<?xml version="1.0" encoding="UTF-8" standalone="yes"?>



	
	
			
			
		<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/">
		
		<channel>
		
			<title>Demos Project : The Business of Resilience</title>
			
			<link>http://www.demos.co.uk/projects/thebusinessofresilience/</link>
			<language>en-us</language>
			<copyright>Copyright 2008</copyright>
			<pubDate>Fri, 21 Nov 2008 19:28:16 UT</pubDate>
						
			<description>Latest items from The Business of Resilience on http://www.demos.co.uk/ - the thinktank for everyday democracy</description>
			

			
			<lastBuildDate>Fri, 21 Nov 2008 19:28:16 UT</lastBuildDate>


			
		
		
		
		
	
	<item>
		<title>Remarks at the Launch of &amp;apos;The Business of Resilience&amp;apos;</title>
		<link>http://www.demos.co.uk/items/7146</link>
		<description><![CDATA[Philip Broadley of The Prudential made the following speech at the launch of Demos&amp;apos; report, &amp;quot;The Business of Resilience&amp;quot; at the Prudential Building on 29 June 2006: &amp;quot;Charles Darwin, the noted writer on security matters, wrote &amp;quot;it is not the strongest of the species that survive, nor the most intelligent, but the one most responsive to change&amp;quot;. When security is part of the daily rhythm and routine of a business that business is better able to respond to unexpected... ( from BlogPosts )]]></description>
		<guid isPermaLink="false">http://www.demos.co.uk/items/7146</guid>
		<content:encoded>
		
