top of page

IT Cyber Risk & Compliance - Delivering Timely Value and Ongoing Success

  • Jun 22
  • 4 min read

The Situation and Challenge


XCF were engaged by a clients Chief Information Security Officer (CISO) implementing IT and Cyber - Policy, Risk and Compliance capabilities on a leading GRC platform. The client is a leading global provider of products and services for industrial assembly. The implementation scope was to cover the organisations’ data and information security needs in the first instance; broader use may follow. Technology is critical for the organisation in differing scenarios including its’ products and services where, among other things, technology is used in (i) the fabrication and manufacturing  of more than 1M products and (ii) the delivery of services such as automated warehousing and ordering systems used by its’ clients. 


The organisation has a business need to adhere to obligations from various certifications and regulations that might be (i) globally recognised (e.g. NIST, IS027001); (ii) regional or country specific;  (iii) industry specific (e.g. meet safety certifications for the car or aviation industry). These obligations are required to meet the requirements of their current and prospective clients, and to protect the integrity of their products and services. The organisations’ businesses are organisationally fragmented and autonomous with no firm-wide information security related, policies, standards and processes, there are various localised resource intensive process to meet the various obligations. It is challenging for the board to get a clear and comprehensive understanding of the status of the various obligations across the firm and any associated risks. The CISO role was new within the firm; the individual in the role was also new to the firm and  cognizant of the current culture and practises. Despite the budgetary authorisation there was little-to-no awareness of the impending transformation within the businesses. 


With the situation in mind, the clients intended implementation and rollout approach, plans and expectations were conservative, and over an extended period. The client recognised there was a significant volume of activity required supplementary to the introduction of the GRC platform itself, it was envisaged that it would be at least twelve months before the platform would go live in any form, followed by a couple of years for a full rollout. 


What XCF Consulting Did 


XCF worked with the CISO and team to  (i) familiarise and train them on the GRC Platform and processes; (ii) crystalise their objectives and identify challenges in meeting the objectives. There was ready acknowledgement and understanding that they were undertaking a business transformation and not purely a technology implementation. Accordingly, there was upfront recognition of areas that required work in addition to the delivery of new processes and technology;  things like, but not limited to (i) clarification about ownership of risk, (ii) roles and responsibilities, (iii) policies and standards, (iv) prioritisation of the transformation within the business areas and (v) identification of technology and data assets. The conservative expectations on progress were coupled with an anxiety that there was a need to get things 100% right upfront to win the businesses over, gain credibility and make progress.


XCF spent time with the CISO and team bringing to life the experiences with clients undertaking similar transformations dealing with challenges that are both cultural and practical in nature, and the approaches that XCF have successfully deployed to address the challenges with clients in the past. There should always be disciplined and diligent upfront planning and budgeting; however, in undertaking transformations of this nature companies often learn and uncover things they might not initially know,  and also business priorities change. The reality of such transformations is time and/or effort may be different than initially anticipated; there is greater credibility in such situations (particularly concerning delays or increases in spend) if there is clear and visible evidence of having already delivered material business value. Additionally delaying and backloading implementation ( “to get things right” ) can create a toxic mix of delayed delivery and value, mixed in with any significant issues and risks that have arisen;  this toxic mix can create an environment where the  perception and/or reality of failure takes hold. Among other things success will come from the timely delivery of appropriate value which must be underpinned by delivery agility and optionality as new and changing information arises.


From the discussions various focus area were established, the following should be highlighted as being key:


  • Planning - a focus on business value and agility :


    • Plans were established to target a first delivery and implementation. Policy capability was rolled out in around 4 months; the implementation created immediate material business value (operationally and in underpinning the transformation activities). This initial delivery created visibility and credibility that was the catalyst for focused business engagement. 


    • Two capability areas were targeted for the second delivery, and each was progressed in parallel with a view that either would be implemented at the earliest opportunity and business units would be onboarded when ready. Business prioritisation was encouraged by the board who were keen for businesses to adopt the new capabilities and value that was being made available at the earliest opportunities.


  • Reporting Strategy - a focus on status and what is expected:


    • Reporting was established that looked at the key (i) operational aspects of the system and processes, (ii) business onboarding and adoption of the deliveries and (iii) metrics were devised that focused on highlighting desired and undesired characteristics and behaviours. The reporting, with league table style business comparisons and the board keenness for adoption drove businesses to prioritse.


  • Business Engagement - a focus on communication, education and operating model:


    • XCF worked with the CISO and team on communication, operating model and training materials; the CISO team engaged XCF directly in sessions with colleagues when required to provide a breadth of perspective.


    • The communication transparently and openly articulated the desire to move forward in a timely manner with an initial solution that will evolve from an imperfect initial start, there would be compromise but the businesses timely engagement will ensure the right balance in any solution.


Delivering Timely Value and Success


XCF helped the client successfully implement and generate value from the transformation and GRC product much earlier than expected. The GRC product is used as an enabling tool for the final state and to enable the  successful transformation journey. The client and its business units understood that the details of the plans they make may change but what is critical is ensuring the (i) focus on the direction, (ii) delivery of value and (iii) ongoing positive momentum.

 
 
 

Comments


bottom of page