Dr Justin Okoli (PhD) – Written evidence (RSK0061)
Senior Lecturer, Leicester Castle Business School, De Montfort University
This is an individual submission
Brief Bio: Justin is a Senior Lecturer in Crisis & Business Continuity Management at Leicester Castle Business School, De Montfort University after previously working at Coventry Business School as lecturer in cyber security management. Justin is involved with teaching and research on the MBA, MSc and UG programmes. He is a member of the centre for Decision Analysis and Risk Management at Middlesex University where he obtained his PhD in 2015. Justin's work explored the decision-making strategies used by experienced emergency responders when solving complex tasks in dynamic and high-staked environments. Recently his research interest is focused on managing cyber risks and understanding how computer end users make security decisions, mainly from a cognitive and human factor perspective.
Reason for submitting evidence: I have been teaching and researching on the subject of risk and crisis management for over 10 years and found this opportunity particularly timely and relevant to lend my voice to such a strategic discourse of national importance.
What are the most significant extreme risks that the UK faces? Are these kinds of risks discrete, linked or systemic? What do you understand the term ‘extreme risk’ to mean?
- Risks are everywhere – they are with us, around us, and they largely influence the way we act both individually and collectively. The view that a riskless society exists is not only mythical but extremely misleading. With advancements in technology and increased innovative capabilities, the risk landscape of every society will always be dynamic and emergent. But as the resources available to manage these risks are limited, risk prioritisation becomes an important consideration for risk management.
- Between 2017 and the time of this publication in 2021, the UK has faced notable disruptions ranging from medium to high scale terrorist attacks (e.g. in London Bridge and Streatham); the collapse of strong business empires such as Thomas Cook Group, Carillion, and more recently Debenhams and the Arcadia group; natural hazards such as the ‘Beast from the East’ winter storm and high scale flooding across various parts of the country; threats associated with chemical weapons in Amesbury and Salisbury and Amesbury; and the ongoing COVID-19 global pandemic (UK national risk register 2020). Also, as many businesses were legally required to respond to the UK government’s guidelines in relation to reducing the transmission of the coronavirus, a significant number of firms subsequently authorised homeworking arrangements for their employees. Whist telecommuting offered a quick fix to any potential business continuity issues amidst the pandemic, this was not without a cost. The rate of cyber-attacks and privacy risks continues to burgeon both in the UK and abroad as cyber criminals are now able to perpetuate their malicious acts against a wider “client-base”, an omen that is particularly plausible with companies lacking the strategic will to raise cyber resilience and awareness amongst their employees.
- Modern day risks are hardly ever linear or discrete; a single risk factor could impact upon a system in both direct and indirect ways, and sometimes create a perfect storm for the more significant risks to occur. As the dependencies between people, systems and societies continue to increase – what Perrow (1984) termed tight coupling, problems inevitably tend to jump from one system to another. For instance:
‾ A mortgage crisis in the United States as observed in the 2009 financial crisis was found to undermine foreign exchange transactions in the UK.
‾ A coronavirus reportedly originating in Wuhan China has significantly destabilized economic and social order in cities across the world.
‾ A war in Syria was somehow able to trigger immigration crises in Europe
- In light of the above, I conceptualise extreme risks as distinct sets of non-routine or intricate activities that often exceed the coping capacity of those tasked with decision-making and potentially result in catastrophic damages to both human and non-human resources, and for which rapid intervention protocols would be required to exert control and/or limit the severity of possible losses.
Are there types of risks to which the UK is particularly vulnerable or for which it is poorly prepared? What are the reasons for this?
- Frankly speaking, telling the risks a country is specifically vulnerable to, or ill-prepared for, is often difficult. This is because we never really know for a surety, until a disaster strikes, by which time the failure to anticipate and prepare becomes apparent. This is arguably the most difficult task facing policy makers i.e. being able to predict the main risks their constituencies are vulnerable to, and effectively planning, testing and exercising around those risks to enhance resilience. Having said this, there is compelling evidence to suggest that the risks of cyber-attacks at private, public and inter-governmental levels is one that could hardly be ignored, particularly in a constantly growing digital economy. Recent WEF (2020) research shows that more than 50% of the world’s population is now online, with roughly one million people coming online for the first time every single day, and two-thirds of the world population owning at least one mobile device. Moreso, with more working remotely, there has been a sharp rise in cyber-attacks on popular videoconferencing platforms.
