1、Operational Resilience Tooling Panorama 2024Navigating the evolving tooling landscape2Summary1.Introduction Introduction32.Dataset OverviewFunctional categories4Total vendors4New vendors in scope43.Category SpotlightDeep-dive into the 6 key functional categories54.Must-know Trends&Challenges Trends7
2、Challenges95.Whats Next?The future&SME comments103IntroductionThis report delves into the evolving tooling landscape for operational resilience,highlighting the top vendor functionalities and outlining critical considerations for organisations seeking to implement these tools effectively.Our 2024 Op
3、erational Resilience Tooling Panorama highlights a major turning point.Market demands are driving a surge in the adoption of unified operational resilience solutions.This report delves into the evolving tooling landscape,outlining the vendor functionalities,key trends and critical considerations for
4、 organisations seeking to implement these tools effectively.Our vendor selection encompasses a spectrum of firm sizes,ranging from small to very large vendors.Notably,over 75%of the vendors offer their services globally.Medium-sized vendors appear more than twice as often as large or mid-large vendo
5、rs across the Operational Resilience tooling categories.This suggests that more businesses are opting for agile,customisable,solutions.Potentially,with lower costs,and direct access to decision-makers,compared to those associated with large-size vendors.30%46%19%18%11%Vendor ScaleSmall Firms(1 to 50
6、 employed)Medium Firms(51 to 250 employed)Mid-Large Firms(250 to 1000employed)Large Firms (1000 employed)Very Large Firms(10,000 employed)Medium-sized vendors are seen twice more than large or mid-large vendors across all the Operational Resilience tooling categories.4Dataset OverviewIn contrast to
7、last years Operational Resilience Tooling Panorama,vendors are now offering tools in unified platforms with a wider range of functionalities,rather than focusing on a single functionality,as seen previously.Thus,our 2024 Tooling Panorama focuses on the vendors themselves,rather than the various tool
8、s offered by each vendor.This year,we examined 143 vendors across six functional categories.Here is a breakdown of the number of vendors offered across the various categories,identified by the 2024 Tooling Panorama.Of these 143 vendors,our 2024 Tooling Panorama has identified 22 new vendors in the m
9、arket,with the largest proportion of vendors falling under the Governance,Reporting,and Learning category.6 6143 143 2222Total VendorsNew Vendors in ScopeFunctional CategoriesFunctional CategoryNo.of VendorsBusiness Service Mapping08Crisis response44Technology and Cyber Resilience26Resilience and Re
10、covery Planning15Third-Party Risk Resilience 16Governance,Reporting and Learning345Lets deep dive into the 6 functional categories,exploring the market leaders*and key capabilities.1 Business Service MappingBusiness service mapping tools help organisations to identify critical business services,map
11、processes to assets and dependencies,and conduct impact assessments.These tools often have capabilities which support the visualisation of upstream and downstream business processes,illustrating critical dependencies and clarifying how various parts of the IT infrastructure are connected and how the
12、y function together.Game-Changing Capabilities:A unified platform capturing critical dependencies and offering a holistic view of people,processes,and technology.Doing so by connecting to the existing referential,in addition to the use of powerful data modelling and analytics capabilities to generat
13、e a clear picture of your entire organisation.2 Third-Party Risk Resilience:Third-party risk management(TPRM)toolsassess all potential risks posed by vendors and other third-party relationships,enabling organisations to define strategies to mitigate their risk exposure.These tools act as a central r
14、epository for storing and managing vital third-party information including contracts,risk assessments,etc.Additionally,these tools detail Environmental,Social,and Governance(ESG)and other regulatory requirements specific to business operations.Game-Changing Capabilities:Tool(s)offering robust dashbo
15、arding capabilities that provide a centralised view of third-party risk information and real-time monitoring.Efficient vendor management from vendor onboarding to contract life cycle management,is crucial.A tool with an embedded questionnaire-creator is a plus,which enables users to create tailored
