The transcription features discussions on the importance of building resilience in organizations to combat various risks. It stresses the need for structured and agile resilience functions in the face of global crises and interconnected risks. Emphasis is placed on leadership's role in fostering resilience, particularly in addressing supply chain risks like extreme weather events and geopolitical disruptions. The text also highlights the evolving challenges posed by misinformation, cyber insecurity, and adverse AI outcomes. Overall, the importance of proactive risk identification, robust mitigation strategies, and comprehensive testing of business continuity plans is emphasized to ensure organizational resilience in the current complex and rapidly evolving risk landscape.
Transcription
4618 Words, 27321 Characters
Hello, I'm Cathy Syfus, Head of Risk, Resilience and Technology within Marsh Advisory UK.
Welcome to Risk in Context, which features conversations with Marsh colleagues and risk professionals.
We are here to help you better understand today's risks, build more effective insurance programs,
and think creatively about risk as a whole.
The world is facing multiple crises, with global events acting as constant reminders
about the need for organisations to build structured, agile and holistic resilience functions.
According to this year's Global Risk Report, produced by the World Economic Forum with support from Marsh McLennan,
interconnected and multi-layered risks are contributing to a rather pessimistic outlook for 2024 and beyond.
The report underscores the importance for all organisations to build strong resilience strategies
in preparation for both emerging and evolving risks, such as supply chain disruption and AI.
To learn more about the Global Risk Report, take a look at the Global Risk and Resilience episode of the Risk in Context podcast.
But for today, we will discuss the importance for organisations to put the necessary structures in place to build resilience
so that they are able to withstand the impact of known, emerging and evolving risks.
To explore this topic, I'm joined by Nicholas Martin, Head of Strategic Risk Consulting for Pacific,
and we will hear insights from Renata Elias, Senior Vice President within Marsh Advisory's practice in the US.
Welcome, Nick. Great to speak with you again about one of our favourite topics, resilience.
Let's contextualise our conversation a little up front.
The term business resilience, in my view, shifts the focus from internal operational continuity
to being able to withstand external turbulence.
When we consider the combination of increasing interconnectedness and increasing turbulence,
organisations are forced to consider resilience as a consequence.
Just to give you a feel for the scale of concern, the majority of respondents to the Global Risk Perception Survey
in September 2023 found that 54% anticipate global catastrophes this year,
whilst another 27% expect greater turbulence.
So, Nick, in the light of that outlook, how are you seeing organisations change the way they adopt resilience within their organisations?
It's a good question. I think we've been through a significant period of disruption.
If you go back to the start of 2020 and COVID,
and in intervening years, we've seen significant natural disasters, we've seen global conflict in certain regions.
We've also seen an uplift in cyber-related attacks on organisations.
So, I think organisations are now starting to figure out that the resilience programme is an important part of the way they do business,
and it's an important aspect to the business's tools to protect itself.
But what I don't think we've got to yet is organisations still have a very strong historical view of resilience
in that it was always you did crisis management, you did business continuity, you did IT disaster recovery,
and there were programmes that were running various parts of the business,
and you tried to bring them together once a year in a big bang exercise.
Now, unfortunately, those programmes really aren't fit for purpose in this environment.
We've seen in the Global Risk Reports that the top five risks in this report were all generally representing all five risk categories in the Global Risk Report.
So, to focus a resilience programme on one particular risk to a business
or hope that that risk will only manifest itself once a year is no longer fit for purpose,
and good organisations now are linking strategy to their risk, which is then linking to the resilience programme,
and they're bringing their resilience programmes to life through, I would call, white growth simulations
and lots of small scenario-type exercises that allow them to work on the current state of risk in their business,
not wait for that annual exercise.
Yeah, great point on the fact that there's a top-down view from strategy down to operational level,
and you also need that operational preparedness to percolate upwards.
Renato, I wonder whether you can tell us a bit more about the role of leadership when it comes to building or as a leading organisation.
That is a really good question, and I think a question that a lot of organisations are asking themselves.
You know, how do they ensure that they have a resilient organisation?
First of all, when we look at resilience, we're thinking sort of the whole organisation from top to bottom.
So, whether you're looking at the C-suite level, we think of that at the 40,000-foot level.
Right down to your employees at the operational tactical level, making sure that you have an organisation that is aligned and integrated,
whether it's in day-to-day operations or even in response mode.
It's really important if you also think about your organisation like an umbrella, and I call it the resilience umbrella,
where if you think about the tip of that umbrella, it's your crisis management team,
but then every spoke of the umbrella is another component of resilience, whether it's emergency response,
this is continuity, crisis communications, workplace violence, cyber response.
