<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>programme - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/programme-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/programme-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 14 Sep 2020 11:03:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>programme - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/programme-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Test, test and increase your Resilience: how to build your testing programme</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/09/test-test-and-increase-your-resilience-how-to-build-your-testing-programme/</link>
		
		<dc:creator><![CDATA[m@THIEU]]></dc:creator>
		<pubDate>Mon, 14 Sep 2020 11:03:17 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[BC]]></category>
		<category><![CDATA[CM]]></category>
		<category><![CDATA[CR]]></category>
		<category><![CDATA[cyber resilience]]></category>
		<category><![CDATA[DR]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[programme]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[testing]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14194</guid>

					<description><![CDATA[<p>This year has been exceptionally trying for individuals, businesses and governments globally. Living and working in a crisis mode introduced an array of challenges, with some firms dealing with them better and faster than others. What is the common denominator?...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/09/test-test-and-increase-your-resilience-how-to-build-your-testing-programme/">Test, test and increase your Resilience: how to build your testing programme</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3 style="text-align: justify;">This year has been exceptionally trying for individuals, businesses and governments globally. Living and working in a crisis mode introduced an array of challenges, with some firms dealing with them better and faster than others. What is the common denominator? The answer in most cases is strong crisis reflexes, built over the years with consistent effort.</h3>
<p style="text-align: justify;">Testing is an important part of <b>operational </b><b>resilience</b> and can take <b>many shapes and forms, </b>from disaster recovery testing for ensuring service continuity to end-to-end crisis simulations examining decision-making. It enables to proactively <b>manage risk, embed crisis management framework</b>, and allows to continuously improve capabilities such as <b>business continuity </b>(BC), <b>crisis management </b>(CM), <b>disaster recovery </b>(DR), and <b>cyber resilience </b>(CR). Needless to say, training plays an important role in such a testing programme.</p>
<h3 style="text-align: justify;"><i>“Better awareness nurtures an organisational culture that embraces operational resilience and, as a result, improves the company’s preparedness to deal with adversity.”</i></h3>
<p style="text-align: justify;">From firm to firm, good testing programmes vary in nature, scale and complexity. Depending on how a firm is structured and what it does, testing is addressed at different organisational levels and locations, with involvement of external parties (i.e. critical suppliers). In reality, given little guidance from the regulators on what ‘good’ looks like, programmes are often fragmented and can cause a real headache.</p>
<p>&nbsp;</p>
<h2>Principles for creating a successful testing programme</h2>
<div class="uncode_text_column">
<p style="text-align: justify;">While there is no silver bullet to creating a fit-for-purpose testing programme, we recommend following <b>6 guiding </b><b>principles </b>to devise one that is successful and tailored to your organisation’s needs. Following these could significantly improve the outcomes of the programme.</p>
</div>
<div class="row-internal row-container">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<h3 style="text-align: justify;">1. Think long term</h3>
<p style="text-align: justify;">When constructing a testing programme, it is of paramount importance to define what you want to achieve in 3 years. A <b>focus on outcomes </b>provides the required direction yet allows the flexibility to re-shape the testing programme each year in order to respond to changes while focusing on the end goal. Begin with small and less complex tests, such as <b>test walkthroughs</b>, and progress to very involved, <b>realistic crisis simulation exercises.</b></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row-internal row-container">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<div class="uncode_text_column">
<h3 style="text-align: justify;">2. Start with threats</h3>
<p style="text-align: justify;">Every test needs to link to threat(s) resulting in one or several plausible major incident scenarios (and impacts). <b>Anticipate and understand new threats </b>through market watch and leverage audit reports and risk assessments when building or reviewing your programme.</p>
<p>&nbsp;</p>
</div>
<div id="gallery-146195" class="isotope-system">
<div class="isotope-wrapper no-gutter style-color-xsdn-bg">
<div class="isotope-container isotope-layout style-masonry" data-type="masonry" data-layout="masonry" data-lg="1000" data-md="600" data-sm="480">
<div class="tmb tmb-iso-w10 tmb-iso-h4 tmb-light tmb-overlay-text-anim tmb-overlay-anim tmb-overlay-middle tmb-overlay-text-left tmb-text-space-reduced tmb-image-anim tmb-bordered tmb-media-first tmb-media-last tmb-content-overlay">
<div class="t-inside style-color-xsdn-bg">
<div class="t-entry-visual" tabindex="0">
<div class="t-entry-visual-tc">
<div class="t-entry-visual-cont">
<div class="dummy">
