Showing posts with label BC events. Show all posts
Showing posts with label BC events. Show all posts

Tuesday, 24 May 2016

IX Business Continuity International Conference

by Jorge García Carnicero


As every year, BSI has been the promotor of the Business Continiuty International Conference, in its IX edition. The place that has been chosen this year was the Gran Melia Fénix Hotel, in Madrid, where the conference took place at first hour of the morning. In a room almost full, with 50 or 60 people, BSI shows that their ability for calling business continuity professional is healthy.

The first speech was driven by Jose Luis Miguel, Country Manager at BSI, that was exposing the BSI capabilities in both generating standards and auditing and in training. Then, he presented the results of the Horizon Scan Report 2016, led by the BCI and promoted by BSI, highlighting aspects such as the top ten threats of continuity, which can be seen in the image or the percentage of companies seeking to increase its budget business continuity for the coming months / years .


The second speech was done by Julio San Jose, from EY, in tandem with Cristina Pereira, continuity responsable at Abanca. Julio emphasize about the key aspects related with continuity:

  • Need of deploying tests and drills.
  • The importance of crisis communication.

He comment aspects as the different estrategias of communications that existe (in a good or a bad way): Silence, Negation, Responsability transference, Confession and controlled discretion, been Confession the best communication strategy.
(I would call it Transparency)

Cristina Pereira exposed the case of Abanca, commenting the different problems with which she has been to deal with when deploying the Business Continuity Plan in the organization. In the same direction than Julio’s speech, she also emphasized the importance of drills.

Before the break, took place the third speech carried out by Agustin Lopez, as representative of DRI in Spain. Agustin exposed the different contingency scenarios in the datacenter with an original presentation, using classical films as a thread (back to the future, Groundhog Day, etc)

When the Confee Break and Networking moment finish, we come back to the room, in which GMV was responsible for the fourth speech in the morning. It was based on the business continuity management system (ISO 22301) and the possibility of integration with other management systems standards, like security (27000), IT Management (20000), quality (9000), etc, with an orientation to certification.

The fifth speech was performed by Uxía Fernandez, from Grupo Ozona. Uxia expose the concept of IRBC (ICT Readiness for Business Continuity) that is used in the standard 27031. Uxia expose the content of the standard with the 5 mainstays as a elements to protect: Facilities, technology, people, data, providers and process. Since usually only technology and data was taken into account, Uxia would like to make special consideration about the other elements. It was a long speech.

Finally, the sixth speech was done by Ricardo Mesias, Risk Management Director at EDP. Ricardo made a speech showing the main problems that he had to deal with in developing the business continuity plan in EDP. He talk about the team, about achieve the complicity of all departments of the company, about the importance of test, about the metrics and about the external support, which is always important.

Conclusion

As a conclusion, I think that the role of BSI maintaining this event year after year is laudable and all the business continuity professional should be thankful about that. This event is a meeting point and is also a way to measure the state of the art of business continuity in spain.

However,  I think that messages has to be improve, since many of them are not showing the actual situation of customers. Recently I was reading an article of Amy DeMartine, senior analyst research in Forrester research for Devops, for Computer World that I think is applicable in Business Continuity. She said: “I think the reason why a lot of companies start with DevOps activities and forget the security staff is that there is a cultural gap. Security people speak a language almost different - incidents, vulnerabilities, risks - , so everybody put them at the end of the development life cycle”. This could be applicant also to business Continuity, that should be included in all the processes of the company but, however, it’s not, at least in Spain. If we focus on the management system and we forget that continuity should be practical it will drive us to see Business Continuity as a waste instead of an investment.  

Recently has took place the Business Continuity Awareness Week, led by the BCI, with a main objective: to show the ROI of the continuity and I think we should learn about int.
Although obviously, BIS as a promotor of the event has to focus speech on management systems, is urgent and essential to update the messages to a market reality different, mainly in the IT area.  It makes no sense to talk about take a tape out of the datacenter when all companies are talking about backup in the cloud, making a third copy in a public cloud, for example.

Friday, 27 September 2013

Conference AENOR-Continuam: Business Continuity Management

By Moises Lopez Soto


Last Friday, 27th of September, has taken place a conference about Business Continuity Management: ISO22301, promoted and organized by AENOR and Continuam with a high success of attendance and a great level of lectures. There has been perhaps for the first time that there were people of a great variety of industries, like Telcom such as Telefonica, energy companies like Iberdrola, or transport, represented by the Municipal Transport Company of Madrid (EMT).


