ready for anything - barclays...a successful business is ready for anything. 3 of 15 fewerthan one...
TRANSCRIPT
Ready for anythingBuilding your business resilience for the unexpected
Let’s go forward
Contents3 Introducingresiliencetoyourbusiness
4 Identifyingthethreatstoyourbusiness
5 Beprepared Protectingyourpeople
Protectingyourpremisesandsupplychain
Beatingthefraudsters
8 Insurance–areyoucovered?
9 Casestudies VividaProductions
GloriousSpa
inYourFaceAdvertising
12 BusinessEmergencyResilienceGroup’s10-minuteplan
13 Usefulcontacts
14 Keytakeaways
15 AboutBarclaysandBERG
2of15
Introducing resilience to your businessWouldyoubereadyifextremeweather,acyberattackorterrorismdisruptedyourbusiness?
Smallandmedium-sizedbusinessesareoftenthemostvulnerabletothesetypesofthreats.Issuesaffectingstaff,customersandsuppliers,orutilitiesandtransportcanhaveasevereimpactonthesuccessofabusiness.
SMEshavealottojuggle,butalongsidecashflow,recruitmentandstaffissues,therisksofdisruptionsfromcybercrime,naturalhazardsandcivilemergencieshavebecomemoreimportanttothinkaboutthanever.
“Disruptiveeventscanhappenanywhere,atanytime,fromnaturaldisasterstocybercrime.Takingtimetoplanandprepareyourbusinesscansaveyoutimeandmoneywhensomethinguntowardhappens.BusinessEmergencyResilenceGroup(BERG)ishelpingsmallbusinessownerscreateresilienceandrecoveryplansthatwillhelpguaranteefutureprosperity.Beresilient.Beprepared.”
Lee Webb,Director,GroupResilience,Barclays
Businessownersoftensaytheycan’taffordtospendtimeandmoneybuildingresilienceagainstrisks,orthattheyarealreadydoingenoughtoprotectthemselves.Thismindsetcanbeoneofthebiggestbarrierstobeingprepared.ManySMEsalsounderestimatehowlongitwouldtaketogetbackupandrunningiftheywerehitbyanunexpectedevent.
Takingaction
Whileyoucanneverprotectyourbusinessfromalltherisksintoday’sworld,youcancertainlybecomemoreresilienttothem.Businessresilienceneedstobefirmlyonthemanagementagenda,asdoingnothingcanhaveseriousconsequences.
Fortunately,therearelotsofworthwhileactionsthatcanmakeyourbusinessmoreresilientandhelpyouprepareforeventsthatmightjeopardiseyourfuturesuccess.Takingtimetoplanandprepareyourbusinesscansaveyoutimeandmoneywhensomethingunexpectedhappens.
We’veproducedthisguideinpartnershipwithBusinessintheCommunity’s(BITC)BusinessEmergencyResilienceGroup(BERG),toraiseawarenessofresilienceplanningandtohelpyourbusinessgettogripswithpreparingfortheunexpected.
Thisguidediscussesthetypesofthreatsyourbusinessmightfaceandhowyoucanprepareforthem.Itincludeslotsofstraightforward,practicalstepsyoucantaketolessentheimpactonyourbusiness,aswellasreducinginsurancepremiumsandclaims.
Asuccessfulbusinessisreadyforanything.
3of15
Fewer than
oneinfive(17%)SMEshasassessedtheirexposuretorisingUKsecuritythreats,despite44%
expectingtofacesomekindofthreatinthenext12to18months.*
68%ofSMEsclaimtoberesilienttosecuritycrises,yetnearlyhalf(43%)admitto
havingnobusinesscontinuity,disasterrecoveryorcrisismanagement
plansinplace.*
*Source:ArthurJ.Gallagher–UnderstandingSecurityRisksreport,2017.
4of15
Identifying the threats to your business Tomakeyourbusinessmoreresilient,thefirststepistothinkaboutsomeofthethreatsyoumaybevulnerabletoandhowtheycouldimpactyourbusiness.
1www.beaming.co.uk/press-releases/cyber-security-breaches-cost-businesses-30-billion2www.nao.org.uk/wp-content/uploads/2017/06/Online-Fraud-Summary.pdf3FederationofSmallBusinessesandClimateReadyattheEnvironmentAgency4EnvironmentAgency:Aguidetopreparingyourbusinessforflooding.5BarclaysEnergyResiliencereport,20166https://www.beaming.co.uk/press-releases/british-businesses-lost7billion-internet-outages-2016/7https://www.ons.gov.uk/employmentandlabourmarket/peopleinwork/labourproductivity/articles/sicknessabsenceinthelabourmarket/20168CentreforEconomicsandBusinessResearch,EconomiceffectofUKroadinvestment,February20179BusinessContinuityInstituteSupplyChainSurvey.