16、questionnaires,specific to their needs.3 Resilience and Recovery PlanningThese tools safeguard business continuity and ensure rapid recovery during adverse events.Disaster Recovery(DR)features in these tools allow users to create,store,and manage recovery plans for the rapid restoration of data,appl
17、ications,and critical functions during or after unforeseen disruption(s).This proactive preparedness will help organisations to minimise downtime during an unexpected event.Category SpotlightCategory SpotlightMarket leaders:In addition to the six functional categories,our 2024 Operational Resilience
18、 Tooling Panorama further classifies tools within each of the following categories:Broad:Tools that offer functionalities beyond the specific area,providing a wide range of capabilities.Standard:Tools which focus solely on functionalities specific to that topic area.Niche:Tools which provide an in-d
19、epth focus on specific functionalities within the topic area.*Market leaders for each functional category are identified based on recent Gartner and Forrester reports.Market leaders:6Game-Changing Capabilities:Tool(s)offering a centralised,intuitive platform for the management of all aspects of DR p
20、reparedness,in turn,facilitating continuous improvement.Additionally,enabling collaboration between different departments involved in DR planning and execution,enhancing cross-departmental synergy.4 Technology and Cyber ResilienceThe category functionality includes creating secure data backups and e
21、nabling data restoration in the event of a cyberattack or any other disruption to the IT infrastructure.It also includes features such as backup generators and technical disaster recovery mechanisms to maintain operations during unforeseen events.Game-Changing Capabilities:Tool(s)which provide compr
22、ehensive backup and recovery solutions to protect data wherever it resides:virtually,physically and in the cloud.Automated backup schedules and instant disaster recovery capabilities offered by such tools ensure consistent data integrity with minimal human intervention.5 Crisis ResponseThis category
23、 encompasses critical event management functionalities for maintaining business continuity while also ensuring that your organisation has effective response strategies in place.They facilitate the management of business incidents by logging events,producing mass emergency notifications,and supportin
24、g appropriate escalation(s).Additionally,crisis exercise platforms provide environments for training and testing crisis simulations.Game-Changing Capabilities:Unified platforms that offer multichannel real-time alerts.Look out for vendors that offer 24/7 threat monitoring to immediately detect threa
25、ts,assess their impact,and respond accordingly.The tool must have ability to run incident simulations/exercises and seamlessly compare them with real-time data to refine crisis response strategies and make data-driven decisions to deliver business continuity.6 Governance,Reporting,and LearningVendor
26、s within this category offer comprehensive solutions for managing risks,incidents and compliance policies.Almost 1/4 of the tools in this category provide employee training systems such as Learning Management Systems(LMS)and E-learning Authoring Platforms.This category establishes processes for ongo
27、ing monitoring,reporting,and quantification of resilience efforts.Game-Changing Capabilities:Tool(s)which offer robust reporting,and metric features to help organisations to track compliance efforts and manage risks effectively.Real-time monitoring and reporting dashboards as well as AI-driven insig
28、hts can support senior management to improve their decision making.Market leaders:Market leaders:Category SpotlightMarket leaders:Market leaders:Critical considerations:A tool that can be scaled and customised to your organisations requirement A tool that can facilitate collaboration and integrates
29、datapoints across cloud,on-premises,and hybrid environments A tool with a wide range of features beyond specific niche functionalities*Market leaders for each functional category are identified based on recent Gartner and Forrester reports.71 The Market Shifts Towards Unified Platforms with Integrat
30、ion CapabilitiesThis trend was observed in 2023 Operational Resilience Tooling Panorama,but it is more pronounced in 2024,with nearly 2/3 of tools operating as unified resilience platforms with broad functionalities.SureCloud,Allgress,Archer,Logic Manager,MetricSream,Riskonnect,NorthGRC and many mor
31、e vendors in the Governance,Reporting,and Learning category offers a single pane of glass view of risk management,third-party risk,compliance,incident management,and business continuity capabilities.However,there are vendors that have additional functionalities along with their niche characteristics