Although this pot is not intended to be a wide summary of the session and there will probably be a lot of details not covered, I’d like to make widely known the event and some points that were covered by the different experts invited.

The session started with the exposition of the content and scope by Mr. José Luis Tejera, business development director of AENOR, who made a review about the different security standards and who made the first reference to an issue that was emphasized in the lectures after him: it’s really necessary to collaborate with supply chain, that is providers, because of the dependences on them.

After that, a round table was established about Regulation and Certification, in which there were reviewed different contents of ISO 22301 by Mr. Tomas Marín Iñurrieta, chief of Regultations service and Coordination of CNPIC, and Mr. Carlos Manuel Fernández Sánchez, Business Development TIC manager of AENOR, who emphasizes about the importance of deploying business continuity system instead of certificate it, although certification requires you to keep your deployment up to date.

Mr Juan José Miguez Iglesias, technology risks associate of PwC, contribute with the experience of PwC in Business Continuity consultancy, defining a four phases methodology (Document review, BCMS gap analysis, verification and tests and support to audit process) with which they intend to cover most of their customer requirements for deployment of BCMS. PwC metohodology also can include fast track actions, with which they will test in a first approach through a role play the knowledge and maturity of the company take this test as a starting point and developing the plans and procedures in a second approach. This combines Latin character (based in improvisation) with Anglo-Saxon character (based in procedures).

Closing this first round table, Cristo Perez, Busines Continuity Manager of Sanitas, made a presentation of the pocess follow by Sanitas for deployment and certification of BCMS, showing an example of a DRP evolution since it was not enough to cover the varity of scenarios typically included as Business Continuity scope. He used two examples: thread of terrosit attack in Campo de las Naciones, that caused a unavailability scenario and Aviar flu. As a resasault their have a global management system in which they include the business decision makers and, over all, that put People as cornerstone of all system.

In the second part of the session, Mr. Cesar Perez Chirions, President of Continuam, and Ms Maria Parga, general director assessor of BME-INNOVA and vicepresident of Cotinuam, made a presentation about the “Instituto de continuidad de negocio” and about their objective of connect professionals who want to share their knowledge and try to to make widely known and promote Business Continuity activities.
Closing the session, there toke place a second round table with the following professionals:
  • Mr. Manuel Carpio Cámara, Information Security and Fraud Prevention director in Telefonica, who apart from giving information about specific cases and present the global BCM structure of such a big company, made his particular vision of BCM, with two dimensions: a vertical dimension with BCMS and a horizontal dimension which put together particular requirments). He also expose the way they support the different BCM plans of each telco belonging  to Telefonica Group through SUNGARD BCM tool in DRASS model. I would like make two highlights of his lecture: The phrase “Continuity is NOT an option” and Event Correlation, which can bring information about where is anybody at any time during an incident.
  • Mr. Ángel Robles Rodríguez, Deputy lawyerd at EMT, presented how from his organization they have to think on buses as if they was an employee.
  • Mr. Pedro Pablo, Security, privacy and Global Continiuty Manager of RSI, talk about necessity of reinforce supply chain and make emphasis in problem trying to grant the service level agreed with providers, especially with big ones.
  • Mr. Javier García Carmona, responable of information security and communications in Iberdrola, was the autor of an other phrase that I consider it a great phrase: “In Spain there is not Business Continuity Culture”. Apart from that he sent a calming message about Spanish electric infrastructure, considered one of the critical infrastructures.
  • Mr Roberto Rodriguez, Business Continuity Director in Grupo Santander, made an exposition remarking the  value of test as a way establish automatism responses to a contingency and serving as a catalyst that avoid the potential shock of personal selected to answer the incident because of the type of crises that could be close to their environment, or because of their own character and their ability to answer to a contingency, being critical to the success to the Business Contintuity program the election of this people and we do not usually pay to much attention to this.
  • Mr Victor Llorente, bussiness consultor at Grupo SIA, go into detail about the need of support Business Continuity programs in tools that allow the automation of BCMS processes.
The closing lecture was carrying out by Mr Avelino Brito, general director at AENOR, who toured the organization and put into relevance the meaning of AENOR as a unifying knowledge organization.