Supplierfailure
Terrorism
experienceatleastoneincidentthatdisruptstheirsupplychaineachyear.
Illnessandstaffabsence
workingdayswerelostduetosicknessorinjuryin2016.
137.3 million
Anestimated
ExtremeweatherNearly
ofUKbusinesseshavenoplansinplacetodealwithextremeweather.
66%
FraudScamsthattargetsmallbusinessesareontheincrease.Theprivatesectorlostanestimated
tofraudin2016.
PowercutsTechnicalfailureorsevereweathercancauselossofpoweratanytime,withoutwarning.
ofUKmanufacturersarevulnerabletothis.
fromgaspipelinesortoxicchemicalstoragecancausedamagetopremisesorpreventaccesstobuildings.
Industrialactionorsevereweathercandisruptroadandrailnetworks.By2030thiscouldcosttheBritisheconomyasmuchas
Traveldisruption
Criminalorindustrial explosions
WorldeventsPoliticaloreconomiceventsinotherpartsoftheworldcancausedisruptiontoexchangerates,tradeandfinancialtransactions.
Cybercrimehit
ofUKbusinessesin2016,costingalmost
52% Cyberattacks
£144billion
£307billion.
TerroristincidentsintheUKareontherise.Theyarenotonlyathreattolivesbutcancausemajordisruptiontoyourbusiness.
FloodingSince1998therehasbeenatleastoneseriousfloodeveryyear.
3DAYS’Britishbusinessessuffered
internetdowntimeonaveragein2016.
ITandTelecomsoutages
ofUKbusinesses75%
60%
£30billion.12
3
4
5
6
7
8
9
Be prepared: protecting your peopleAlthoughtherearenumerousthreatsthatcouldaffectyourbusiness,therearemanysimplemeasuresyoucantaketobecomebetterprepared.Thisincludeslookingattheresilienceofyourpeople,premises,suppliersandITsystems.
5of15
Develop a communication plan:
1. Makealistofemployees’contactdetailsandthinkaboutstaffwhomayneedspecialassistanceintheeventofanevacuation
2. Keepstaff,customersandsuppliersup-to-dateaboutanydisruption
3. Thinkabouthowyouwouldcommunicateifstaffneededtoworksecurelyfromhomeorfromanotherlocation
4. Monitortransportupdatesandcheckyourlocalcouncil’swinterresilienceplans,includingwhichroadstheywillgrit.
Train staff to deal with disruption:
1. Ensureyourstaffunderstandtheircolleagues’jobrolestocoverforabsences
2. Considerhealthandsafetytrainingforstaff,includingfirstaid
3. Briefyourstaffonevacuationroutes,floodplans,chemicalplans,safespacesandhowtosecureyourpremises
4. Createachecklistofsafetyprocedurestoadoptinanemergencyandensurestaffarefullybriefedonwhattodo
5. Putsecuritymeasuresinplaceandmakesureyourstaffunderstandthemandtheirpartinmakingthemwork
6. ShowyourstafftheGovernment’s‘StaySafe’videoforadviceonwhattodointheeventofaweaponsattack.
Smallbusinessesareparticularlyvulnerabletostaffabsence,soit’svitaltohavewell-testedsystemsinplacethatwillallowyoutocarryonintheeventofillness,traveldifficultiesoranincidentaffectingyourpremises.
6of15
Be prepared: protecting your premises and supply chainSafeguardingyourpremises
Businesspremisesandequipmentarevulnerabletoarangeofthreats,fromextremeweatherandpoweroutagestoterrorismandindustrialincidents.
PlanhowyoucontrolaccesstoyourpremisesandwhetheryouneedtoinstallCCTV.
Consider the risks to your premises:
• Workoutwhereyouaremostvulnerabletodecideonthelevelofsecurityyourequire,planhowyoucontrolaccesstoyourpremisesandwhetheryouneedtoinstallCCTV
• Checkyourfloodrisk,createafloodemergencyplanandinstallfloodprotectionproductsandflood-resistantmaterialsifnecessary
• Ifyourpremisesareaccessibletothepublic,thinkaboutmeasuresyoucouldtaketominimisetheriskofanattack,suchasremovalofwastebinsorbagsearches
• Thinkaboutwhereyoucouldoperatefromifyoucouldn’taccessyourpremises.
