unit or department.  It is something we know to be of great value to the ongoing mission we both face, to address the (problem-set).


 Please know that she/he knows me very well and how I think and what our organizations real capabilities are.  We will miss them, yet want her/him to work alongside your leaders to learn as fast as possible about your greatest hurdles and problems.  It is only then, that we envision a chance for our respective teams to move faster with the most effective joint solutions, to obtain and synchronize our advantage."  


This few minutes face-to-face may make all the difference on the potential for a successful and trusted relationship.  As you stand up and leave your Liaison with their new assigned organization, remember this.


Your Liaison's ability to succeed, will only be as good as the job you have done in preparing them for the assignment.  Think about all the months or years you have worked to shape their character, to instill the ethics and integrity into their daily decisions.  How many problems did you let them solve on their own?


We look forward to hearing the stories about your "Liaison's" and their respective missions to achieve decision advantage and to reach those lofty outcomes you seek...

Saturday, May 09, 2026

Business Resilience: Beyond Readiness...

The Continuity-of-Operations-Plan (COOP) for your Communications operations is an operational risk that in many cases is underestimated until a significant business disruption occurs.


When Comms are down, this means a combination of voice and data services that serve your business enterprise may not be available.


The resilience of both the voice and data communications is the holy grail of continuity of operations and disaster recovery professionals on a global basis.


Business Resilience and the ability to effectively anticipate or absorb the impact of an incident, whether man made or as a result of a natural phenomenon differentiates your suppliers.


When is the last time you tested your Tier I service supplier for a mission critical business process to determine the ability to keep their voice and data services running during a time of crisis?


And maybe more important, is your own enterprise “Incident Command” system survivable so that you can provide voice leadership to your "Incident Commanders" where ever they may be located on the globe.


When it comes to planning for the next Hurricane Katrina or the "Tip of the Spear" overseas operations readiness, resilient business organizations need to implement robust planning, immersive exercises and systems to be able to overcome the asymmetric “Operational Risks” that are now before them.


Power blackouts are the catalyst for many risks to the “Critical Infrastructure” including Transportation, Internet, Voice communications and even those services that you take for granted, like pumping gas at the local petrol station or emergency services at the local hospital.


Cyberspace as we know it is so deeply embedded into most of the mission essential aspects of business today that our readiness factor needs to go well beyond redundant power supplies and battery back ups just for power.


Cyber-Readiness is a key component of any organizations plan to stay resilient in the face of a Distributed Denial of Service Attack (DDOS) and other cyberspace exploits that may disrupt our operations.


Do you think you're spending too much time with your team planning and training?


You haven’t.

The organizations whose teams have planned for every possible scenario and trained together in live immersive simulations will become the most successful in their strategy execution.

Their missions will be accomplished on time and within budget.


Incidents of different severity and frequency are happening all around you and your organization every day.


Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?


Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things will go wrong…

Saturday, February 28, 2026

Operational Risk: The Pursuit of Trusted Information...

Operational Risk is about Performance Management and Business Resilience. A few months ago the topic of "Compete or Die" was discussed here. Why revisit this topic?

CEO's and the Board of Directors realize the road to eliminating fear in their organization and the marketplace is through trusted information.

Being agile, ready and capable of a quick recovery is what competitiveness is all about, on the field, on stage or around the table in the Board Room.

Working towards control and protection while "Fear" builds in the back of your mind makes you stiff, depletes your energy and creates doubt. And when you are operating a business or standing on the tee of your first sudden death hole on any PGA weekend, you better have resilience.
The business equivalent to Homeland Security and Critical Infrastructure Protection is Operational Risk Management—a domain that many executives see as the most important emerging area of risk for their firms. Increasingly, failure to plan for Operational Resilience can have “bet the firm” results. 
There are numerous examples of how errors, omissions and glitches have brought down the reputations of many a Fortune 500 companies. What do they all have in common that led to their demise? A lack of economic and business resilience to remain competitive in the marketplace.