In general terms, I feel has been an interesting event, which highlights the progress in Business Continuity industry. Business Continuity professionals begin to look for strengths and obtain resilience, ensuring not only our internal capabilities but also the dependencies by third parties. This requires focus much more towards people, towards their responsiveness, to heard and given the capacity of business decision makers as opposed to the old IT disposal. And all this is done under a global international framework, which is ISO22301 in which to look and be bound to improve.

Sunday, 24 March 2013

Conference SIA - Continuam. Summary

With a relevant number of attendees, about 100 people, last 20th of March took place a conference sponsored by SIA Group and Continuam in which there were given an overview of the different activities that are taking place within the sector. The conference took place in the restaurant Loft39, at C/Velazquez in Madrid, calling for assistants at 12:00 and elongating until 16:00.

Introduction to the conference was provided by Enrique Palomares, CEO of SIA Group, who highlighted the commitment of this company for business continuity and the path along the last years, with both services consulting and automation tools, with SunGard AS.

First lecture was given by Daniel Blanco, BCM consultant at SIA Group. Under the title “Continuity, state of the art” Daniel gave an overview of the various standards and their evolution over time. He identified the main differences between BS25999-2 and ISO 22301 and highlighted the relevance of training and drills, specifically to provide visibility to the rest of the organization.

After Daniel, Juan Manuel Gil, CEO of F24, continued putting in value the relevance of notifications and how this notifications should change from traditional models (calls, SMS, emails, etc) to latest channels, dependent on the resources available for the employees of the organization.
In the third lecture Alfonso Costa, BCM Manager of Mutua Madrileña, stated which, from his point of view, are the cornerstones of business continuity within an organization:
  • Alignment of objectives, mission and vision. The strategy of the organization must be aligned with the continuity management program.
  • Governance model. Management should be involved. It is important to have a good sponsor.
  • Visibility: must publicize the work done since continuity areas. You have to "come out". Testing is the largest showcase of business continuity
  • Report: The record of what is becoming essential to show activity.
Then Pablo de Vera and Luis Sancho exposed the management structure of the business continuity used in BBVA, providing continuity of different committees depending on the severity of the incidents that occur: corporate continuity committee, country continuity committee and plan continuity committee. They gave a clear message which is the aim of his plans to ensure the service that BBVA provides to their customers and, therefore, their business.
 
Luis made it clear what is and is not a contingency BBVA, going more in detail about different scenarios to which BBVA had faced in recent years: pickets impeding access to a center, Hurricane Katrina and Ike, fire "neighbor" in the Windsor building, falling bank communications, critical power drop, the Icelandic volcano ash, etc..
 
To conclude the presentations, Tomas Martin, from CNPIC, outlined the activities being developed as a national critical infrastructure center, in collaboration with other European bodies: BUCOPCI standard, workgroup with AENOR, Smart grids: Spanish industrial safety platform, collaboration with coesga, among others.
 
To round off the event, it took place a panel discussion, moderated by Cesar Perez Chirinos (Continuam president) in which there was in an interesting representation: CNPIC, Bank of Spain, RSI, BSI, AENOR, Arsys and SIA. Cesar was moderating the table with different speakers that were answering the questions and gave their views on business continuity.
 
As a conclusion, the event was very well organized by SIA. Perhaps the time of lectures was extended in excess, but the speakers transmitted very pragmatic views, changing the discourse of IT by business discourse, closest to a comprehensive understanding of business continuity. The BC industry is maturing every day in Spain.

Sunday, 20 January 2013

Crisis management in Madrid Arena party


There has been a lot of information about Madrid Arena Halloween party, in which four women was killed in a stampede. Most of this information is related to political responsabilities, but there are an issue that has gone unnoticed and I think there Is very important from business continuity perspective. It’s  the role played  by mobile communications in whole crisis.

According to the testimony of the participants, it seems that there were a mobile communications breakdown, mainly due to the great amount of people in such a small space. It similar to what happen in a sport event with huge crowds, for example a football match each weekend or to what happened last year in the Mobile World Conference in Barcelona. 

However, when this situation occurs in crisis scenarios we have  two problems:

  • Those affected cannot communicate or make emergency calls
  • Emergency teams cannot communicate with each other in order coordinate if this communications depend on the mobile generic infrastructure. 

In order to avoid this kind of situations, there are two options: make the service stronger or use an alternative service.

Thinking on the attendees, there could be explored the possibility of providing an alternative coverage (wifi network). With such a large crowd, it will probably has the same problem than the generic mobile infrastructure, but it will not be dependent on a mobile operator and could be offered as an aggregated service to the whole infrastructure.