Prepare for emergencies:
• Protectyourbusinessagainstcrime,vandalismorunrestbytestingfirealarmseveryweek
• Makesureyoursecuritysystemhasanuninterruptibleandregularlytestedpowersupply
• Storekeydocuments,emergencyplans,andcontactinformationforstaff,emergencyservices,customersandsuppliersinasafeplace
• Makesureyourphysicalassetscanbestoredabovefloodlevelandidentifyanythingthatmayneedspecialprotectivemeasures
• Knowhowtoshutoffyourgas,electricityandwatersupplies,andkeepacontactlistofyoursuppliersonahardcopyinasafeplace.Makecopiesofyourcontacts,incaseonerecordfails
• Keepmobilephones,laptopsandtablets fullycharged
• Puttogetheranemergencykit,includingabattery-operatedorwind-uptorchandradio.
Supplierresilience
Yoursuppliersarejustasvulnerabletounexpectedthreatsasyourownbusiness.Understandingyoursupplychainanddevelopingresiliencetoanyweaknessescanhelpyoureactmorequicklytoadverseeventsandcouldevengiveyouanadvantageoveryourcompetitors.
Understand the importance of your key suppliers:
• Beawareofhowmuchyoudependonyoursupplierstorunyourbusiness.Lookatyourmostprofitableproductorserviceandthepotentialprofitimpactifthesupplierfailed
• Thinkabouthowyouwillkeepcustomersup-to-dateintheeventofsupplierfailure.
Build resilience into your supply chain:
• Thinkaboutdiversifyingyoursuppliersandreassesscontractswhentheyarerenewed
• Considerusingsuppliersthatoperatefrommultipleorlow-risklocations
• Discussyourcontingencyplanswithyoursuppliersandassesstheeffectivenessoftheirownbusinesscontinuityplans
• Find outmoreabouthowCyberEssentialscertificationcanhelpdemonstratethatyouandyoursupplychaintakecybersecurityseriously.
Understandingyoursupplychainanddevelopingresiliencetoanyweaknessescanhelpyoureactmorequicklytoadverseevents.
7of15
Be prepared: beating the fraudstersCybersecurity
IfyouuseITsystemstosell,deliveryourservices,manageyourfinancesorcommunicatewithcustomersyoucouldbeaneasytargetforcybercriminals.Lackofcybersecurityposesathreattoyourprofitability,cashflowandreputation.OurDigitalEaglesareonhandtosupportifyouwouldliketotalkabouthowthefollowingappliestoyourbusiness.
Back up your data:
• Takeregularbackupsofyourimportantdataandtestwhetheritcanberestored,andhowlongthistakes
• Ensurethedevicecontainingyourbackupisnotconnectedtothedeviceholdingtheoriginalcopy,neitherphysically,noroveralocalnetwork
• Considerbackinguptoasecureandlegallycompliantcloudserversothatyourdataisstoredinasafelocationandyouareabletoaccessitquicklyfromanywhere.
Prevent malware damage:
• Installapprovedantivirussoftwareonallcomputersandlaptops
• Makesurethatallsoftwareandoperatingsystemsareupdatedregularlytoprotectagainstknownthreats.Turnonautomaticupdateswherepossible
• ControlaccesstoremovablemediasuchasSDcardsandUSBsticks
• Considerdisablingportsorlimitingaccesstounreliablemediaandencouragestafftousesecurefiletransfermethodsinstead.Rememberthatemailsareunsecure,sowhensendingsensitivedatamakesureitisencrypted.
Avoid phishing attacks:
• Makesurestaffareawareofscams,suchasemailsaskingforsensitiveinformationlikebankdetailsorcontainingroguelinks
• Ensurestaffdon’tbrowsetheweborcheckemailsfromanadministratoraccounttoreducetheimpactofanattack
• Watchoutforemailsthatofferfinancialrewards,askyoutoacturgentlyorusescaretactics
• Checkthatyouknowthepersonororganisationsendinganemail–makesuretheemailaddressislegitimateandnottryingtomimicsomeoneyouknow
• Lookoutforemailsandwebsitescontainingpoorspellingorgrammar,orlowqualityversionsoflogos
• Bewaryofclickingonlinksorenteringdetailsonloginpages–ifitlookssuspicious,itisbesttodeleteormarkasjunkmail.