<figure id="post-14195 media-14195" class="align-none"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-14195 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3.jpg" alt="" width="1866" height="333" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3.jpg 1866w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3-437x78.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3-71x13.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3-768x137.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture3-1536x274.jpg 1536w" sizes="(max-width: 1866px) 100vw, 1866px" /></figure>
</div>
<div class="t-entry-visual-overlay-in style-dark-bg">
<div class="row-internal row-container">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<h3></h3>
<h3 style="text-align: justify;"><b>3. Focus on Important Business Services (IBS)</b></h3>
<p style="text-align: justify;"><b>Align testing of existing contingency arrangements </b>to important business services and key processes. This ensures preparedness when a situation of high business impact occurs and avoids challenges arising from lack of end-to-end vision.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row-internal row-container" style="text-align: justify;">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<h3><b>4. Diversify testing</b></h3>
<p>The most likely and most impactful scenarios should be examined with <b>different stakeholder groups </b>through different types of testing. This ensures that the theory works in practice and different reflexes are <b>embedded in the organisation’s DNA</b>.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="t-overlay-wrap">
<div class="t-overlay-inner">
<div class="t-overlay-content">
<div class="t-overlay-text single-block-padding">
<div class="uncode_text_column">
<p style="text-align: justify;">To achieve more benefits, go beyond standalone contingency plans and comms tooling testing and examine a combination of them with internal and external, business and technical stakeholders.</p>
<p>&nbsp;</p>
</div>
<div id="gallery-342260" class="isotope-system">
<div class="isotope-wrapper no-gutter">
<div class="isotope-container isotope-layout style-masonry" data-type="masonry" data-layout="masonry" data-lg="1000" data-md="600" data-sm="480">
<div class="tmb tmb-iso-w10 tmb-iso-h4 tmb-light tmb-overlay-text-anim tmb-overlay-anim tmb-overlay-middle tmb-overlay-text-left tmb-image-anim tmb-bordered tmb-media-first tmb-media-last tmb-content-overlay tmb-no-bg">
<div class="t-inside">
<div class="t-entry-visual-cont">
<figure id="post-14197 media-14197" class="align-none"><img decoding="async" class="aligncenter wp-image-14197 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture4-uai-1440x594-1.jpg" alt="" width="1440" height="594" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture4-uai-1440x594-1.jpg 1440w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture4-uai-1440x594-1-437x180.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture4-uai-1440x594-1-71x29.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/09/Picture4-uai-1440x594-1-768x317.jpg 768w" sizes="(max-width: 1440px) 100vw, 1440px" /></figure>
</div>
<div class="row-internal row-container">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<p style="text-align: center;"><i>The radar above is an indicative example of what a good testing programme would consist of. The threat categories considered are random and could be selected differently as long as diversification is maintained (mix-and-match).</i></p>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="uncode-accordion" data-collapsible="no" data-active-tab="1">
<div id="accordion_1849304804" class="panel-group" role="tablist" aria-multiselectable="true">
<div class="panel panel-default">
<div class="panel-heading" role="tab">
<p><strong>Crisis simulation</strong></p>
<div id="crisis-simulations" class="panel-collapse collapse in" role="tabpanel">
<div class="panel-body">
<div class="uncode_text_column">
<p style="text-align: justify;">Crisis simulations examine a <b>hypothetical disaster situation </b>with defined parties and multi-cells of stimulus. They allow to rehearse the establishment and communication of recovery requirements and carry out relevant activities effectively. Crisis simulation can be a tabletop exercise (level 1), a hands-on simulation (level 2), a multi-cell hands-on crisis simulation (level 3) or an international hands-on multi-cell multi-party simulation (level 4).</p>
<div class="panel-heading" style="text-align: justify;" role="tab"><strong>Work area recovery testing</strong></div>
<div id="work-area-recovery-testing" class="panel-collapse collapse in" role="tabpanel" aria-expanded="true">
<div class="panel-body">
<div class="uncode_text_column">
<p style="text-align: justify;">Work area recovery testing checks whether <b>full end-to-end business processes</b> can be run offsite, <b>ensuring</b> <b>that</b> <b>all elements of a process can be completed during a test </b>and not just the technical aspects. They can involve a team (level 2) or a number of geographically dispersed teams (level 3) working from recovery sites or home. Both third parties (i.e. outsourced teams) and internal teams should be considered.</p>
<div class="panel-heading" role="tab"><strong>IT disaster recovery plan and cyber range testing</strong></div>
<div id="it-disaster-recovery-plan-and-cyber-range-testing" class="panel-collapse collapse in" role="tabpanel" aria-expanded="true">
<div class="panel-body">
<div class="uncode_text_column">