32、.For example,Everbridge,Kinetic Global,OnSolve,RockDove Solutions and Ascent Business vendors within the Crisis Response category not only offer mass notifications,but also incident alerting,and threat/risk intelligence.Meanwhile,vendors like AIM,Virtual Corp,Gieom,Quantivate and C2 Meridian from th
33、e Resilience and Recovery category are now encompassing business process improvement,business/IT continuity management,risk,compliance and incident management capabilities.2 Operational Resilience tools are Incorporating AI&AutomationThis trend was observed in at least 10%of the vendors from our 202
34、4 Operational Resilience Tooling Panorama.Vendors such as Coupa,UpGuard,Black Kite,Prevalent,and ProcessBolt from the Third-Party Risk Management and Resilience category use AI algorithms to automate the completion of security questionnaires from historical data,to check for regulatory/compliance re
35、quirements and to identify potential threats.Governance,Reporting,and Learning vendors like ServiceNow and OneTrust use AI to analyse data metrics aiding in threat anticipation,performance monitoring,and the identification of gaps.Additionally,vendors that offer Learning Management Systems like Doce
36、bo,Litmos and LearnUpon have integrated AI capabilities to personalise the overall learning experience.Commvault,Veeam,and Rubrik of the Technology and Cyber Resilience vendor category utilise AI for vulnerability scanning and the classification of backups which help to swiftly isolate and recover c
37、leaned data.Furthermore,Crisis Management vendors such as Everbridge and Rave Mobile Safety leverage AI for THE MARKET IS SHIFTING TOWARDS UNIFIED PLATFORMS WITH INTEGRATION CAPABILITIES12OPERATIONAL RESILIENCE TOOLS ARE INCORPORATING AI&AUTOMATION3NEW REGULATIONS ARE DRIVING THE OPERATIONAL RESILIE
38、NCE TOOLING TO INCLUDE COMPLIANCE CAPABILITIES4OPERATIONAL RESILIENCE TOOLS UTILISE VISUALISATION TECHNIQUES FOR ANALYTICS AND METRICS4 Must-Know Trends Through comprehensive observation of the most relevant tooling vendors from our 2024 Operational Resilience Tooling Panorama,we have established 4
39、key trends present across all:8incident reporting and the automation of workflow triggers which can help to reduce the workload of human responders.3 New regulations are driving Operational Resilience tooling to include compliance capabilitiesAlmost all of the vendors within the Governance,Reporting
40、 and Learning category have compliance modules,for example,LogicGate,SAI Global and MetricStream.More than 3/4 of the Third-Party Risk Management vendors,such as Brooklyn Solutions,Black Kite,and Process Unity feature compliance modules and almost half the vendors in Resilience and Recovery Planning
41、 category,including 4C Strategies,AIM,MEGA and C2 Meridian demonstrate this trend.In response to an increasing emphasis placed on sustainability and corporate social responsibility,many vendors featured in our 2024 Tooling Panorama offer Environmental,Social,and Governance(ESG)compliant solutions an
42、d incorporate third party ESG assessments into their tooling solutions.More specifically,many vendors within the Governance,Reporting and Learning Category,such as Diligent,Mastercard,SAI Global and almost half of the vendors within the Third-Party Risk Management category like,Brooklyn Solutions,Pr
43、evalent,Sphere and Certa,have incorporated ESG compliance features.4 Operational Resilience tools utilise visualisation techniques for analytics and metricsAnalytics,metrics,and visualisations empower organisations to gain a deeper understanding of their environments,identify patterns and risks,and
44、foster collaboration.The above-mentioned features are more notable within the Business Service Mapping category with vendors like Fusion Risk Management and Avolution and the Governance,Reporting,and Learning category through vendors such as SAI Global and Allgress.Furthermore,tools such as UpGuard,
45、Coupa,and Process Unity from the Third-Party Risk Management category also offer a visually-driven approach to risk assessments,with advanced analytics and metrics.Perhaps,an easy-to-use,customisable platform will enable users from varying technical backgrounds to navigate and derive insights from a
46、ny type of data.Main Challenges9Main ChallengesReflecting on the hardships that confront organisations today,we have collated some important challenges prevalent across their tooling landscapes:1 Legacy Tech,Siloed Estates and Complex Internal Operating Models Hinder ResilienceThe Financial Conduct