Take care when using mobile devices:
• SwitchonthePINorpasswordprotectionandrecognitiononallsmartphones,laptopsandtablets
• Configuredevicessotheycanbetracked,remotelywipedorremotelyblocked
• DonotconnecttopublicWi-Fihotspotswhensendingsensitivedata–use3G,4GorVPNinstead,andcheckthatyourdevicesarenotautomaticallyconnecting
• Replacedevicesthatarenolongersupportedbymanufacturers.
Use strong passwords to protect your data:
• Avoidpredictablepasswords,suchasfamilyandpetnamesthatcanbefoundeasily,andcommonpasswordsthatcanbeeasilyguessedsuchaspassw0rd
• Makepasswordsaslongaspossible–atleasteightcharactersandacombinationofletters,numbersandsymbols,oruseamemorablesentenceorphrase
• Donotreusepasswordsondifferentsites
• Considertheuseofapasswordmanagertosecurelystorepasswords
• Getprotectionbeyondpasswords,suchastwo-factorauthentication
• Makesurealldevicesuseencryptionproductsthatrequirepasswordsandthatsecuritymeasures,suchaspasswordsorfingerprintrecognition,areswitchedon
• Controlaccesslevelsacrossyourworkforce,ensuringstaffonlyhaveaccesstoinformationnecessaryfortheirroles.
10DataBreachInvestigationsReport.
23%of recipients open
phishing emails and
11% open
attachments.10
8of15
Insurance – are you covered?Althoughyoucantakevariousstepstomakeyourbusinessmoreresilient,unforeseeneventsmaystilloccur.Theonlywaytoprotectyourbusinessagainstlossofstockordamagetobuildingsisthroughinsurance.
Check your insurance Consideryourinsurancelimits,excessandcoveragetermsandconditions;readthesmallprintandensurethatthecoverageissufficientforyourneeds.Ontopofyourmandatoryinsurancerequirements(suchaspublicliabilityandemploymentinsurance),makesureyouarealsoinsuredagainstthreatsthatcouldimpactyourbusiness,includingextremeweatherandflooddamage,businessinterruptionandlostrevenue,cybercrimefraudandotherlosses.
Respond quicklyCallyourinsurancecompanyassoonaspossibleafteranincident.Makesureyouknowwhatinformationyourinsurerwillrequiretosupportaclaim.Takephotosandvideoasevidenceofanylossordamage.
Think about using a loss adjusterYoucanappointyourownCharteredLossAdjustertolookafteryourinterestsasaclaimproceeds,preparetheclaimandnegotiatesettlementonyourbehalf.
Respondingtoanemergency
Therearemanysourcesofadviceandsupportforbusinessesintheeventofaseriousdisruption,includingtheemergencyservices,localauthorities,localresilienceforums,regionalresiliencepartnershipsandthevoluntarysector.
Call999ifpeopleorpropertyareindanger
Assesstheimpactonyourbusinessandhowlongitwilllast
Contactyourinsurancecompanyandrecordphotosandvideosasevidenceofanylossordamage
Contactstaff,suppliersandcustomerstoletthemknowwhathashappened
Rememberthatitcantakeseveralmonthstogetyourbusinessbackonitsfeetafteramajordisruption,anddon’tunderestimatetheemotionalstressonyourstaffandtheirfamilieswhoareaffectedbyacrisis.
Todiscussyourinsurance,pleasecall03301021849,*arrangeacallbackorvisitusatbarclays.co.uk/business-banking/manage/business-insurance
Immediately after an incident there are a number of actions you could take:
1 5
6
7
8
2
3
4
Ifyouarecomfortablethatitwouldworkforyourbusiness,considerusingsocialmediatoshareinformationaboutthedisruption
Identifywhatbusinessactivitiescancontinueandwhichmayneedtobeputonhold
Speaktoneighbouringbusinessestoseeiftheycanhelp
Contactyourlocalcounciltoseewhathelpitcanoffer.
*Callsto03numbersusefreeplanminutesifavailable;otherwisetheycostthesameascallsto01/02prefixnumbers.Callsmaybemonitoredorrecordedinordertomaintainhighlevelsofsecurityandqualityofservice.
9of15
Case study: Vivida ProductionsSimeonQuarrie,ownerofVividaProductions,avisualstorytellingbusinessusingvideoaswellasvirtualandaugmentedreality,recallsanITfailureintheearlydaysofhisbusinessthatthreateneditssurvival.