- The probability of the risk of cyber-attacks in the UK is also reflected in the recently published 2020 national risk register, with the risk classified as medium to high (25-125/out of 500) on the probability scale. Collectively as a country, the UK seems vulnerable to the risk of cyber-attacks as increased reliance on the cyberspace implies hackers are more incentivised to deploy sophisticated tools that allows the exploitation and manipulation of naïve computer end-users e.g. through simple social engineering tricks. These malicious tools have also become easier and cheaper to purchase compared to previous years, as cyber criminals find better ways to leverage on the fast-growing criminal networks located in various “cyber sanctuaries” —countries with little or no cyber-related regulations.
- Admittedly, all it takes to be vulnerable to the threat of cyber-attacks is having some form of reliance on IT infrastructure (hardware, software, networks) when performing one or more business operations. Whilst the assumption is for businesses to recognise the need to plan and prepare for digital risks, only few businesses are currently showing significant interest in doing just that. The trend is growing and the numbers are stacking up, but investments in cyber resilience are not moving at a similar pace. Statistics show that over 600 cyber incidents were responded to by the National Cyber Security Centre (NCSC) in 2019, and over 700 in 2020.
How could the Government’s approach to risk assessment be strengthened to ensure that it is rigorous, wide-ranging and consistent? Your answer could refer to any aspect of the risk assessment process including, for example, its governance, the evidence base, or the degree to which it is open to scrutiny and the input of experts.
- The interconnected nature of risks creates interdependencies between various stakeholders and thus calls for better collaboration in the various stages of risk management, risk governance and risk communication. More than ever, the COVID-19 pandemic has emphasised the need for cooperation and collaboration at regional and international levels, especially given that emerging risks are, by definition, risks that are likely to overwhelm the coping capacity of any single entity. In terms of collaboration, lessons could be drawn from the European Cyber Security Directive where companies managing critical networks (energy, banks, health) are required to report every IT cyber incident that has affected their normal functioning, thus enabling industry-wide learning and sharing of best practice. For this to work, firms must be reassured that disclosure of IT glitches or data breaches will not be met with hostility and that affected firms will not be unduly demonised.
- Government’s approach to risk assessment in the UK may need to be redressed to allow consideration of both the upside and downside of risks before a conclusion on possible intervention mechanism is reached. This requires balancing short-term benefits against longer-term implications through a rigorous and holistic evaluation process. This will also necessitate seeking input from relevant stakeholders – not just domain experts.
- It is impossible to create a completely safe and secure world where risk is entirely absent. Hence, being overly risk averse will do nothing but eliminate openness and transparency, stifle creativity and innovation and ultimately destroy the economic and social benefits these properties can unleash. No matter how well intended, the fact is that every single proposed intervention (e.g. full lockdown in the case of COVID-19) will likely generate a secondary risk elsewhere (e.g. monumental economic shock including job losses and business closures), with the secondary risks sometimes proving more damaging than the problem it was designed to solve.
How effectively do current ways of characterising risks (for example, the use of a five-point scoring system of a ‘reasonable worst-case scenario’) support evidence-based policy decisions? What other information would be useful?
- Whilst it is often a good idea to elucidate the most probable risks faced by a country at both local and national levels, it is equally important to clarify that no risk assessment will be able to fully identify and assess all possible risks. This is because unforeseeable risks may occasionally emerge and risks that have previously been identified could also resurface in novel ways.
- An age-long traditional method for characterising risks in high risk organisations is through the use of a risk matrix (either 3x3, 5x5 or 7x7). This provides a quick snapshot of the level of risk an entity is exposed to, typically categorised on both probability and impact dimensions. An additional benefit of a risk matrix lies in its appeal to top management, whereby each risk item is visually presented and typically adorned with colour codes (red, amber, green) that signify low, medium or high ratings. However, as the pace of events continue to grow across societies, with new risks expressing themselves in novel ways, it is increasingly becoming common knowledge that improved methods for risk characterization are needed. Relying on risk matrix or other mathematical traditional risk characterisation methods has proven to be too objective; failing to consider people’s perception and values; ignoring social, cultural and psychological aspects of risk; having a high tendency to ignore low probability but high impact events; and the notion that the respective risk estimates tend to vary across different domains of practice.