<p style="text-align: justify;">IT DRP and Cyber range testing practically examines <b>each step in a specific disaster recovery plan</b> or <b>tests cyber forensics capabilities</b>. This ensures the possibility to <b>recover data, restore critical IT system </b>after an interruption of its services, critical IT failure or complete disruption due to cyber attacks or IT disruptions. This testing can happen as a standalone (level 2) or as part of a crisis simulation (level 3-4).</p>
<div class="panel-heading" style="text-align: justify;" role="tab"><strong>Business recovery plan walkthroughs</strong></div>
<div id="business-recovery-plan-walkthroughs" class="panel-collapse collapse in" role="tabpanel" aria-expanded="true">
<div class="panel-body">
<div class="uncode_text_column">
<p style="text-align: justify;">Business Recovery Plan walkthroughs for group/business divisions/business units are undertaken following a major revision of a plan or team and are <b>designed to increase the understanding of the recovery processes, roles and responsibilities</b>, <b>and</b> <b>question the suitability and completeness of the plan</b>. Normally this would be carried out as a review-and-challenge session with the plan owner and a BC expert (level 1) or to test the efficiency of the specific measures and planned workarounds (level 2).</p>
<div class="panel-heading" role="tab"><strong>Communication cascade tests</strong></div>
<div id="communication-cascade-tests" class="panel-collapse collapse in" role="tabpanel" aria-expanded="true">
<div class="panel-body">
<div class="uncode_text_column" style="text-align: justify;">
<p>Communication cascade tests establish whether <b>contact details </b>are accurate, determine whether <b>cascade roles and responsibilities </b>are understood by staff, and establish whether or not the <b>documented procedures </b>are robust. They can be completed in one of three ways – either a standalone live test (e.g. text cascade; level 2), as part of a crisis simulation exercise (level 2-4), or an audit involving review of plans and interview of staff with key responsibilities (level 1).</p>
</div>
<div class="row-internal row-container" style="text-align: justify;">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<h3><b>5. Stay current</b></h3>
<p>Review your testing programme at least once a year in order to <b>adapt to the changing threats landscape</b> and ultimately <b>ensure operational resilience</b>. Make sure your crisis management framework and contingency plans are regularly improved based on the testing outcomes and changes in the business.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row-internal row-container">
<div class="row row-child">
<div class="row-inner">
<div class="pos-top pos-center align_left column_child col-lg-12 single-internal-gutter">
<div class="uncol style-light">
<div class="uncoltable">
<div class="uncell no-block-padding">
<div class="uncont">
<div class="uncode_text_column">
<h3 style="text-align: justify;"><b>6. Engage and drive</b></h3>
<p style="text-align: justify;"><b>Involve different parties </b>in shaping and running your testing programme (e.g. cyber, risk, Ops, DPO, legal, business resilience champions, etc.). Use MI to share progress and alignment with the 3-year operational resilience vision.</p>
<p>&nbsp;</p>
</div>
<div class="heading-text el-text">
<h2>What next: how do you structure your testing programme?</h2>
</div>
<div class="uncode_text_column">
<p>While it is not possible to prescribe a testing programme without better understanding the organisation of interest and deep-diving into the specifics of a threat landscape, it is clear that investing time and resources is worthwhile from operational resilience and regulatory standpoints.</p>
<h3><i>“Having recently gone through a pandemic, it is a high time to keep the momentum and continue fostering the right culture and correct reflexes for the next </i><i>major </i><i>crisis.”</i></h3>
</div>
<div class="uncode_text_column">
<h4><b>A few concluding tips</b></h4>
</div>
<div class="uncode-wrapper uncode-list">
<ul>
<li><b>Make it realistic: </b>Where maturity allows, aim for more <b>complex and realistic tests </b>as they are essential to effectively respond to real events and increase end-to-end resilience. This means engaging more internal and external parties in the ‘live’ exercises.</li>
<li><b>Leverage internal and market crises: </b>Continuously <b>monitor</b> events happening on the market (major incidents and crises) as well as your internal major incidents to feed your testing program, prioritise your threats and devise your scenarios making it more tangible for your stakeholders.</li>
<li><b>Engage early: </b>Share the vision for testing with <b>key stakeholder groups </b>so they understand the journey on which you want to bring the organisation. This will enhance collaboration and, therefore, outcomes.</li>
<li><b>Facilitate remotely:</b> Remote working arrangements should not put your whole testing programme on hold &#8211; use collaborative solutions or leverage tools from the market for carrying out the exercises. This is especially relevant for cyber range testing and follow-the-sun testing. Experience shows that <b>digital workplace solutions </b>introduce a more democratic participation and is an excellent way to record interactions.</li>
<li><b>Continuously improve:</b> Reflect on tests by producing post-test reports and defining an action plan to <b>drive and track improvements</b>. Involve key stakeholders throughout so they understand the gravitas of the outcomes and help with driving positive changes.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/09/test-test-and-increase-your-resilience-how-to-build-your-testing-programme/">Test, test and increase your Resilience: how to build your testing programme</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