Learningthehardway
Earlyoninthebusiness,VividaProductionsmainlyproducedhigh-endvideosofweddingsandotherfamilyevents.SimeonQuarrierecalls:“Myteamwasworkingawayonvideoeditswhenourharddrivessuddenlywentdown.Initiallywedidn’tpanicbecauseweknewwehadbackupsoff-site.Butwhenwetriedtousethebackupstheywentdowntoo.”
Itturnedoutthattheserverswereexceedingtheirrecommendedoperatingtemperatureduringaheatwave,duetolackofventilation.Fortunately,thecompanyhadanotherbackupofthesourcedata,butstilllostalotofwork.“Ihadtopaymystaffovertimetogetthebusinessbacktowhereithadbeen.Ithadahugeimpact.
“Theincidentcouldhavebeendevastatingforourreputationandpipelineofnewbusiness,aswellasfinanciallyifwe’dhadtorefundclients.Andthereistheimpactonstaffmoraleofhavingtorepeatcompletedwork.
“Ithinkit’sreallyimportantthatbusinessesfocusnotjustongrowthbutonwhatcouldgowrong.Keeplookingforpotentialweaknessesinyourbusinessandbeprepared.We’velearnedthatyouneedtobeawareofthelimitationsofthetechnologyyourbusinessdependson.”
Thecompanyhassinceinvestedinsophisticatedharddriveswithbuilt-inanalyticsthatcanberebuiltinamatterofhoursandmakessureitprovidessourcedatafilestoclients,aswellasusingcloudbackupforallitsdocumentation.Itisalsovigilantaboutplanningforhotweatherandhasincreaseditsinsurancecover.
Havingsurvivedandrecoveredfromtheincident,thebusinesshassincedoubledinsizeandbusinessresiliencehasbecomeafactorinwinningbiggercontracts.“We’velearnedourlessonsandemergedasastrongerbusiness,trustedbysomeofthebiggestbrandsintheworldforourvisualstorytelling,”saysSimeon.
SimeonQuarrieOwnerofVividaProductions
“It’sreallyimportantthatbusinessesfocusnotjustongrowthbutonwhatcouldgowrong.”
Theincidentcouldhavebeendevastatingforourreputationandpipelineofnewbusiness,aswellasfinanciallyifwe’dhadtorefundclients.
10of15
Case study: Glorious SpaStephanieRidge,ownerofGloriousSpa,achainofhigh-streetspaandbeautysalonsinWestSussex,explainsthelessonsshehaslearnedaboutresilienceandpreparingforemergenciesaftersufferingafloodtoherpremises.
Planningfortheunexpected
StephanieRidgeopenedGloriousSpain2010inChichester.ShenowhasthreesalonsinWestSussex,withafourthonthewayandatrainingschoollaunchingin2018.
InlateOctober2013thegroundfloorofthesalonwasfloodedfollowingflashstorms,andStephaniehadtocloseforthreedays.Sheexplains:“Theelectricswerecompromised,andwehadtorepaintandrefurbish.Itwaschaotic,anditcostusalotofmoney.Cashflowwasvitalaswe’dopenedduringtherecessionandsunkeverypennyintothebusiness.“Atthetimewehadjustoneshopsoitwasouronlysourceofincome,andwehadasubstantialpayrolltomeet.ItwasalsothelastbusyweekbeforeNovember,whichisthequietesttimeofyearforusaspeoplearesavingforChristmas.Itwasamajorincidentforus.”
Aftertheflood,StephanieworkedwithBarclaystoimprovethecompany’semergencyplanandmakesureitiseasytoputintoaction.
“Wenowhaveanup-to-datelistofstaffphonenumbers,contactdetailsforneighbouringshopsandourbookingsystemisonlinesoalltheseniorteamhaveaccesstoit,”shesays.“We’vealsogrownoursocialmediapresencesowecancommunicatequicklywithcustomers,andwehaveadirectoryoftradesmenwhowetrustandwhowouldbereadytoassistinemergencies.
“Iwouldalwaysadviseotherbusinessestomakesuretheyhavearobustplaninplacetocontacttradesmen,staffand,ofcourse,customers.”
StephanieRidgeOwnerofGloriousSpa
We’vegrownoursocialmediapresencesowecancommunicatequicklywithcustomers,andwehaveadirectoryoftradesmenwhowetrustandwhowouldbereadytoassistinemergencies.
