

Chief Information Officer, JTK

IT Service Management and IT Project Management Expert, GS
Geopolitical uncertainty, the rise of cyber threats, and our dependence on digital services make technological capability an even greater security issue.
As companies become increasingly dependent on technology, not all critical technology is in the hands of the company. Cloud services, external IT vendors, digital services, and artificial intelligence solutions have become an increasingly important part of business-critical operations.
Companies are often also part of another company's supply or service chain. When one operator's operations are disrupted, the effects quickly spread to others.
We discussed the topic with the Chief Information Officer of the Joint Research Centre (JRK). Satu Koskisen, who also works on preparedness, artificial intelligence and cybersecurity in both Finland's security of supply work and in the European Commission's tasks, and Graniitti's IT service management and IT project management expert Kati Ahtiainen with.
”Companies usually know what the key services are that they deliver to their customers. But do they also know what internal functions those services consist of and what IT systems are needed to produce them?” Kati Ahtiainen asks.
”The answer may seem obvious, but in many cases of serious disruption, it is discovered that there are underlying dependencies that have not been taken into account or documented. This can prolong the recovery from the disruption.”
The dependencies of critical services are not limited to the company's own systems. Partners and supply chains must also be identified.
”"This is absolutely true. Companies should first have a clear list of systems, their ownership and the dependencies of the entire system spectrum. This is not enough, we should also understand who our critical service-related partners are, and what we will do in the event of potential supply chain disruptions,", Satu Koskinen stress.
”Going deeper than this, there should be a recovery plan for each system. How will the entire environment recover from a disruption? Additionally, a decision should be made for each system as part of the whole about what the level of backup solution is,”, Koskinen continue.
”This is a completely business decision, but this discussion may sometimes not be had between IT and business in companies.”
Resilience should also be discussed within the company's management and board. Ultimately, it is about how well the company knows its own ability to survive a serious disruption.
”"In how many companies do the board, management team, or even experts know how quickly they recover from various disruptions?"” Ahtiainen ponders.
”In my experience, this question is asked too rarely in boards of directors, the knowledge in management teams may already be at a better level, but even an expert-level answer may not necessarily come from a pharmacy shelf,” Koskinen says.
Koskinen would like to see the issue come to the fore more strongly in Finnish companies.
”"This is something I would like Finnish companies to focus on in the coming years, because recovering from disruptions is part of our society's resilience to crises!"”
The changing technology and supplier environment also presents its own challenges in terms of preparedness.
”When environments change, the critical service delivery chain may not be updated with the changes made, whether in terms of technical details or information related to suppliers and contact methods,”, Ahtiainen points out.
A company's operations can be completely dependent on services whose functionality it does not control. Cloud services, external IT suppliers, digital services and artificial intelligence solutions form entities on which the business is built. In a disruption situation, it is essential to know which services are critical to operations, what their operation depends on and how quickly they can be restored.
”"Many companies do not necessarily have sufficient expertise to investigate matters related to preparedness. It requires expertise and time. At first, the investigation may seem quite laborious, but in capable hands, the investigation can be completed relatively quickly,", Koskinen evaluate.
”What do we do now?” shouldn’t be the first question when a critical IT service goes down. The answer should be known before anything goes wrong.
Resiliency needs to be discussed openly and broadly across the organization. IT needs to know how to recover systems. But it is equally important that the business, the executive team, and the board understand how quickly critical services can be restored.
Graniitti Services conducts studies that assess a company's resilience to IT disruptions., identify areas for development and provide concrete recommendations for further action.
You can cancel your subscription at any time. Discover Privacy statement
Do you have a project or change coming up or underway that you need the perspective of an experienced expert for? Send us a message and we'll take your project to the finish line together.

Customer Relationships & Sales

CEO, Sales

Sales, public