0% found this document useful (0 votes)
15 views11 pages

Risk & Security Value Chain Analysis

Risk and security are inherently intertwined with value chains due to their influence on the creation and production of value within organizations. Measuring risk and security across value chains is challenging due to differing definitions, lack of visibility, and their influence across many activities. Moreover, risk and security analysis is made more difficult by the dependence of value chains on secure environments and an increasingly uncertain threat landscape.

Uploaded by

aggibudiman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views11 pages

Risk & Security Value Chain Analysis

Risk and security are inherently intertwined with value chains due to their influence on the creation and production of value within organizations. Measuring risk and security across value chains is challenging due to differing definitions, lack of visibility, and their influence across many activities. Moreover, risk and security analysis is made more difficult by the dependence of value chains on secure environments and an increasingly uncertain threat landscape.

Uploaded by

aggibudiman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Value Chain Analysis (Risk & Security)

Protection, Measurement & Co-Creation Challenges

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Risk and security value chains are inherently and uniquely different.

Because risk and security both co-create value, acts as units of


measure/analysis and protect value chain elements and processes.

In other words, when done well, especially within a global context, risk and
security are virtually impossible to decouple from value chains due to the ever-
present and changing influences that both risk and security have on the
creation and production of value within organisations, communities and
nations.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Moreover, different actors within the risk and security


vocation, profession or discipline may represent and influence
value chains at differing times, scales and reasons.

Furthermore, no single risk or security actor or individual may


have full visibility and influence across the entire value chain
reality or theoretical model.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Value Streams

While value streams such as planning, building, delivery and operational


outputs (running) create value, supporting activities and other intangibles
contribute in a significant, meaningful way, further obfuscating valuation,
analysis and measurement.

Therefore, how do you measure risk and security within one or more value
chains?

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

The first of many practical issues of complexity and scale is


that of definitions, knowledge and information.

More specifically risk and security definitions vary


wildly within a single organisation, let alone across supply
chains, communities, cultures and borders.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

In other words, nobody is measuring the same 'thing' when it


comes to risk and security because they aren't even using a
single, unifying and consistent definition or interpretation of
what risk and security is.

These definitions rarely remain constant over spatiotemporal


variances and decay either.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Supporting Activities

Risk and security have become interwoven and indiscernible within supporting
activities, when it comes to value chain/s.

That is risk and security have become the primary areas of concentration where
risk and security practices are most visible, frequent and represented.

This is the land of risk registers, security risk assessments, cybersecurity, and
third party risk management themes, labels and tribal devotees.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

It is worth noting that production of risk and security artefacts such


as registers in the same of each vocation and discipline is neither
value creation nor representative of each of the professions, let alone
science/s.

They are one of many tools, process and practices, albeit routinely
superficial, wrong and misleading... risk registers that is.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

In sum, risk and security value chain analysis is an


inherently unique and problematic challenge as both
offer visible and invisible degrees of support,
dependence and measurement in any contemporary
value chain or creation process.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]
Value Chain Analysis: Risk & Security

Even more so, where people, product, information and assets


are stored, managed or accessed in environments where
threat actors, criminals, fraudulent/deceptive actors,
adversaries and other hostile actors exist.... particularly during
a current/post-pandemic world of brittle, anxious, non-linear
and incomprehensible (BANI) threats, hazards, risks and
danger.

Tony Ridley MSc CSyP CAS MSyl


Risk, Security, Safety, Resilience & Management Sciences (Applied) [Link]

Common questions

Powered by AI

Intangible support activities are crucial in the assessment and management of risk and security within value chains because they provide the foundational processes and practices that underpin formal risk management efforts, such as cybersecurity measures and third-party risk management. These activities can be complex to measure and analyze but are integral in maintaining the efficacy and resiliency of overall risk strategies, revealing dependencies that may not immediately relate to direct value creation but are essential for organizational security and stability .

The production of risk and security artifacts does not represent true value creation because these tools are often seen as ends in themselves rather than means to achieve broader objectives in risk management. They may underrepresent the complexity and nuanced contributions of risk and security practices, potentially leading to missed opportunities for enhancing organizational value and resilience. Consequently, organizations might focus excessively on compliance and documentation rather than developing robust, dynamic strategies that adapt to evolving threats and circumstances .

Risk and security contribute to value chains by co-creating and protecting value, acting as units of measurement and analysis. They are challenging to decouple because they significantly influence the creation and production of value, especially in a global context where risks and security needs dynamically change. The interconnectedness and variability of risk and security within different areas of value chains make them integral and inseparable from value creation .

Risk and security have become deeply interwoven with supporting activities in value chains through common practices such as risk registers, security risk assessments, and cybersecurity protocols. These areas are where risk management and security practices are most visible and frequent. The implications for organizations include a need for continual adaptation to manage and mitigate risks, better alignment of processes with security measures, and possible adoption of comprehensive strategies that consider these intertwined elements for maintaining value chain integrity .

The BANI concept highlights the complexity and unpredictability of modern challenges, which significantly impact risk and security management in value chains. It suggests that traditional linear approaches to risk management might be insufficient, necessitating more flexible and adaptive strategies that can respond to brittleness, anxiety, non-linearity, and incomprehensibility. This impacts how organizations anticipate and counteract potential threats, necessitating a shift towards more resilient and innovative risk management techniques .

Different actors in the risk and security disciplines influence value chain elements at varying times, scales, and reasons by providing expertise and policies tailored to specific contexts. However, their influence might be limited due to the lack of a unified perspective across the entire value chain, diverse and shifting definitions of risk, and the challenge of aligning strategies across different regions and supply chains. Each actor's influence can be constrained by their limited visibility and partial understanding of the broader value chain complexities .

Risk registers, while widely used, are criticized as superficial because they often do not truly represent the depth of risk management and can be misleading by oversimplifying complex risk factors. They are merely tools within the risk management process and sometimes fail to account for the dynamic and multifaceted nature of risks in value chains. The document highlights that risk registers are not reflective of risk or security professions’ practices and do not directly contribute to value creation .

Definitions of risk and security vary within and across organizations due to differing interpretations, cultural perspectives, and evolving risks that change over time and across locations. These variations pose challenges in value chain analysis as they lead to inconsistencies in understanding and measuring risk and security, resulting in potential misunderstandings and misalignments in risk management practices across entities within the value chain .

The variability of risk and security definitions across supply chains affects management globally by creating challenges in consistently applying and communicating risk strategies, leading to potential gaps in risk and security coverage. Organizations may experience difficulties in aligning policies and enforcing measures that are coherent across different geopolitical and cultural contexts, which can result in vulnerabilities and inefficiencies in mitigating risks effectively .

Supporting activities contribute to the obscurity of measuring risk and security in value chains by introducing complexity through intangible factors that are difficult to quantify, such as trust, cultural practices, and informal risk assessments. These activities are integral to operations but may not align neatly with conventional metrics, creating a challenge in assessing their true impact on value co-creation and protection. This obscurity necessitates innovative approaches to measurement that consider these indirect, yet significant, contributions to risk and security management .

You might also like