There are mobile cells to allow operators improve mobile coverage in special locations, moreover, there are companies focused on offer coverage in public locations with a large crowds, for example Spring.

However, although could be technical solutions to avoid this kind of situations, neither facilities responsible will include wifi service, nor mobile operators will strengthen coberage in an altruistic way.  Government should include this as a requirement for license this kind of events with the guarantee that mobile communications will be delivered.

On the other hand, in order to allow the communications between members of emergency teams they use the RF network, Tetra. This network were not working because the walls were of concrete, so emergency staff had to use they own personal mobiles to allow the communications with other members. This situation is complicate to avoid without valuing the architectural problems of the building.

A good practice could be to advise the attendees about the problem that they could have when using their mobiles, specially when the location are not prepared to host a very huge crowd, form example in public demonstrations. Generalitat of Catalunya do it every year when is near the day of National Day of Catalunya.

Thursday, 1 November 2012

In a desaster like the one in New York, Can we be prepared?

Colaboration by Moises Lopez Business Continuity Consultant at Grupo SIA
From my point of view, except multinational companies with a global and diversificated market which don’t depend on one or two locations, in disaster like this one very few companies can resist.
When identifying resources required to business continuity, every organization can estimate the amount of resources they will need to assure their resilience for each activity. Having a deeply look into some of the main resources supporting business, can find:
  • People: welfare has to be a priority and, in this case, forecast and advertising is an advantage to assure their safety. Except emergency services, nobody should be in their jobs, moreover, in this case there has been some victims.
With city paralyzed and employees only available in their houses, Will only technology support all the business? Are workforce prepared to develop their activities when their city is under emergency?
  • Technology: with power outages and floods, it’s very difficult to maintain a adequate service level, even if our IT infrastructures are based in Cloud. Even more, Can we assure that our employees’ communication provider will still deliver services in this scenario?
  • Providers: We can have the most restrictive service level agreement that, in this scenario will be wet paper. Moreover, we can have back up providers, but Can they will deliver the service in a proper way?  Can they deliver services even in scenarios in which we can’t?
  • Locations: When city is not available, Will our facilities be available?
We can have a business continuity plan, with a communications plan properly defined, the response and emergency procedures also established,  even we could have decided to establish our backup datacenter in other city, but our budget and technology could be enough to put it in New Jersey, for example,… If despite all this measures we cannot restore our business, then we can only hope the help of the government or pay of insurance premium.
As a conclusión, if the scope of unavailability is as big as our city and around, it will be time to start from the beginning.. or  Would be realistic to consider as an scenario in our plan about “unavailability of the whole city”, if the city is our main operation center?  How many companies in Spain would be able to assure it resilience in such a big disaster situation? 

Monday, 22 October 2012

Healthcare service continuity

Blackout taken place in Fundación Jimenez Diaz hospital , last 16th of October in Madrid is a good example to realize that there is not necessary great disasters or disruption  to activate Business Continuity Plans.
Although we have not too much information about this incident, it can be clearely indenfied two tradicional continuity measures:
  • Power generators activation, to support critical systems
  • Redirection of new admissions to other hospitals, in this case the Hospital Clínico.
When we are talking about a hospital, such as I discuss in my previous post components supporting business, this service is so critical that  availability of all components supporting the service has to be granted, that is, facilities, suppliers, medical staff or information technology. Impact caused by lack of service is simply unaffordable because the life of patients is in play.

However, the incident occurred in Jimenez Diaz Hospital must make us think about if our health system is really prepared for emergency situation or disasters when hospitals are affected. 2004 terrorist attacks in Madrid realized that the emergency agency are prepared to deal with such a great disaster, but What would happen if the own hospitals were affected by the disaster?

In a hospital there are a lot of diverse healthcare services, with different criticalities: emergencies, maternity, hospitalization, operating rooms, doctor appointments, radiology,.... Strategies must be different depending on this criticality. For example, a pediatric appointment could be delayed or redirected to other hospital, but a serious patient that has to go through surgery or with dependation of ventilation can no be unattended and any delay can be fatal.

Having a look abroad, for example to United States, hospitals has a global framework since lasts 80s, called HICS (Hospital Incident Command System). This framework identifies different issues to be taken into account to assure healthcare service. HICS was born as a emergency specific framework (HEICS), but it nowadays is a system for use in both emergency and non-emergency situations. George W Bush govern created in 2003 a global framework to manage incidentes (NICS) and this caused a new revision or HICS which is the last version (version V).