11of15
Case study: in Your Face AdvertisingArthurChirkinian,founderandCEOofinYourFaceAdvertising(iYFA),explainswhathehaslearnedaboutmakinghisbusinessmoreresilienttocybercrimefromhisinvolvementinBarclaysB:Resilientevents.
Beresilientandcarryon
Launchedin2015,iYFAoffersbusinessesanewplatformtoadvertisetheirproductsorservicesinaneco-friendlywaytotheirlocalcommunity.Arthurexplains:“Companiescanuseourcustom-builtonlinesoftwaretodesignandcreateadvertsandpromotionsthatcanbeputonecologicallysustainableeBinsandeBags.”
HavingbeeninvitedtoaB:ResilienteventoncybersecurityforSMEs,iYFAhassinceattendedseveralotherevents,whichArthursayshavealsobeenusefulfornetworkingwithotherSMEs,aswellasshowcasingthecompany’sproducts.
“TheB:Resilienteventshavebeenincrediblyhelpfulandinspiring.Cybercrimeisakeythreatforus,andwe’vealreadyhadtwohackingattemptsagainstourwebsite.
Butwemanagedtosuccessfullyprotectourselvesandourcustomers’datafromtheattacksbyapplyingwhatwehadlearnedattheseevents.”
In2017,thecompanywasafinalistinBITC’sBarclaysAwardforBuildingResilientBusiness.
Thecompanynowhastwobackupcloudservers,customerdataissecuredusingSSLcertificatesandtheyhaveaself-healingcloudinfrastructure,whichismonitoredroundtheclock.
Akeenbelieverinbusinessesbuildingtheirresilience,Arthursays:“OureProductsnotonlycarryadvertisingfromlocalbusinesses,theyalsopromotetheworkthatBITCandBarclaysisdoingtofurtherpromoteresilienceinlocalbusinesscommunities.
“Asastart-up,weunderstandthatbuildingresilienceiscriticaltoourgrowth.Whetherit’sfire,floodorcyberthreats,it’simportanttotakestepstoprepareyourself.Beresilientandcarryonisourmotto–aresilientbusinessmeansstayinginbusiness.”
ArthurChirkinianFounderandCEOofinYourFaceAdvertising
“TheB:Resilienteventshavebeenincrediblyhelpfulandinspiring.”
Weunderstandthatbuildingresilienceiscriticaltoourgrowth.Whetherit’sfire,floodorcyberthreats,it’simportanttotakestepstoprepareyourself.
12of15
Business Emergency Resilience Group’s 10-minute planBERG’s10-minuteplanisdesignedtohelpsmalltomedium-sizedbusinessespreparefor,respondtoandrecoverfromemergencies,suchasflooding,cybercrimeandcivilunrest.
Take10minutestohelpprepareyourbusiness:
How
Emergencies
Accesstositeandpremisesisprevented,possiblyforanextendedperiodoftime
Disruptionfromexternaleventssuchasaterroristincident,floodingorafire
Criticalequipmentfailsoramajorsuppliergoesoutofbusiness
Lossofelectricity,waterorgas
Disruptiontokeytransportnetworks
Keystaffareabsentatthesametime
Burgledorvandalisedoffice
ITandtelecommunicationsoutages
Planahead
Checklivealerts–signupforEnvironmentAgencyandcross-sectorsafetyandsecuritymessages
FollowtheadviceontheofficialNationalCounterTerrorismSecurityOffice(NaCTSO)website
DownloadtheBritishRedCrossEmergencyapp
CheckyourfloodriskontheEnvironmentAgencywebsite
Showthegovernment’s‘StaySafe’videotoyourstaffforadviceonwhattodointheeventofaweaponsattack
Considerhowyoumightsecureyourpremisestokeepyourstaffandcustomerssafeinside,andcanyouprovidefood,waterandaccesstotoilets?