			<![CDATA[Philip Broadley of The Prudential made the following speech at the launch of Demos' report, <span style="font-style: italic;">The Business of Resilience</span> at the Prudential Building on 29 June 2006:<br /><br />&quot;Charles Darwin, the noted writer on security matters, wrote 'it is not the strongest of the species that survive, nor the most intelligent, but the one most responsive to change'.<p style="text-align: justify; line-height: 200%;" class="MsoNormal"><!--[if !supportEmptyParas]--> <o:p></o:p></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">When security is part of the daily rhythm and routine of a business that business is better able to respond to unexpected events, to manage its way through change and - most importantly - be able to take decisive action with confidence in its capacity to manage the intended and unintended outcomes, having previously thought carefully about the risks involved.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal"><!--[if !supportEmptyParas]--> <o:p></o:p></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">I will come back later to security being part of daily rhythm and routine.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Before that I want to address some of the questions that are posed by the launch today of the Demos report - The Business of Resilience.<span style="">&nbsp; </span>The report advocates a specific approach to security - as a management function - rather than a responsive and defensive approach which it suggests is still common across the business community, I agree with this view.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">I would like to talk about the value that we place on security in Prudential; offer some views as to how security can play a role in business development; and what Boards should look for in their Head of Security.<span style="">&nbsp; </span>Finally, and most ambitiously, I will try to offer some views about measuring success.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">So what value do we place on security?</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">I joined Prudential six years ago as Finance Director from one of the Big Four accounting firms.<span style="">&nbsp; </span>It would be overstating it to say that I had never heard of group security functions but I had certainly never worked with them directly.<span style="">&nbsp; </span>This gave me the benefit of no preconceived ideas and when after about a year it was suggested I take on responsibility for Group security from a retiring director I was very keen to do so.<span style="">&nbsp; </span>To me it seemed integral to my agenda covering as it does such topics as governance, reputation, resilience and cost containment.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">First, governance.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">There is a growing recognition that effective security management is an essential part of good corporate governance.<span style="">&nbsp; </span>This is especially true I think for the financial services sector which is so highly regulated and where we now have a capital charge for operational risk.<span style="">&nbsp; </span>We operate a model here that we call three lines of defence, others use it too.<span style="">&nbsp; </span>Controls are embedded into processes as a first line of defence; we have a committee structure and other monitoring controls as a second line of defence and thirdly we have internal audit whose role it is to examine the operation of the first two lines.<span style="">&nbsp; </span>Security's role is to ensure that appropriate controls are embedded in the first line of defence, to participate actively in the monitoring in line two, by membership of GORC for example.<span style="">&nbsp; </span>Unusually, and in exceptional circumstances, I would also see security as having a role in line three.<span style="">&nbsp; </span>In response to serious accusations raised against senior management as part of our internal whistle blowing procedures it would likely be Group Security that would be charged with the task of investigation.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Secondly some words on reputation.<span style="">&nbsp; </span>A relationship between effective security management and reputation is well understood and works in a number of ways.<span style="">&nbsp; </span>Badly handled security that is not cognisant of local sensitivities has been shown to damage reputation time and time again.<span style="">&nbsp; </span>Secondly, poorly managed security incidents can escalate quickly and damage a company's reputation with stakeholders and shareholders.<span style="">&nbsp; </span>The incidents themselves are not necessarily damaging - many studies have shown that companies fare better after an incident if they handle it well as it reassures shareholders of the quality of the company's senior management.<span style="">&nbsp; </span>Certainly one of the things that I am very proud of is the way we have managed our response to natural events.<span style="">&nbsp; </span>We have had operations in California affected by forest fires and in Florida many times by hurricanes in recent years.<span style="">&nbsp; </span>Our customers will however never have known that we were operating under contingency plans.<span style="">&nbsp; </span>That is to me a measure of success.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Next resilience.<span style="">&nbsp; </span>The role of security is not just to protect a company from threats whether they be generated by natural events, terrorism or organised crime.<span style="">&nbsp; </span>Properly integrated and proactive security can increase a company's resilience to change more generally.<span style="">&nbsp; </span>The processes and approaches that underpin effective security management increase the capacity of the organisation to adapt.<span style="">&nbsp; </span>This allows it to steer itself away from unexpected problems and respond to new opportunities when they arise.<span style="">&nbsp; </span>We learnt from our experience of operating in Northern Ireland and Florida in making the detailed plans for our operations in Mumbai that support our UK business.<span style="">&nbsp; </span>These were tested in the extraordinary monsoon season of 2005 (a metre of rain fell in 24 hours) when our operation was down for less than 12 hours and operated for several days rather like Noah's Ark.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Cost containment - when there is a good fit between security and the rest of the business it can be managed in an integrated way as part of the daily practices of all employees.<span style="">&nbsp; </span>I will talk about this again later but it is my point about building security as the first line of defence.<span style="">&nbsp; </span>Security that is tacked on as an afterthought is like any process that is inspected in rather than built in - it is one that increases costs.<span style="">&nbsp; </span>Again thinking about Mumbai, security was involved in early planning about property, and IT configuration, to ensure continuity of service and to address data protection issues.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Security helps with decision making.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">So the second main question - what role should security play in business development?<span style="">&nbsp; </span>How do you shift the mind set within corporate security departments and among the senior management teams within them?<span style="">&nbsp; </span>I don't see security as a back of house function keeping undesirables out of the building.<span style="">&nbsp; </span>If integrated in the right way it can generate significant value for the company and be a major asset in new business development.<span style="">&nbsp; </span>As one Head of Security comments in the report - &quot;we want to be the grease not the grit&quot;.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">So linked to my comments on value I see security as having three roles in business development: </p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">First, pre-investment work looking into new markets in time to ensure that the company can operate effectively without unexpected surprises.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Secondly, ensuring that security is built in - it is involved at the design and implementation stage to ensure security is built into rather than added on to the way the business operates.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">And thirdly it addresses adaptive capacity.<span style="">&nbsp; </span>Security helps to ensure that the operating model is responsive to the changing business environment.<span style="">&nbsp; </span>This in many ways takes us back to my comment about resilience.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">So to fulfil this what should the Board be looking for in its Head of Security?</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">It is a far cry from the traditional approach to corporate security as John Smith here would characterise somewhat crudely as the guard on the gate, a guard perhaps portraying his origins by his brightly polished footwear.<span style="">&nbsp; </span>I would describe it as a proactive forward looking and business critical function which is involved with taking the business forward will require a number of qualities.<span style="">&nbsp; </span>Many of these qualities are also recommendations made in the report that I would endorse from what I have seen here.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Security experience is still important.<span style="">&nbsp; </span>I certainly value the quality of the external networks with government, police, security services and so on that come with this experience.<span style="">&nbsp; </span>It is right to recognise that security professionals and Board directors are likely to have operated in different worlds.<span style="">&nbsp; </span>This is not about, as the report describes it, the dark art of security in which presentations are littered with Le Carre like clich&eacute;s but rather recognising the complementary value of networks.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Leadership and the ability to operate at the highest level in the company is critical too, not just for the Head of Security.<span style="">&nbsp; </span>I would expect any of his direct reports to be able to present confidently about their area of expertise to the Group Audit Committee for example.<span style="">&nbsp; </span>The Head of Security must be able to influence change among senior management and inspire trust and confidence among the company.<span style="">&nbsp; </span>Business acumen is essential too.<span style="">&nbsp; </span>Security departments must understand what makes the business tick and take their lead from this rather than simply the external threat assessment.<span style="">&nbsp; </span>Financial services firms are not alone in having a risk based approach to management and security functions must be able to operate comfortably within this model of risk assessment.<span style="">&nbsp; </span>There is no room in my view for security purists in the corporate world and I note that the survey suggests that the current level of those surveyed has a relatively low level of general business experience that I would expect to increase over time.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Finally here I would say that collaboration is critical to business aligned security.<span style="">&nbsp; </span>If the security department is to get the buy-in and involvement of staff right across the company it needs to be run by people who are committed to collaboration rather than instruction.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">Command and control approaches to management in the corporate world were modelled originally I think on the 19<sup>th</sup> century civil service, certainly Prudential's was.<span style="">&nbsp; </span>They are rarely encountered today other than in major incident management when that approach may be appropriate.<span style="">&nbsp; </span>This probably does effect the degree to which people coming in to security may need to adapt, although I probably betray here my own ignorance of the organisational models from which security professionals are often initially drawn.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">All of what I have mentioned has consequences for the Board too.<span style="">&nbsp; </span>They have a part to play.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">It is essential for somebody at Board level to have responsibility for security and to ensure that he is available to the Head of Security at all times.<span style="">&nbsp; </span>Saturday morning football with my son has been interrupted to hear about the consequences of teenage joy riders driving into one of our call centres.<span style="">&nbsp; </span></p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">I hope this shows that here, our Board takes an active interest in security matters, and appreciates the value it can add to the business and is willing to have a champion within the boardroom.</p><p style="text-align: justify; line-height: 200%;" class="MsoNormal">I said at the outset I would try and offer a view on how you measure success and it is a personal view.<span style="">&nbsp; </span>On 7 July last year one of our employees who had just left Liverpool Street station heard the sound of what he correctly judged was an explosion beneath him.<span style="">&nbsp; </span>He was not on one of our security teams but his first thought was to call in to our incident management team and report the matter.<span style="">&nbsp; </span>Our team then began to invoke our incident management procedures somewhat ahead of any official notification.<span style=""> <br /></span></p><p><span style="">To me this was the best measure of the way we have succeeded with our security agenda. First it proved th</span><span style="">at we had generated awareness of security mat</span><span style=""> ters widely throughout the organisation, and secondly we were confident enough to act on the information that we had been given by an untrained employee who happened to be on the scene. As the Demos report says security is achieved through the everyday actions of employees right across the company. While I hope constantly that we will not need to test this maxim again I know only too well that we will.&quot; </span><span style="font-size: 11pt; font-family: Arial;"><span style=""><span style=""> </span><span style=""></span></span></span></p>]]>
		
