Case Studies | Our Work & Expertise | Inoni

BCM for SaaS Software Providers | Inoni

Written by Mark Robinson | Jan 11, 2023 12:09:37 PM

“We engaged with Inoni to overhaul our incident response and business continuity programme. The success of the programme was of high importance to our business leaders, our investors and our financial services clients who rely on our ability to maintain ongoing business operations. Inoni delivered the programme to the highest standards, hitting the all the original objectives of the programme. Inoni clearly demonstrated industry best practice throughout the engagement and their staff were very engaged and friendly throughout. I would highly recommend them for future opportunities”

Client CTO

 

The client

Our client is a provider of client onboarding lifecycle management software for corporations, investment banks, and private banks. We were invited to develop their business continuity plan (BCP) and management system because we showed we could build a high-quality solution quickly and painlessly, evolving easily as they grow.

 

 

Their objectives

  • They already had a business continuity plan (BCP) but needed materials capable of withstanding scrutiny by their demanding customer base - mainly financial institutions and banks.
  • They wanted a structure and framework for managing major incidents effectively, avoiding a “headless chicken” response.
  • They wanted to be able to test their plans realistically to demonstrate their capability and provide assurance to customers.

Our approach

Fast and painless delivery of the project

Working virtually, we liaised frequently with the client’s internal risk team to understand their pre-existing BCP and collect related information. We spoke to representatives from each department to understand and map their dependencies, then ran a handful of workshops with key members of the management team to validate, develop and share our insights. Our consultants then populated the online system, generating draft documentation for evaluation and adoption by the client. This concentrated first phase was completed in eight weeks.

 

 

Project outcomes

We built a client-dedicated standards-aligned Business Continuity Management System (BCMS)

It included the following automated documents:

  • Business Impact Analysis and Risk Assessment – providing a detailed analysis of the business from a continuity perspective. It identifies critical business services, specifies recovery deadlines in a major incident, and defines the continuity scenarios the business faces and must plan for.
  • Business Continuity Plan – providing a step-by-step decision guide, role-task allocation and information to enable recovery from continuity-threatening incidents. 
    • Scenario runbooks – provides detailed but easy-to-read responses to each identified scenario.
    • Role cards – anyone with a designated BCP responsibility received one of these, detailing their specific role tasks and requirements when responding to a continuity incident.
  • Framework – demonstrating alignment with ISO 22301 and defining the components of the business continuity programme.

We helped develop BC capability through training and exercising

This activity was new for many staff, so we aimed to build their knowledge, familiarity and capability gradually and consistently to ensure their response to major incidents is as smooth and effective as possible. The stages we took were:

  • Walkthrough with the business continuity committee, providing top-level validation, agreement and understanding of the Business Continuity Management System.
  • Virtual training with all role assignees, introducing them to the plan, the strategies and their assigned roles.
  • Development of online training modules, integrated into the client’s internal LMS (Learning Management System), which gave our client the ability to regularly refresh all staff on their business continuity arrangements.
  • Virtual incident simulation against a challenging information security scenario, which provided the opportunity to further enhance individual capabilities, build their confidence, and test the effectiveness of the BCP.

Our software accelerated delivery, supporting ongoing maintenance and effective document management

  • Our consultants developed end-to-end standards-aligned documentation using the Inoni SaaS system. 
  • The client can now access to the system to easily manage change themselves.
  • A dependency map helps them visualise their business, identify single points of failures and trace scenario effects on critical business services.
  • All business continuity role assignees have read-only access to the latest version of documents and plan, from any device, anywhere.