Considerinsurancelimits–excessandcoveragetermsandconditions,watchforsmallprintandunderinsurance
Understandyoursite–evacuationroutes,floodplans,chemicalplansandsafespaces
Considerback-uputilities–energy,waterandcommunications
Createchecklistfornewstartersandleavers–newpasswords,accesscodes,keysandemergencyprocedures
Followdataprotectionguidance.Backupcomputersandkeydocuments–keepcopiessafe/offsite
Undertakeweeklysecuritychecks–IT/firealarm/safetysystem/burglaralarm
Ensurestaffunderstandcolleagues’jobrolestocoverforabsences
Considerhealthandsafetystafftraining,includingfirstaidandMetPoliceProjectGriffintraining
Createacontactlistofcurrentandalternativesuppliers
ChecktheCentrefortheProtectionofNationalInfrastructure(CPNI)websiteforinformationandadviceonphysicalsecurity,personnelsecurityandcybersecurity
Shareresilienceplansandidentifywaystosupportneighbouringbusinesses
CaptureBusinessEmergencyContacts
shouldyoucommunicate? Yes No
CaptureBusinessEmergencyContacts
Detailimportantinformationandcontacts,includingstaff,emergency,customersandsuppliers
Regularlycommunicateyourplantostaffandensuretheyhavemanagement’scontactdetails
Regularlyreviewandupdatecontacts(everythreetosixmonths)
Keepcontactsinasafeplace/offsite
Regularlytestandcheckkeyelementsoftheplan(everythreetosixmonths)
Createanemergency‘grabbag’–keydocuments,plansandcontactdetails
3
What couldyoudotoprotectyourbusiness? Yes No
2 Considerthefollowingimpacts onyourbusiness High Med Low
1
13of15
Useful contactsEmergency• BERG Offerspracticalhelpforbusinessesduringacrisisandintherecoveryperiodintheformofgoods, servicesandadvice. www.bitc.org.uk/berg/prepare
• British Red Cross Supportsthepolice,ambulanceandfireservices,localandhealthauthoritiesandutilitycompanies
tohelpthosemostaffectedbyUKcrises.www.redcross.org.uk
• The Samaritans Hasateamofvolunteerstrainedtoprovideemotionalsupportinresponsetoanemergency. www.samaritans.org
Insurance• Barclays WorkingwithAllianz,oneoftheUK’sleadinginsuranceproviders,tohelpsmallbusinessesdesign
insurancecovertosuittheirspecificneeds.www.barclays.co.uk/business-banking/manage/business-insurance
• The Chartered Institute of Loss Adjusters Canhelpyoufindasuitablelossadjuster. www.cila.co.uk
Cybercrimeandfraud• Cyber Essentials CyberEssentialscertificationallowsyourorganisationtoadvertisethatitmeetsaGovernment-
endorsedstandard.www.cyberaware.gov.uk/cyberessentials
• National Cyber Security Centre (NCSC) ApartofGCHQ,NCSCistheUK’sauthorityoncybersecurity.Furtherguidanceforsmallbusinesses
canbefoundontheirwebsite.www.ncsc.gov.uk
• Action Fraud TheUK’snationalfraudandcybercrimereportingcentre. www.actionfraud.police.uk
Extremeweather• The Environment Agency Provideslotsofinformation,warningsandadviceonfloods. www.gov.uk/flood and a 24hr Floodline is 0345 988 1188*
• The National Flood Forum Hasadviceforbefore,duringandafterflooding. www.nationalfloodforum.org.uk
• The Association of British Insurers Producesaguidetoresistantandresilientrepairafteraflood. www.abi.org.uk
• Aviva Givesguidanceonwhattoexpect,whocanhelpandwheretostartwithcleaningup. www.aviva.co.uk/news-and-guides
Terrorismandworldevents• The National Counter Terrorism Security Office Providesinformationonpreparingforaterroristattack,withdetailedinformationonprotecting yourbusiness’sassets. www.gov.uk/government/organisations/national-counter-terrorism-security-office
• The Centre for the Protection of National Infrastructure (CPNI) Websitegivesadviceonphysicalsecurity,personnelsecurityandcybersecurity. https://www.cpni.gov.uk
Illnessandstaffabsence• Government information and advice on flu pandemics www.gov.uk/guidance/pandemic-flu
• NHS England Hasproducedanoperatingframeworkformanagingtheresponsetopandemicinfluenza. www.england.nhs.uk/ourwork/eprr/pi/
• Highways England Hasinformationontrafficdisruptions. www.highways.gov.uk
Supplierresilience• The Business Continuity Institute (BCI) RunssupplychainresiliencecoursesandproducestheSupplyChainResilienceReport,whichtracks theorigins,causesandconsequencesofsupplychaindisruption. www.thebci.org/
*Calls to03numbersusefreeplanminutesifavailable;otherwisetheycostthesameascallsto01/02prefixnumbers.Callsmaybemonitoredorrecordedinordertomaintainhighlevelsofsecurityandqualityofservice.