The threat of Tort Liability and the loss of reputation is top of mind these days with every major global company executive. The threat is real and increasing at a faster rate than many other real operational risks to the enterprise. Litigation from regulators, class actions and competitors has given the term Legal Risk new emphasis and meaning.

Once corporate management understands the need for a "resilience" mentality in place of a "protection" mental state, a new perspective is found. Investing in the vitality, agility and competitive capabilities of the organization sounds and is more positive.

It alleviates the fear of doom and gloom and inspires new found innovation. The future of your organizations longevity and in it's adaptability can be achieved with a new perspective. Compete or die.

Performance Management could be enabled or suppressed by the amount of power you give your leadership. Do they have the ability to make a $1M decision or $10K decisions when it comes to investing budgeted capital into their business unit growth?

Do they manage risk on a level where they are the most informed and the most knowledgeable about the business, or is the "Mother Ship" back at the home office dictating the way they spend or the way they invest?

The ability to know how to manage risk at the point of creating new information is the nexus of several disciplines and requires substantial training. Every minute that goes by with people not behaving correctly puts the enterprise at greater risk to lost performance opportunities.

All these issues can be summed up in a single concept: trusted information. Simply accessing data is no longer enough. Today's CEOs, CFOs and knowledge-workers must be able to reliably track the information they use for decisions back to the original source systems in order to ensure its timeliness, accuracy and credibility.

Over the last few decades, organizations have invested Billions of dollars in systems to collect, store and distribute information more effectively. Despite this, information users at all levels of the organization are often uncomfortable with the quality, reliability and transparency of the information they receive.

Today's organizations rarely have a "single view of the truth." Executives waste time in meetings debating whose figures are correct, rather than what to do about the company's issues.

Additionally, they worry about the AI consequences of making strategic decisions using the wrong information, directly impacting the long-term survival of the organization.

The search for trusted information is a continuous pursuit for commanders in the "Mission Ready Room" and the "Corporate Board Room".

So how do you achieve the level of assurance that's required to make the "bet the farm" risk management decisions in your enterprise?

Saturday, February 07, 2026

SMART Objectives: The Catalyst for Resilience...

Operational Risk Management (ORM) is evolving into a discipline with an over arching set of objectives. The organizations and entities that do not understand the purpose and the reason behind having SMART objectives, might need a refresher:
  • Simple
  • Measurable
  • Achievable
  • Realistic
  • Task-oriented
Without "SMART" objectives, any project will continue to strive for a purpose and a relevant set of outcomes. Constituents, stakeholders and various affected employees that intersect with an internal risk mitigation exercise, will continuously require coaching on how to base the project on "SMART" objectives.

Next, the stakeholders will require a path forward that includes a building block approach to gaining consensus, agreement and a set of written events that will either be simulated or real.

These events comprise a master scenario, that the organization will utilize to test a hypothesis or set of operational capabilities. The high reaching outcome, is to determine where there are gaps, vulnerabilities and opportunities to improve.

The building blocks approach may include:
  1. Seminars
  2. Workshops
  3. Table Top Exercises
  4. Games
These provide the stakeholders with the opportunity to converge on their respective areas of expertise and integrate them with the overall scenario being developed. However, these are still based upon first identifying the "SMART Objectives" and the application to your particular business, organization, city, state or country.

Taking the foundation of Operational Risk Management and applying a process for evaluation, requires a set of standards so all of the respective constituents, will be talking and practicing from the same exercise play book.

In the United States this standard is HSEEP or "Homeland Security Exercise and Evaluation Program":
The Homeland Security Exercise and Evaluation Program (HSEEP) is a capabilities and performance-based exercise program that provides a standardized methodology and terminology for exercise design, development, conduct, evaluation, and improvement planning.

