How will your organisation respond to a disaster?
Most organisations don't find out whether their plans work until they need them. By then, it's too late to fix the gaps.
We work with organisations before a crisis hits, building the plans, the governance and the capability to respond quickly and recover well. Whether you're starting from scratch, updating existing plans, or working towards full APRA CPS 230 compliance, we can help.
We can help you do this in three simple steps:
step one
Establish what’s important to your organisation
Before you can plan for a disruption, you need to know what matters most. We run a Business Impact Analysis (BIA) to identify your Prioritised Activities (the activities in your organisation that are most time-critical) and the resources they depend on. This becomes the foundation of everything that follows.
step two
Plan how you’ll recover
Once your priorities are clear, we develop the plans and procedures your staff will need to restore your time-critical activities after a disruption. Plans are written to be used under pressure, not to sit in a drawer.
step three
Exercise before it matters
A plan that hasn't been exercised is a guess. We facilitate exercises that simulate a real crisis, exposing gaps in your plans and building your leadership team's confidence to manage under pressure. APRA-regulated entities are required to exercise annually; we recommend all organisations do the same.
Regulated by APRA?
If your organisation is subject to APRA's CPS 230 (Operational Risk Management), you have specific obligations around Critical Operations, recovery time objectives, and third-party risk management. We help regulated entities meet these requirements, from initial gap assessment through to full compliance.
What our customers say
“The team at Continuity Matters were great! The feedback we received following the crisis management exercise was an important part of the improvement process.”
Independent State Government Agency
“I really enjoyed the exercise - in particular, the support and encouragement in applying the contents of the BCP to the scenarios.”
Not for profit organisation
“Thanks for all your help with our BIAs this year, I really enjoyed working with you and look forward continuing the resilience journey with Continuity Matters in the future.”
Victorian State Government Agency
“We are very thankful for the assistance from your team – it has really set us on a good path with our BCP work.”
Specialist Insurance company
“It has been a privilege to collaborate with you and your team over the years. The work we’ve accomplished together has been amazing.”
Health Insurance company
Not sure where to start?
Download our free eight-page business continuity planning guide, a plain-language introduction to BIA, recovery strategies, and exercising for Australian organisations.
We recommend...
APRA regulations for the financial services sector
If your company is an Authorised Deposit Taking Institution, General Insurer, Superannuation company, Life Insurer or Friendly Society and regulated by the Australian Prudential Regulation Authority (APRA) - you are subject to a number of Prudential Standards. Here’s an explainer of the standards that address risk management, resilience and recovery. We’ve also listed the relevant ASIC and ASX rules for the financial services sector and for listed companies.
A global shortage of one crucial piece of technology is causing delays in everything from cars and televisions to video game consoles and Australia’s National Broadband Network rollout.
Use your 2020 experience to re-asses the resilience of your organisation. The WEF Global Risks Report 2021 has identified the top three risks to focus on: supply chain, cyber and climate change.
After a brutal first six months of the year, governments across the world are hoping for an economic bounce-back. Rich-world gdp fell by about 10% in the first half of 2020. Yet much has changed since—including that more people are now wearing masks. Economists, obsessed with translating everything into gdp, wonder if more widespread face-covering could help the recovery.
Cybersecurity oversight is a key fiduciary responsibility for a board of directors and was a significant concern for companies even before the COVID-19 pandemic forced so many organizations to suddenly shift to remote work. Data breaches and other cyber threats pose significant competitive, reputational, and litigation risks and require increasingly costly investments to prevent, detect, and respond to. Changes in the environment as a result of the pandemic have created new risks that need to be managed with board oversight.
“It’s an intriguing approach that illustrates the type of novel approaches to scalable community testing that might be used as a community opens up,’’ Doherty Institute co-deputy director Mike Catton told The Age and The Sydney Morning Herald.
A very useful, locally produced web site that provides daily information on the pandemic nationally.
“We argued in the original preprint version of this article on 17 July that Melbourne and Victoria should not waste the opportunity that the (then) 6-week lockdown presented and go hard and early. By learning from the lessons on social and preventive measures to lower SARS-CoV-2 transmissibility (7,8,12,14), and specifically the lessons from NZ (3), Taiwan and the six Australian jurisdictions that have achieved elimination, Victoria could have increased its chances of also eliminating community transmission.”
“The University of Melbourne model suggests that if we ease restrictions when there is a fortnightly daily case average of 25, there is a 6 in 10 chance of having to lock down again before Christmas.”
"This has been a really strong evolution going from the 80s, the 90s, the 2000s, to take fat out of the supply chain, to tighten down everything," says supply-chain management expert Rich Weissman. He says in the past 10 years companies have come to really rely on analytics to fine-tune supply chains to make sure that supply and demand absolutely line up. And that's where I think we've gone too far.”
The heavy dependence on China across industry verticals is an obvious example of the sole-sourced nature of today’s supply chains.
"It suggests that climate-related risks and pandemics such as Covid-19 have similarities. Both are massive global negative externalities and both are related to changes in our natural ecosystems. In addition to the extensive economic and financial damage they both produce, both directly affect human lives and thus could be classified as Green Swans. And, for both, there is a discrepancy between how scientists warn us about the quasi-certainty of their occurrence and how we fail to systematically consider their potentially huge costs and integrate them into risk frameworks and final prices."