14of15
Key takeaways• Think aboutsomeofthethreatsyoumaybevulnerabletoandhowtheycouldimpactyour
business.FillinginBERG’s10-minuteplan(page12)isagreatwaytobegin
• Ifyourbusinesscouldbehinderedbystaffabsence,it’svitaltohavewell-testedsystemsinplacethatwillallowyoutocarryonintheeventofillness,traveldifficultiesoranincidentaffectingyourpremises
• Planhowyoucontrolaccesstoyouroffices,andhowyoucanprotectyourtechnologyandlocationsfromallinstances–whetherthat’sascommonasapoweroutageorsomethingmoreseverelikeweatherdamage
• Evaluateanydependenciesinyoursupplychainandidentifycontingencyplansforanyweaknessesthatcouldarise
• Cybercrimeisontherise,soit’simportantforallbusinessestobeprepared.Followingthefivequickandeasystepsonpage7couldsavetime,moneyandevenyourbusiness’sreputation
• Considertakingoutbusinessinsurance,or–ifyouarealreadyinsured–reviewyourlevelofcovertoensurethatyouwouldbeprotectediftheworstweretohappen
• Makeanoteofanykeycontacts–bothinsideyourbusinessandexternalsupportnetworks–thatcanhelpinatimeofcrisis.
About Barclays and BERGGettingyourbusinessreadyforfuturechallengeshasneverbeenmoreimportant.OursincerethankstotheBusinessEmergencyResilienceGroupforpartneringwithustocreatethisreport.
AboutBusinessBankingatBarclays
Barclayshasbeenworkingwithbusinessowners,organisationsandcompanyexecutivesforover327years,helpingandinspiringthosethatrelyonlocalconnection,insightandknow-howtomoveforward.
YourbusinessplaysacrucialroleinthesuccessoftheUKeconomy,andwebelievethatthemoreknowledgeyouhave,themoresuccessfulyourbusinesscanbe.
Wehopethisreportwillproveusefulwhenfuture-proofingyourbusiness’soperationsandupcomingplans.
AboutBarclaysGroupResilienceteam
BarclaysGroupResilienceteamhasdevelopedaninitiativewhichbringstogethertheskillsandexperienceofitsteamofexperts,thewiderBarclayscommunityandexternalpartnersonbusinessresilience.IthelpsSMEstoshareexperiencesandlearnfromreal-lifeexamplesofbusinessesthathavebeenaffectedbycybercrime,floods,fireandotherdisruptions,andwhattheynowdodifferently.BarclaysisamemberandsupporteroftheBusinessEmergencyResilienceGroupprogramme.
AbouttheBusinessEmergencyResilienceGroup
PartofBusinessintheCommunity(BITC),aninitiativeofHisRoyalHighnessThePrinceofWales,theBusinessEmergencyResilienceGroup(BERG)helpsbusinessesandcommunitiesacrosstheUKtopreparefor,respondtoandrecoverfromemergenciessuchasflooding,cyberattacksandcivilunrest.
Findoutmoreatwww.bitc.org.uk/berg
Formoreinformation,pleasecontactyourlocalRelationshipManagerorvisitbarclays.co.uk/business
ThisdocumenthasbeenpreparedbyBarclaysBusiness,atradingnameofBarclaysBankUKPLCandisprovidedtoyouforinformationpurposesonlyandmaybesubsequentlyamended,supersededorreplaced.Barclaysacceptsnoliabilitywhatsoeverforanylossesarisingfromtheuseofthisdocumentorrelianceontheinformationcontainedherein.Theaccuracyorcompletenessofanyinformationhereinwhichisstatedtohavebeenobtainedfromorisbaseduponanythird-partysourcesisnotguaranteedbyBarclays.Allopinionsandestimatesaregivenasofthedatehereofandaresubjecttochange.Theinformationinthisdocumentisnotintendedtopredictactualresultsandnoassurancesaregivenwithrespectthereto.©Barclays2018.NopartofthisreportmaybereproducedinanymannerwithoutthepriorwrittenpermissionofBarclays.
BarclaysisatradingnameofBarclaysBankUKPLCanditssubsidiaries.BarclaysBankUKPLCisauthorisedbythePrudentialRegulationAuthorityandregulatedbytheFinancialConductAuthorityandthePrudentialRegulationAuthority(FinancialServicesRegisterNo.759676).RegisteredinEngland.Registerednumberis9740322withregisteredofficeat1ChurchillPlace,LondonE145HP.
April2018.BD05915-02.
15of15