If your organisation has any of those spokes of your umbrella missing or they're broken,
there's a good chance that your organisation will not be resilient and therefore will get drenched in a crisis.
So, if you think about resilience, thinking about your whole enterprise from top to bottom,
also being really proactive is really important.
So, think about these things now. How resilient is your organisation now?
The time to think about whether you have things in place to bounce back from a crisis is not once a crisis has occurred.
You want to be looking at this very proactively because that resilient organisation most often will withstand any type of hit to your people,
your operations, your assets, legal and financial standing, but most importantly, your reputation.
So, I think, Kathy, that sums it up as far as, you know, really the importance of a resilient organisation.
Thanks, Malta. I couldn't agree more. I think all too often we see resilience owned in a non-revenue generating function,
which limits the influence impact that that team or the activities undertaken by that team can have.
Nick, I'm wondering how you've seen this play out with your previous roles and with your current clients.
Well, I think in the whole, we're still seeing the resilience program sitting within cost centres, within organisations,
and they can be in many different parts of the business.
They can sit within the safety program, within the risk function, under general counsel, inside finance.
And I think sometimes that's a challenge for a business to find a home for the resilience program.
But as Renato himself have been alluding to, I think the true home in this environment for resilience is somewhere where it has visibility by both the board and the executive team.
And we've seen an example of a change in the perception of the resilience program and a move to the top of the organisation in the side of the landscape
and how organisations are now responding to ransomware events.
Boards and the executive teams want to be a part of the decision-making process around ransomware,
and they want to also understand the decision-making that occurs right down at the front line.
So when a cyber event occurs, how it's passed through an incident management process makes its way through a crisis team,
and consultation with an executive team and then finally comes to a board for decision-making, that is really the future of resilience.
And so we're actually seeing examples of that, and I'm hoping that that methodology and that visibility of the resilience program will now play through into other aspects of resilience.
Yeah, ransomware is a great example, Nick, and just touching on what's important for leadership right now,
at least with our clients, we're seeing supply chain resilience become a real hot topic amongst the C-suite.
And when we look at supply chain resilience, it became particularly acute during the pandemic, but also more recently with the conflict in Ukraine.
And when you take these real-life examples and cross-check it with the Global Risk Report, the report found that 25% of respondents
anticipate supply chain disruption to be the most likely cause of a material crisis on a global scale this year,
and thus without considering how other risk events would trigger a supply chain crisis.
For example, 66% believe that the next global crisis will be caused by a climate event, and the impact of that would also trigger most likely a supply chain disruption.
So all in all, it's really filtering to the top of the agenda.
And what this tells us is that supply chain disruption is very likely to impact international organizations, and it's a risk we need to prepare for.
It's giving us the red flags. It's warning shots have been fired. We need to step up by preparing us to this risk in particular.
Nick, I'm wondering whether you can give us a feel for what supply chain risk in particular is worrying organizations that you're working with.
Thanks, Kathy. Supply chain risk to me is really the centre of a lot of risk facing businesses today, and I'll explain why.
If you think about supply chain, it has a lot of aspects to it.
You have the impact of not only extreme weather events, but you have also the impact of climate change.
So crops in certain regions may no longer be viable, so you can't source your products from there.
Then you also have the geopolitical aspects of supply chain, and probably most recently you've seen the disruption to one of questionably the three main shipping routes in the world, the Red Sea,
and the expansion of the conflict in the Middle East and how that's disrupting shipping through that particular part of the world.
Resulting in now shipping companies either not being able to get insurance, either paying extreme amounts for insurance, or having to reroute their ships to extend their voyages by 10 days.
So it's a huge financial cost and obviously delay to supply chains.
Then you also have off the back of that in the supply chain aspect, you have aspects of anti-modern slavery, and we've seen a recent example of that where cars were impounded on a port in the United States
because they contain products that were sourced from parts of the world that had modern slavery concerns attached to them.
And then finally, you can actually take supply chain right into the digital environment, and the digital supply chain now, and the aspects around who are you or software vendors.
So I might have a hardened cyber security environment for my organization, but I'm reliant on vendors.
Are they as hardened? Are they an attack surface that a threat actor could access?
So it's a really, I think supply chain, if you look at historically has always been, it's something we do in our business, a really top of mind.
I think now if you look at supply chain, the many aspects to it, it's actually fast rising up to be one of the top risks for businesses.
