Download - Horizon Scan 2016
BCI Horizon Scan 2016Andrew Scott CBCI
Senior Communications ManagerBusiness Continuity Institute
About the BCI
• Membership• 8,000 members• Students -> Fellows• 40% in the UK
• Partnership• 120 organizations
About the BCI
• Training & certification• 1,300 new business
continuity professionals are certified each year
About the BCI
• Research
About the BCI
• Research
Why horizon scan?
• To assess the threats• To address the impact
“The best-laid schemes o' mice an' men gang aft agley”
Black Swan Theory
1. Fooled by Randomness (2001)
2. The Black Swan: The Impact of the Highly Improbable (2007)
Nassim Nicholas Taleb
• The event is a surprise• The event has a major
impact• In hindsight it could have
been predicted
About the BCI Horizon Scan 2016 Survey
568 74organizations countries
2012 2013 2014 2015 20160
10
20
30
40
50
60
Level of concern - percentage
Concerned Extremely concerned
2012 2013 2014 2015 201612345678
Level of concern - ranking
No. 5 threat:Security incident
2012 2013 2014 2015 20160
10
20
30
40
50
60
Level of concern - percentage
Concerned Extremely concerned
2012 2013 2014 2015 20161
3
5
7
9
11
Level of concern - ranking
No. 4 threat:Act of terror
2012 2013 2014 2015 20160
102030405060708090
Level of concern - percentage
Concerned Extremely concerned
2012 2013 2014 2015 20161
2
3
4
Level of concern - ranking
No. 3 threat:IT/telecoms outage
2012 2013 2014 2015 20160
102030405060708090
Level of concern - percentage
Concerned Extremely concerned
2012 2013 2014 2015 20161
2
3
4
Level of concern - ranking
No. 2 threat:Data breach
2012 2013 2014 2015 20160
102030405060708090
Level of concern - percentage
Concerned Extremely concerned
2012 2013 2014 2015 20161
2
3
4
Level of concern - ranking
No. 1 threat:Cyber attack
What does this mean?
• Are cyber attacks the most likely disruption?
• Will a cyber attack have the biggest impact?
• The BCI Horizon Scan Report sets the baseline.
• Every organization must conduct their own horizon scan.
Tracking threats
• Appears in the top 10 for the first time since the survey began
5
Availability of keytalents or skills
(14th to 9th)
Tracking threats
• Almost three-quarters of organizations (74%) report at least 1 disruption/year*
• 14% claim losses of at least €1 million*
2
Supply chain disruption(5th to 7th)
*BCI Supply Chain Resilience Report 2015
Tracking threats
5
Human illness(8th to 13th)
• Ebola no longer the threat it once was
Top 5 trends
Further analysis - location
• Europe mirrors global view• Adverse weather top threat in Central/Latin
America• Interruption to utility supply top threat in Sub-
Saharan Africa• Political change a growing concern for Middle East
& North Africa, Central/Latin America and Sub-Saharan Africa
Further analysis - sector
• Supply chain disruption the top threat in the manufacturing industry
• IT/telecoms outage the top threat in health and social care. Emergence of a global pandemic the top trend to watch out for
• New regulations and increased regulatory scrutiny the top threat in the finance and IT/telecoms industries
• Political change the top trend in education
Further analysis - size
• Very little difference between SMEs and large businesses
• Loss of key employee more of an issue for SMEs• New regulations more of an issue for large
businesses
Conducting trend analysis
70% of organisations conduct trend analysis to betterunderstand threats, a slight decline from 73% last year.
Use of trend analysis in informing BCM
A third (33%) DO NOT use trend analysis to guideBCM programmes, a figure unchanged from last year’s.
Level of BC investment
There is a slight increase in organizations reportingmore investments in BC (23% to 24%).
Key takeaways
• Cyber issues continue to dominate the threat landscape although physical security incidents are seen as a growing concern for many professionals.
Key takeaways
• The ‘human factor’ (i.e. skills shortage, loss of key employees) clearly impacts on business performance and requires a strategic response.
Key takeaways
• Access to important data (e.g. trend analysis results) remains a barrier for many organizations which impairs resilience.
Questions?