- What is crucially needed are knowledge-based estimations that offer flexibility as well as incorporate context specific variables in the estimation of risks. For instance, in my previous study with the UK fire service (Okoli et al. 2016), evidence showed that the firefighters, who are constantly exposed to hazardous conditions in dynamic and time-pressured fireground environment, were sometimes faced with novel tasks that exceeded the remit of what they have trained for. While it is worth acknowledging that rules and standard operational procedures are useful in most high-risk domains to help establish risk tolerance levels for operators, compelling evidence suggests that experts often make high stake decisions in crisis situations mostly by drawing on their experiential knowledge. Tellingly, there are limits to contingency planning; beyond this point, some incidents will require making knowledge (experiential) based decisions as opposed to rule-based decisions. This is in part because stipulated “gold standard” way of doing things may seemingly contradict current proceeding of events on the incident scene. Hence, the fact that a fire book labels a particular procedure as high risk does not necessarily warrant employing a defensive (or risk averse) strategy in real life. Risks must be evaluated in context of current informational cues, and risk owners must be trained to understand how and when to adjust their risk appetite, particularly where a tension is deemed to exist between rule based and knowledge-based decision-making.
What lessons have been learnt or should have been learnt about the approach taken to risk assessment and risk planning in this country from the COVID-19 pandemic?
- Building on lessons learnt from COVID-19 pandemic and the devastating impact it has had on the UK economy, the focus here is on improving business resilience and making firms better prepared to withstand major disruptions and to thrive amidst turbulence. A company’s viability depends on its resilience, as even the shortest downtime can bring a company to its knees. Experts estimate that 40% of small businesses close their doors permanently after experiencing a major disaster, while 80% of organisations faced with a significant business discontinuity are unable to survive without having a tested business continuity plan in place. Despite the numerous sad reports in media of companies crashing out of business – a situation that has become worsened by the ongoing COVID-19 pandemic — many SMEs still do not understand what to do to keep their business safe, and many still get mystified by constructs such as business continuity planning (BCP) and business impact analysis (BIA) which are regarded as the bedrock of enterprise-wide risk assessment.
- Business continuity is concerned with the ability of an organisation to plan for and respond to business disruptions, and thus continue to provide service to their customers at an acceptable pre-defined level. As a strategic and operational tool, business continuity management (BCM) provides an objective evaluation of a firm’s ability to continue operations in the face of risks. BCM is therefore concerned with identifying and managing the risks that threaten to disrupt essential processes and associated services, mitigating the effects of these risks, and ensuring that recovery of a process or service is achievable without significant disruption to the enterprise. It is a crucial tool for business survival in an ever-growing threat landscape and should therefore be conveyed as such to business managers in the UK, regardless of size.
- Evidence points to the fact that a significant number of UK SMEs do not have a business continuity plan, and those that have one do not fully understand how it can be utilised to deliver value for their organisation. According to the office of national statistics (ONS), the UK witnessed an increase in number of newly birthed businesses between 2018 and 2019 from 370,000 to 390,000, a birth rate of 13.0% in 2019 compared with 12.7% in 2018. On the other hand, the number of business that went on demise also rose from 311,000 to 336,000 between the same time period, a death rate of 11.2% in 2019 compared with 10.7% in 2018. The first statistics are inspiring while the latter are regrettable, further reinforcing the need for improved understanding of business resilience. Hiscock and Jones (2017) also found that many SMEs are painfully unaware of the national risk register, again underlining the importance of improved education and awareness amongst business owners at national level.
- Given that the business sector contributes relatively high dividends to the country’s GDP, it seems imperative that the UK government finds appropriate ways to create awareness amongst businesses regarding the various resilient-building tools that can enhance their crisis preparation efforts. This can be achieved by making strategic instruments such as BCP, BIA and scenario planning a mandatory training requirement for businesses, such that their ability to demonstrate competence in these resilient building tool becomes part of their core operational objectives. Funding can be provided to smaller businesses to fulfil these training requirements without which no firm would be legally allowed to operate in the UK. Indeed, desperate times call for desperate measures, especially as the country continues to navigate murky waters.
References
GOV.UK (2020) National Risk Register 2020 https://www.gov.uk/government/publications/national-risk-register-2020
Hiscock, K. and Jones, A., (2017). Assessing the extent to which the UK’s National Risk Register supports local risk management. Sustainability, 9(11), 1-15.
Office for national statistics (2019) Business demography, UK: 2019 Change in the number of UK businesses broken down by sector of the economy. https://www.ons.gov.uk/businessindustryandtrade/business/activitysizeandlocation/bulletins/businessdemography/2019
Okoli, J., Watt, J., Weller, G., & Wong, W. B. (2016). The role of expertise in dynamic risk assessment: A reflection of the problem-solving strategies used by experienced fireground commanders. Risk Management, 18(1), 4-25.
Perrow, C. B. (1984). Normal accidents: Living with high-risk technologies. New York: Basic Books.
World Economic Forum. (2016). The global risk report 2016, 15th Edition. Geneva: Word Economic Forum.
28 January 2021
7