And then you mentioned before the top 10 current risks that identify in the global risk report, it's debatable, but I would actually say that you could actually link those 25% that have identified that as a risk to a lot of other aspects around climate, destruction and supply chain for food,
attacks on critical infrastructure, cost of living crisis has probably become more expensive, it goes on and on and on.
So I think it's definitely topical, and I think you'll see a lot more focus on that from businesses a year ago.
With the complexity of supply chain risk in mind, organizations now turning their attention to how do they identify those risks that are attached to their current supply chain?
And then how do they look at two aspects? One is a response to an impact on their supply chain or an outage, and that plays into your business continuity arrangements.
But also, how do you actually look at the strategy of the business and the risks that are associated with your supply chain and ensure your business is prepared to address those risks should they manifest through a resilience program?
Yeah, great point, Nick. And Renata, I wonder whether you can talk us through how can organizations become more prepared? What are the key elements of building a resilience supply chain?
No, that's another great question. And I think, you know, really having gone through COVID, many organizations realized how important their supply chain is when they couldn't get parts, they couldn't get product in.
And while they may have had a business continuity plan to address internally how they would continue operations, they hadn't really thought about, well, what if we can't get product? What if we can't get those materials in to continue our operations?
So organizations are really now starting to look at number one, their continuity plan within their organization, but then start identifying those dependencies, those third party dependencies, those that those supply chains that they rely on to do business.
So looking at those business continuity plans, reviewing what your dependencies are is really important, making sure that you have, if you have one third party vendor, who you're relying on materials for or product for, do you have a backup for that vendor?
So that vendor is not able to supply that to you anymore, where you're working or your backup strategies for that. So really document that out and build that out internally, so that you are aware if one of your vendors goes down, is unable to provide you with the services or product that you do have a backup plan.
So Kathy, after building out the business continuity plans, what really is recommended is making sure that the plans are being tested, that employees and those employees with those critical responsibilities understand what the plan is all about.
The last thing we want to ever see or hear from an organization is, well, our plan is collecting dust in the cloud.
We want to make sure that they use, organizations use all different types of risks when they're testing their plan. So think about a risk where you lose a site that's a key manufacturing site.
Think of a situation where you lose key applications or key systems that help you run those critical processes.
Think of a scenario where you lose a third party and think of a scenario where you lose your people and a good example is COVID.
So how would you respond? Test that process that you've built out in that plan in a tabletop exercise, which is discussion based. It allows everyone to provide their insights to really discuss what their priorities would be, what their issues are, how they would respond from their particular functional area.
We recommend that organizations look at doing a tabletop exercise annually, taking into consideration, again, the wide range of risks that could impact their organization, making sure their plans will work.
Because there's one thing to have a plan, but there's another thing to have a plan that doesn't actually work. So make sure you practice because as we say, practice makes perfect.
Great points, Renata. Thank you. As they say, failure to prepare is preparing to fail.
At Marsh, we have reacted by developing a tech-enabled service which helps clients manage their supply chain risk.
To address both Nick and Renata's points on visibility and disruption preparedness, this service allows organizations to map their supply chain rapidly using AI and large-language models, and it also allows them to quantify the risk before deeply analyzing the risk to their supply chain, whether that's structural or climate.
On the topic of data and AI, now might be a good time to touch on the number one risk identified in the Global Risk Report, which was misinformation and disinformation.
This was ranked the number one risk in terms of severity over the next two years, and is joined by cyber insecurity and adverse outcomes of AI in the list of top 10 risks anticipated over the next 10 years.
So it's a cyber and technology, definitely a top concern and only exacerbating.
You sort of mentioned those key areas around misinformation, disinformation, and that's obviously referencing the general election due to occur over the next 12 months in countries ranging from Indonesia to the United Kingdom to India and the United States.
There's obviously some concern around AI, generative AI influencing that come of those elections, but then we obviously have the cyber threat, the malicious acts, whether they're attributed to organized crime or whether they're nation-state act.
And then finally, the emergence of AI inside organizations, whether that's used positively or whether it's going to have an impact on an organization.
And I think the reason I raised those three things, while they all seem slightly different and may have some linkages, I think from many boards and executive teams at the moment, it's been a rapid, rapid knowledge uptake for them coming from what was debatable,
but not that long ago, a reasonably stable digital environment for them.
They went about their business, they have very solid software as a service providers, and now we've moved into a world where we have significant disruption through ransomware.
We have nation-states participating in those attacks, makes it very difficult for organizations to defend themselves.