47、Authority recently announced that 92%of financial services firms still rely on legacy tech and 60%of CTOs felt incorporating modern applications.into their legacy tech was too challenging,requiring extensive configuration and staff training,adding to the cost burden.In 2020,HM Revenue&Customs spent
48、53.2 million patching legacy systems rather than modernising them,providing a real-world example of the statistics.In contrast,far too many companies strive to always have the newest,most efficient technologies which leads to overcomplicated and overloaded operating models.Organisations often rely o
49、n tools that operate in silos,lacking strong connections and data exchange functionalities.64%of business data remains trapped in silos(Gartner 2024),hindering its use for critical decision-making.Organisations tool selection can be often shortsighted.Some focus on user needs or specific tool functi
50、onalities,while others prioritise plugging capability gaps or addressing resilience weaknesses.Factors such as these run the risk of introducing too many tools to an enterprise,forcing tooling to become siloed and often duplicated.This leads to the increased complexity of the estate that is often no
51、t aligned to the organisations Target Operating Model.Drawing from the above,it is important for firms to define a holistic,enterprise-wide tooling strategy that moves away from a siloed and over-complicated landscape.2 The Data Gap:When Tools Cant Keep UpA report by Gartner states that 80%of busine
52、ss disruptions are caused by data loss or inaccessibility,emphasising the importance of flexible data management within operational resilience tools.Clients struggle with tools that cannot accept the specific file formats used within the business landscape.This inability creates a data gap as users
53、avoid uploading crucial documents concerning risk,business continuity plans,incident reports,threat scenarios,etc.A study by Veritas Technologies found that 56%of organisations admit to having data gaps in their disaster recovery plans impacting their recovery times.Organisations with limited data v
54、isibility will experience 23%higher business disruption costs(Ponemon Institute,2023).And to address this issue,organisations must opt for a resilient tool that can be tailored to unique environments and requirements,as highlighted in the critical considerations raised in our category spotlights sec
55、tion.Main ChallengesLEGACY TECH,SILOED ESTATES AND COMPLEX INTERNAL OPERATING MODELS HINDER RESILIENCE12THE DATA GAP:WHEN TOOLS CANT KEEP UP10Whats Next?The tooling landscape is rapidly evolving with AI,unified platforms,and collaboration.Below lie the 4 main tool functionalities we expect to see in
56、 our 2025 Tooling Panorama.Stay tuned!1.Highly adaptable tools that facilitate seamless upstream and downstream data flow regardless of data format restriction,empowering organisations to manage data effectively within their unique environments2.Organisations increasing focus on stress-testing resil
57、ience in the face of dynamic changes reflects an increase in tools incorporating training and exercise platforms3.Shattering siloed risk management tools with the introduction of unified platforms converging internal and third-party risks to deliver a holistic view of organisational risks4.Tools off
58、ering secure,tamper-proof platforms for companies,vendors,and regulators to store,share,and access real-time critical market risk information,including emerging vendor-specific regulationsWhats Next?“We will be watching new releases from different vendors over the next few months and fully expect mo
59、re offerings to allow easier end-to-end testing,risk management and third-party due diligence,as these are key requirements from regulations across countries and even sectors(FCA,PRA,DORA,NIS 2).”Roxane Bohin,Operational Resilience Expert11AuthorsRoxane BohinManagerNigna AnilConsultantRN Tom ClokeyA
60、nalystT Marianna TsigkounakiA12About WavestoneWavestone is a consulting powerhouse,dedicated to supporting strategic transformations of businesses and organisations in a world that is undergoing unprecedented change,with the ambition to create positive and long-lasting impacts for all its stakeholde
61、rs.Drawing on more than 5,500 employees in 17 countries across Europe,North America and Asia,the firm offers a 360 portfolio of high-value consulting services,combining seamlessly first-class sector expertise with a wide range of cross-industry capabilities.Wavestone is listed on Euronext Paris and recognised as a Great Place to W