Top five business continuity risks for 2014

March 2014 Security Services & Risk Management

At the beginning of 2013, ContinuitySA warned that business risks were becoming more complex and intertwined, and so much harder to predict and plan for. But this year they are also becoming more extreme.

Michael Davies, CEO of ContinuitySA.
Michael Davies, CEO of ContinuitySA.

“As the world becomes more interconnected, issues faced in other parts of the globe can create risks here in South Africa. For example, the unprecedented cold weather in the United States and severe storms in the United Kingdom should be prompting businesses to start thinking about the extreme nature of the risks they face,” says Michael Davies, CEO of ContinuitySA. “The global business environment has created a web of interdependencies so that any untoward event has a set of knock-on effects. Directors and executive management, who have a duty to ensure the company is able to stay in business, must have a comprehensive business continuity plan in place.”

Davies and his team have identified five current categories of risk for 2014 that should be featuring in business continuity planning.

1. IT and data risk is growing

IT is strategic and, to a greater or lesser degree, every business is a digital business. However, a key risk is that internal IT departments are failing to keep pace with changing needs, in turn prompting massive use of private mobile devices to access corporate systems and the unplanned use of cloud-based services like Dropbox. Another related IT risk is ‘server sprawl’, creating complex environments that are difficult and expensive to manage, and hard to recover in the event of a disaster.

“The information on a company’s systems is increasingly valuable as advances in analytics make it more useful – its loss now represents a considerable risk,” Davies observes. “A lot of this data is client-sensitive and so is protected by law.”

In parallel, cybercrime appears to be on upward trend, with cybercriminals threatening precious (and often legally protected) data. Denial-of-service attacks can also cause systems to collapse, creating another business continuity risk. While estimates of cybercrime prevalence vary dramatically, it’s clear that it is both significant and underreported.

2. The macroeconomic climate remains problematic

Slow and inconsistent global recovery and a volatile currency are obvious risks that most businesses consider but often from a purely financial perspective. “But the impacts on your business’s viability may be much more subtle; for example, decreased economic activity could reduce tax receipts and so construction of infrastructure on which your business depends,” Davies points out.

3. Long supply chains expose companies to a wider range of risk

Locally, Gauteng e-tolling has emerged as a proxy for political dissatisfaction (and a rare unifying issue) for both the middle and working classes. It’s possible that continued protests could disrupt supply chains, and will certainly raise costs in the short term.

“Looking more broadly, I think the combination of ever longer supply chains and the just-in-time mentality is creating a huge risk that many businesses do not properly factor into their business continuity planning,” Davies says. “The strike by component manufacturers in our local automotive industry is one good example, but think of the effect of extreme weather on manufacturers in Japan and Thailand in past years, which all but crippled international car and electronics supply chains. A comprehensive business continuity management plan for the entire supply chain is now mandatory.”

4. Environmental degradation and climate change are too easy to ignore

Aside from the obvious macro risks of violent climactic events and a compromised environment, South African business needs to pay particular attention to water. Our water resources are limited and yet are becoming ever more polluted. Acid mine drainage is, if the scientists are to be believed, a ticking time bomb although, as is so often the case, experts seem prone to getting the timing of natural processes wrong.

5. Societal risks are escalating in scale and seriousness

As 2014 is an election year, political risk has to feature on business continuity plans. Electioneering raises the stakes and could make industrial action even more bitter, while marches that get out of hand could disrupt operations. South Africa is not the only country with forthcoming elections, and organisations should consider in which countries their products and services are being delivered and from where their supplies come. Generally, too, international political developments could derail the slow economic recovery; Iran and North Korea are only two of many countries that could spark a new crisis.

Following on from the attack on Westgate Mall in Nairobi, extremist violence must be a consideration particularly for companies with Pan-African operations.

Another key societal risk to business continuity is the ‘new normal’ of violent and protracted strike action. This unwelcome state of affairs is part of a widespread dynamic of social discontent and instability. Violent and disruptive service-delivery protests are one example, but so are growing rates of alcohol and drug abuse, not to forget anxiety and depression. All of these factors have an impact on absenteeism and productivity.

All of these five categories of risk carry the subsidiary, but highly dangerous, risk of reputational damage. Warren Buffet has rightly said, “It takes 20 years to build a reputation and only five minutes to destroy it” – and an unmitigated disaster is one way to achieve that destruction.

In conclusion, Davies warns that business continuity – the process for identifying and mitigating these and other risks, remains widely misunderstood. Too many businesses continue to imagine that if they have a plan in place for IT disaster recovery, their business continuity is assured.

“Strategic as it is, IT isn’t the whole business. Business continuity planning and management must cover all the risks the business faces and put in place contingency plans to keep the entire enterprise operating,” says Davies. “The call centre and work-area recovery requirements for a business need to be considered, and the company must understand the risks its supply chain faces. One’s business is now dependent on entities outside of the corporation: is each of them adequately protected?”

For more information contact ContinuitySA, +27 (0)11 554 8050, cindy.bodenstein@continuitysa.co.za,





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...
Verification is reshaping South Africa’s labour market
Security Services & Risk Management Asset Management Commercial (Industry)
Hiring faster, trusting less: in a labour market defined by both constraint and potential, the ability to hire with confidence may well become one of the most important competitive advantages.

Read more...
Africa’s opportunity to shape the future of human-centred AI
AI & Data Analytics Security Services & Risk Management
Across the Global South, countries are not yet locked into decades of legacy AI systems, energy-intensive infrastructure, or governance frameworks designed for a different technological era. That creates something rare in technology development: a cleaner slate.

Read more...
AURA appoints Taryn Winer as global head of people
News & Events Security Services & Risk Management
Following its €13,5 million Series B funding round last year and accelerating international expansion, particularly across the United States, AURA has appointed Taryn Winer as global head of people.

Read more...
95% do not have full trust in cybersecurity vendors
Information Security Security Services & Risk Management
Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels. Lack of verifiable transparency undermines cybersecurity decision-making, according to Sophos-backed research.

Read more...
Enhancing control room operations
iFacts Security Services & Risk Management Surveillance
As South Africa faces complex and more advanced security challenges, the demand for advanced surveillance solutions, including CCTV and security control rooms, continues to surge, but what about the people in front of the screens?

Read more...
Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.