The Homeland Security Exercise and Evaluation Program (HSEEP) constitutes a national standard for all exercises. Through exercises, the National Exercise Program supports organizations to achieve objective assessments of their capabilities so that strengths and areas for improvement are identified, corrected, and shared as appropriate prior to a real incident.
Whether your organization is new to doing functional or full-scale exercises doesn't matter. Having a process oriented model for program management and project management will provide you with the tools and the foundation to achieve new found learning on where and how to improve your enterprise resilience.

Operational Risk Management professionals are working with an organization or population that is constantly striving to be more resilient.

Without testing, without exercising and without the process framework in place to try and achieve measurable objectives, the organization will never gain the vital insight on where and how it can improve rapidly.

It will never fully understand where the enemy will try and exploit the weaknesses. The organization will never realize their resilience factor at this point in time.

When was the last time your organization really tested itself, to survive? How long has it been since you re-established the relationships and the trusted connections with your own supply chain? Why has it been that long?

There are some elite organizations in the world who understand readiness, that have learned along the way of their evolution why exercising and a trusted supply chain is critical to their own survival before the next incident occurs:
To become a SEAL in the Naval Special Warfare/Naval Special Operations (NSW/NSO) community, you must first go through what is widely considered to be the most physically and mentally demanding military training in existence. Then comes the tough part: the job of essentially taking on any situation or foe that the world has to offer.
Direct action warfare. Special reconnaissance. Counterterrorism. Foreign internal defense. When there’s nowhere else to turn, Navy SEALs are in their element. Achieving the impossible by way of conditioned response, sheer willpower and absolute dedication to their training, their missions and their fellow spec ops team members.
This analogy to the Navy SEALs demonstrates that preparedness long before you are asked to test your own resilience, will save lives. Yet there are so many other ways that our planet and the people on it, are being tested every day outside of the context of natural disasters, counterterrorism or national defense missions.

When you think about resilience in the context and relevance of the threats before us, we all have to realize that whether it is the National Level Exercise (NLE), or our US Navy SEALs, only SMART objectives will increase our ability to learn, to save lives and allow for the potential survivability of our organizations or impacted populations...

Sunday, February 01, 2026

OSINT: "Accent on the Future"...

It was early-August of 2000 and topics of the “Dark Web” were prolific around the conference table at 8:00AM on that early Monday morning.  Our building on Wilson Blvd was just a few blocks up the hill from the Rosslyn, VA Metro Station.

Soon the dialogue turned to the weekends OSINT and the Terabytes our Cyveillance Web crawlers had retrieved across the globe.

Minding clients business on the Internet was going beyond what was visible with run of the mill browsers and growing search engines.  It had now gone dark, without the right tools, software and protocols.

Now was our opportunity to begin new strategic ventures with clients on three key “Decision Advantages”:

  • Continuity
  • Safety
  • Resilience

How as a Fortune 500 company operating across the globe could you apply these factors to increase your awareness and integrity of your content on the World Wide Web?

Where and how were your adversaries using your published information in nefarious ways to attack your organization?  To influence your product perceptions.  To launch campaigns of doubt against you.

It was now time to get on a plane to fly to the U.S. HQ of our global clients to inform them what was at stake beyond brand protection, social media monitoring and threat investigation, analysis, and response services.

  • Think about your business technology operations.  What factors could impact the continuity of your services based upon your geographic locations?
  • Think about your employees health and exposure to life threatening acts of sabotage or natural weather events.
  • Think about your organizations ability to defend itself against a spectrum of threats and to bounce back quickly to stay in competition with rivals.

Little did we know what was in our future, just about a year away in September 2001.

What if we could apply Continuity, Safety and Resilience (CSR) into our dialogue with a majority of our clients major growth initiatives?

On that Wednesday morning wake up call after a flight to O’hare the previous evening, it was thoughts of Arthur Andersen and the meeting ahead at their HQ.

That morning in a small office looking out on Chicago, we learned about the vast strategy of making a split of AA and Andersen Consulting into a new renaming on 1 January 2001.