And then we obviously also have the rise of AI being used inside businesses and no governance around that risk.
So I think for a lot of businesses now, they're grappling with that digital picture.
They're very reliant on the digital environment to function.
And so I think what you'll find is that the digital aspect of risk will be looked at very, very closely.
And I actually would compare it to maybe the rise of health and safety.
If you go back a number of years, it was there, it was important, but then all of a sudden it became its own function within a business that had its own risk programs, its own resilience programs.
It had its own boards, some committee dedicated to it, and I think you'll find that will happen in the digital environment.
Well, a lot to consider.
What is quite apparent is the volume of complex risks we are facing and the fact that they are rapidly evolving.
Renato, where on earth do we start to ensure that we're resilient to these various challenges?
There's a lot of things that organizations can consider when building out their, you know, making sure that they're resilient, they're able to manage and respond to a crisis.
I think number one is really think about what are the risks? What are the current risks and forecast? Think about before we're thinking, you know, think outside the box.
What are some other risks that are emerging that could impact your organization?
You know, if you identify the areas that you could be vulnerable in, then you can start identifying what are those mitigation strategies.
How can you ensure that your organization is resilient by planning and preparing for things?
Again, the plans and procedures are very important.
You want to make sure that you formalize your processes so that if employee A, who's responsible for one very important critical process goes on vacation, that employee B, who is their backup, understands what to do.
So build up those processes, build up those plans.
You should have a plan for every layer, every level of your organization.
So from your C-suite, you should have a crisis management plan.
You should have support plans at the crisis communications level, at the ITDR level, at the cyber instant response level.
And then you should have emergency response plans, security plans, business continuity plans at your different site or location or functional levels.
Then once you've got the plans, again, as I mentioned earlier with tabletop exercises, I cannot stress the importance of that practice.
Building that muscle memory within your organization.
And then looking at identifying through those exercises, what are those blind spots?
What are those gaps that you may have?
I have seen organizations that have a resilience program that is 95% effective, but in an exercise, they still find a couple gaps or two.
That is normal and that is what we want to see.
You want to find those gaps, identify those gaps, and then make sure that you plug those gaps.
And then I think, again, learning, the other thing I like to stress is learn from best practices.
Look at other crises and take their lessons learned and make sure you build and adopt that into your resilience program.
I think in the end, it will make your organization stronger and resilient to any type of crisis.
Very good points, Renata.
And one point that I think I'd like to build on and which you mentioned is the importance of resilience programs being risk-admostic.
I think with one, again, traditionally, organizations have tried to develop playbooks around specific risks.
A lot of that has been predicated on past experiences, but we're very much moving into a rapidly changing world with a lot of interconnected risk.
And really, the resilience programs now need to be risk-admostic.
And by that, I mean, they're built in a way that they reflect an organization's current decision-making process.
We don't want to create a parallel decision-making process in times of crisis.
It's not the best time to try and drop one way of working and adopt another way of working.
We also don't want to be too prescriptive, so we need to make sure that the way that they make decisions are based on sets of values or priorities for the business.
Protection priorities, you could call it.
And that allows anyone, whether they are in the business, whatever part of the business they're representing, to make decisions in the best interests.
And they'll also allow them to be flexible about how a risk or a crisis is unfolding for that particular organization.
The other aspect that we've alluded to during the podcast is, and Kathy made a point earlier, is while it's great to have the executive team and the board across the response to a crisis,
we need to make sure that the people at all steps as it comes up through the organization are supported and trained and prepared to deal with any type of risk
and know that that escalation process is in place there to support them as they're making those decisions.
And once again, I'll go back to cyber ransomware response because I feel like that's been such a significant issue
and has such a big impact on the organization that there's been a lot of investment in the last couple of years in all the inside businesses
to make sure that where the incident originates, the decision making is sound, the support that goes around that, the training is all constantly adapted and updated and tested.
And then looking at the linkages between that and the layers above it as it moves up through business.
So when also not going for those big bang exercises that consume a lot of people's time and are really reliant on the people there at that time.
And we know business is a fluid and agile now and people move into other roles and leave organizations.
So I think the holy grail for resilience when it comes to response to events is it reflects the management structure of the business.
It's set in values and protection priorities. All parts of the escalation process are tested and supported.
And you do that in a frequency that's adapting to the current risk environment that the business is facing.
Thanks, Nick. There's a lot to process there.
So as we come to the end of the podcast, what would you really like our listeners to remember?
I think we've got to drop the old ways of doing it.