		</content:encoded>
		<pubDate>Mon, 31 Jul 2006 11:39:19 UT</pubDate>
		<author>molly.webb@gmail.com ( Molly Webb )</author>
		
		
		
	</item>
	
	 	
		
		
	
	<item>
		<title>A fruitless fixation on terrorist attacks</title>
		<link>http://www.demos.co.uk/items/6804</link>
		<description><![CDATA[Today we launched The Business of Resilience, a new report on how companies must align security with their business objectives. We had a comment piece in Wednesday&amp;apos;s Financial Times which argued that the approach of UK companies following the London bombings of July 2005 compared favourably with the heavy-handed response of corporate America to the attacks of September 2001.   While companies take the threat of terrorism seriously, we found that most UK businesses do not regard it as the main... ( from BlogPosts )]]></description>
		<guid isPermaLink="false">http://www.demos.co.uk/items/6804</guid>
		<content:encoded>
		
			<![CDATA[<p>Today we launched <a href="http://www.demos.co.uk/catalogue/businessofresilience">The Business of Resilience</a>, a new report on how companies must align security with their business objectives. We had a comment piece in Wednesday's <a href="https://registration.ft.com/registration/barrier?referer=http://www.ft.com/home/uk&amp;location=http%3A//www.ft.com/cms/s/db0773f0-0603-11db-9dde-0000779e2340.html">Financial Times</a> which argued that the approach of UK companies following the London bombings of July 2005 compared favourably with the heavy-handed response of corporate America to the attacks of September 2001.   </p><p>While companies take the threat of terrorism seriously, we found that most UK businesses do not regard it as the main threat to their security. In a survey we conducted in the early part of 2006, over 50 corporate security chiefs from FTSE 250 companies and their equivalents, 65 percent ranked terrorism as only the fifth most important security challenge facing their company, after crime, IT security, fraud, and natural disasters.</p>]]>
		
		</content:encoded>
		<pubDate>Thu, 29 Jun 2006 13:25:29 UT</pubDate>
		<author>charlie[dot]edwards@demos[dot]co[dot]uk ( Charlie Edwards )</author>
		
		
		
	</item>
	
	 	
	</channel>	 	
</rss>