About content, HICS identifies five management functions hat has to be defined in the hospital to manage incidentes:
  • Incident Command, set by different responsibles of safety, liaison and public information officers and the global responsible
  • Operations section concuct ths tactical operations.
  • Logistics Section: provides required resources to achived operational objectives.
  • Planning Section: Collects information about the incident, maintain resource status and infomration for reports and prepares documents, such as incident plan.
  • Finance and Administration Section: Monitors costs related to the incident and provides accounting, procurement, time recording, and cost analyses
The most important advantange of HICS is provides a common terminology and position titles to enhance standardization among agencies and responders

In Spain, with healthcare service tranferred to Autonomous Comunities and with the actual economic crisis it seems that this kind of initiatives are not a priority, altough from my point of view is an interesting tasks for CNPIC. At the end of the day hospitals should be considered critical infrastructure.

Saturday, 29 September 2012

Conference "CONTINUIDAD DE NEGOCIO 2012"


Contribution by Daniel Blanco Business Continuity Consultancy Solutions Coordinator at Grupo SIA.

Last 26th of september was pleased to attend the conference "CONTINUIDAD DE NEGOCIO 2012" (Bussiness Continuity 2012) in Madrid, organized by Fundación DINTEL in colaboration with continuam and INTECO
In the conference there were invited different lectures as BBVA, Banesto, AccionaMinister of Defensa, Adif, Aena, Bankinter or EMT. The schedule can be seen in the followin link at Fundación DINTEL:
http://www.dintel.org/index.php?option=com_content&view=article&id=216&Itemid=312

Lectures were divided into two blocks, with different presentation models. In the morning, presentations about cases of success and experiences in Security and Business Continuity Management in their organizations were done by speakers speakers; in the evening took place a colloquium in which speakers answer questions done by a moderator. 
Better than describe in deep each lecture, I'd like to highlight some relevant messages and topics commented  repeatedly during the day:
  1. Although there are still points of view in which business continuity is treated as a part of information security, this time there were presented as a independent discipline that complements information security and that, in conjunction with risk management, deliver resilience to organizations
  2. Awareness and Management Commitment are important points not achieved in Spain nowadays and is necessary and essential. Business continuity plans or crisis management training and drills were presented as one of the most important ways to deal with the objective.
  3. There is not enough with having a business continuity plan or a crisis management plan in which an organization critical business process recovery were defined, other actors like police, emergencies support, government and critical providers have to be taken into account in order to get the minimum level of operation after a disruption. Without internal and external support no organizations can recover their business.
  4. The Spanish Critial Infraestructures Protecction Law were presented as an inflexion point that can bring the development of a industrie collaborative framework and allow to have sectorial strategic plans in Spain. Moreover, this can be a energizer of the three point described bellow.
As a conclusion, from my point of view, different lectures of the conference were in the right way: defining business continuity issues, resilience, economic sustainability and not only IT or Information Security. Nevertheless, we have still a long way to achieve what was defined in the second point: management has to commit and promote business continuity activities. As as sign I can point out that most of people attending the conference were chief of IT or were part of the structures of IT in companies.

Tuesday, 25 September 2012

Sabotage

Yesterday, talking with the chief of Business Continuity consultancy in one of the main companies of the industry in Spain, we have doubts about if the case of sabotage in the power infrastructure in Rayo Vallecano's stadium should be consider as a scenario in Business Continuity plans.

La falta de luz obligó a aplazar el choque que debían disputar Rayo Vallecano y Real Madrid.On the one hand, it could be clear that a scenario of lack of power, no matter the origin, must be included in BC plans. Measures to assure power are very common: generators, two power providers, etc.

On the other hand, the sabotage in football match between Rayo Vallecano - Real Madrid has two special considerations:
  • The stadium must be available at a specific time and during a relatively short period (2 hours)  There is not possibility to play the match in other stadium - it would be impossible to move 15.000 - and it's not possible to play at other time, since the main business to be continued is the is the television retransmission.
  • Internal electrical infraestructure were damaged, so there is no way to use an alternative infrastructure. It has to be repaired.
Since Business Continuity has to focus on moments after an events occurs, and the plans covers the actions to be taken on this moments, its seems to be difficult that the staff of Rayo Vallecano could done something different if they would have a Business Continuity plan. Traditional measures would be not effective in this scenario because it was damaged the internal infrastructure. So this scenario is only useful to analyze risks and define the mitigation measures.