I think the business sort of running your strategy and your business direction separate from your risk program, separate from your resilience program.
And then hoping in times of crisis that all comes together magically, that's not going to happen anymore.
I think you really need to look at how a resilience program supports your day to day business and allows it to adapt and evolve irrespective of whatever crisis it made me facing
or whatever is happening existentially outside your business and that global impact on the way that you're operating.
Thanks, Nick. Now is definitely the time to start looking at your resilience now more than ever and taking that practice stance is super important.
Renata, what would you like our listeners to remember?
Thank you, Kathy. Yeah, I could talk for another 30 minutes, Kathy, but I won't do that.
Anyway, my just things I really would like the listeners to remember is, first of all, be proactive. Don't be reactive.
You want to get on top of the crisis before it gets on top of you. We don't have time anymore to have a slower response.
So be proactive. Think about things now before a crisis occurs. And then by being proactive, understand your risks.
Think outside the box. Think before we're thinking. And then once you understand your risks, make sure you have those plans and procedures in place.
Make sure you do training, not only for your response teams, but also for your employees. Make sure your employees are aware.
And make sure you conduct those annual table top exercises to build that muscle memory, because in the end it's about being resilient.
And I always like to quote Warren Buffett, as he always says, it takes an organization 20 years to build a reputation, but only five minutes to lose it.
If you as an organization think about that, you're going to do things a lot differently.
Thanks for that. That's a great point. I think there was a temptation to build big resilience programs, get leadership on board and get your exercising program in place overnight.
But I realized that there are going to be organizations with different levels of maturity when it comes to resilience.
So the takeaway that comes to my mind is that you should be using scenarios that are topical right now as a way to ride the wave, get the right people in the room,
and start the preparedness journey. How would I do that? I would maybe take the risk of supply chain disruption, get the stakeholders in a room and talk about how you prepare to mitigate that risk.
From that conversation and from that preparedness, you're likely to take lessons and build on your resilience and you're starting your journey from that point on.
So I would say start small, start specific and start with something that's important to the business today.
And that's all for this edition of Risk in Context. We hope you enjoyed our discussion and thank you for listening.
You can rate, review and subscribe to Risk in Context on Apple Podcasts or any other app that you're using.
You can also follow Marsh on LinkedIn or X.
In addition to our podcast feed, you can find more episodes of Risk in Context and more insights from Marsh on our website marsh.com.
Until next time, thanks for listening.
[BLANK_AUDIO]
Podcast Summary
Key Points:
The need for organizations to build structured, agile, and holistic resilience functions is emphasized.
Organizations are urged to focus on building strong resilience strategies to prepare for emerging risks like supply chain disruption and AI.
The importance of leadership in building a resilient organization, with a focus on business continuity plans and testing for supply chain resilience.
Supply chain risk is highlighted as a key concern, with factors such as extreme weather events, geopolitical aspects, and modern slavery impacting supply chains.
The significance of addressing risks related to misinformation, disinformation, cyber insecurity, and adverse outcomes of AI is underscored.
Summary:
The transcription features discussions on the importance of building resilience in organizations to combat various risks. It stresses the need for structured and agile resilience functions in the face of global crises and interconnected risks. Emphasis is placed on leadership's role in fostering resilience, particularly in addressing supply chain risks like extreme weather events and geopolitical disruptions.
The text also highlights the evolving challenges posed by misinformation, cyber insecurity, and adverse AI outcomes. Overall, the importance of proactive risk identification, robust mitigation strategies, and comprehensive testing of business continuity plans is emphasized to ensure organizational resilience in the current complex and rapidly evolving risk landscape.
FAQs
Resilience is crucial for organizations to withstand the impact of known, emerging, and evolving risks by building structured, agile, and holistic resilience functions.
Organizations are shifting from traditional crisis management approaches to linking strategy with risk and resilience, conducting continuous scenario exercises, and integrating resilience into all aspects of the business.
Leadership plays a critical role in aligning and integrating the entire organization to ensure resilience from top-level strategic decisions to operational preparedness.
Supply chain disruption poses a significant risk to organizations due to factors such as extreme weather events, geopolitical issues, modern slavery concerns, and digital vulnerabilities.
Organizations can enhance supply chain resilience by identifying dependencies, developing backup strategies for vendors, testing business continuity plans through tabletop exercises, and integrating tech-enabled solutions for risk management.
Top risks include misinformation and disinformation, cyber insecurity, and adverse outcomes of AI, highlighting the increasing concerns around cyber threats, technology risks, and the impact on global events like elections.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.