Andersen Consulting would soon adopt the new name "Accenture". The word "Accenture" was derived from "Accent on the future”.

The question that morning was now on the “White Board”.

"Where are all the places on the Internet with the brand name “Andersen Consulting” that now needs to be changed to Accenture with a new logo?"

We can help with that business problem in a few hours.  The following day we knew that there were thousands of instances on the “Sun Microsystems” sites alone.

In July of 2001 Accenture would go public (IPO) and 8 years later move their HQ to Dublin, Ireland.  Today they have 779,000+ employees and revenue of US$69.xx billion (2025)…

Saturday, January 10, 2026

Risk Visualization: Enterprise Prevention...

When "Corporate Executives" start talking about how to reduce fraud and other critical Operational Risks across the institution, there is going to be plenty of debate.

Where do you focus your resources and investments in order to get the best ROI and economic value?

If you thought the pornographers were the leading ledge of innovation on the AI Internet, there is a new breed of international criminals and corporate attackers that have emerged at the top of the pyramid.

Financial services organizations are taking an enterprise view of global risk prevention to try and keep ahead of these increasingly clever and technology oriented crooks.

Having an enterprise view of holistic risk is the "Holy Grail" and some would say that focusing on the account and not more on the customer is the wrong approach.

What is clear about the online evolution of fraud activity is that social engineering is working in the exploitation game. Hardening all of the systems with two-factor authentication or even IP Geolocation is just part of a layered risk strategy.

Working from within the walls of your institution trying to figure out how to protect your assets and your customers is merely a myopic strategy.

The attackers are moving too fast and have access to the same tools in their labs where they utilize their own methods and processes for exploiting the vulnerabilities in your latest applications.

Now that you have spent millions on implementing that new AML or fraud detection system, are you sleeping any better at night?

"True strategic analysis of risk and the convergence of relevant data makes scenario development, proactive planning and open source intelligence an area that requires consistent attention."

Simulations and evaluation of possible physical and digital exploits that haven't even been detected yet could provide the proactive and preventive advantage you have been seeking.

What is your latest hypothesis?  Have you tested it effectively to determine the likelihood and impact of success? Training and practicing for the unknown and unthinkable puts you and your team in a more resilient mode to survive the next attack. Whether it's through the front door, the suppliers back door or through the copper wire into your customers home or business office, detection is critical.  

Anticipation and deterrence is imperative...

Sunday, December 28, 2025

New Year 2026: Becoming a Knowledge Navigator...

“And the things you have heard me say in the presence of many witnesses entrust to reliable people who will also be qualified to teach others”. From 2 Timothy 2:2

Approaching New Year's Day 2026 people in countries across the globe will be praying for a hopeful future.

What have you accomplished in 2025 to assist others in becoming more Strong, more Smart, more Reliable, more Knowledgeable and more Resilient?

When shall you lead a "Team" to overcome Evil in our world and to build new Safe Havens for those you care about?

How will you lead others to build new skills that will in turn create new innovation?

Creating and delivering knowledge-based products and services that makes those around us smarter is a lofty vision.

The outcomes we seek each week is different and yet very much the same:

  • Create new learning and significant outcomes.
  • Identify weaknesses and any brewing evil on a continuous basis.
  • Develop positive outcomes and share new found “Decision Advantage”.
  • Believe in your ability to show others the way.

New Year's Eve 2026, look around you at 6:00PM.  What do you hear and see?

If it is not all that you wish for yourself, and that you want to change, then Adapt, Change and Innovate.

Your own future into 2026 is all in your hands and awaiting your actions.  At 7:00PM, start reading a book “The Monster Under the Bed” by Stan Davis and Jim Botkin. https://a.co/d/bKS4KRA

In 2026, you too shall learn the “Seven Ways” of opportunity of knowledge for profit and how to teach others.  Pay close attention to the THIRD:

“Any business can become a knowledge business by putting data and information to productive use, creating knowledge-based products and services that makes its customers smarter.”

Onward!