In general terms, when business depends on somebody doing something in a certain location, business continuity plans doesn't help too much: It's not possible to change actors, location or time, so we can only make a good risk analysis and try to mitigate it as far as we can.

Friday, 25 May 2012

5th Business Continuity International Conference

As every year, and this is the 5th, last Tuesday 22th in Madrid and Wednesday 23th in Barcelona has taken place the 5th Business Continuity International Conference by BSi, this year with the new standard ISO 22301 being launched.  Following I summarize the event with a little description of each lecture of the conference in Madrid, to which I had the pleasure of attending.
With an attendance of more than 150 people from different industries, the maximum capacity was practically cover.
 
  • Introduction and welcome by Marcio Viergas (BSi general director). Provides the general definitions of an ISO standard, the different committees and how BSi, as a standard developer, has historically contributed with a lot of norms developments that has became international standards. ISO 22301 is called to be an important international reference and is predicted to be a boost for the industry and, seeing the attendees to the conference, looks set to become a reality.
  • From BS25999 to ISO 22301 - Business Continuity Management by Agustín Lerma (BCM Product Manager at BSi) Agustín provides in general terms the content of the standard and the correspondence with the Demming cicle, which is mainly the following :
Plan
4. Context of the organization
5. Leadership
6. Planning
7.Support
Do
8. Operation
Check
9. Performance Evaluation
Act
10. Improvement
    Agustín also define the alignment of the standard with  Guide ISO 83, about standard structure, PAS 99 about management systems and ISO 31.000 related with risk analysis.
    • The new International Standard for Business Continuity: ISO 22301. Dave Austin (member or ISO committee for standard 22301 development) Dave exposed deeply the standard, in some points overlapping with Agustín lecture. Highlighting the following points:
      • Standard is equivalent to BS 25999-2,  so the schema will be completed when ISO 22313 were published. Its publication is scheduled for next year.
      • There are a new concept MBCO (Minimum Business Continuity Objective)
      • Legal requirement specific for each country are included.
      • Risk evaluation is aligned with ISO 31000
      • Strategy had some shortages in BS25999, in the new standard it has a better definition, proposing the identification to reduce probability and impact, RTOs definition, resources needs and actions to protection and mitigation requirements compliance.
      • Incident communication: is much more complete and gives more importance. A better integration with emergency system is proposed.
    • Business Continiuty Management  end to end. Fernando Picatostes (Deloitte) The lecture was based on Deloitte business continuity methodology, focused in risk too much. Incidents in which Deloitte was involved some years ago (Windsor building and Twin Towers) were mentioned, as usual.
    • Crisis management and Business Continuity. Andrés Gonzalez (Near Technologies) made a review of the main security and business continuity incidents occurred lately and lesson learned for each one: Twin Towers, Tepco in Japan, Spanair MD-82, etc. The "prezi"ntation can be viewed here
    • Risk Management ISO 31000 and integration with new ISO 22301. Angel Escorial (AGERS) After a description of what Asociación Española de Gerencia de Riesgos y Seguros is, Angel make a deep review of the standard 31000 and the contrast between this standard and ISO 22301. From a personal point of view, the lecture was very interesting and I highlight a phrase: Risk management works with impact, while BC management works with time and impact. If we think on continuity as risk management, I think is not the better approach, aligned with the tittle of this blog.
    • Business case of Telefónica UK in Business Continuity. David Clarke (Telefonica O2) With on of the most complex business continuity management, David expose the long way he have to walk before the certification. From the lecture I highlight the benefits of implementing the BCM, what I think is key for every BCM system:
      • Increase trust from customers, partners and third parties.
      • Ability to work with suppliers to build continuity strategies
      • Industry recognition
    • Experts colloquium- Workshop about new standard ISO 22301. Julio San Jose (Bankinter), Fernando Picatostes (Deloitte), Andrés Gonzalez (Near Tech.). Moderator: Marcio Viegas. Due to agenda problems, I cannot attend this interesting colloquium.
    Conclusions
    With a great attendee, the event shows the general interest in Business Continuity from the different Spanish companies and organization. Furthermore, the fact that ISO 22301 has been launched do foresee that the directors interest in BC will rise.
    From an organizational point of view, once again, congratulate BSi by the professionalism with which held both the call as the event itself (Congratulations Patricia, Silvia, Beln and company)
    About contents, I think that attendees general feeling was they were poor, mainly those from BC service providers.