ABNT Global Sdn Bhd

Business Continuity Plan

Introduction

ABNT Global Sdn Bhd recognizes the critical importance of ensuring the continuity of its business operations in the face of disruptive events, including natural disasters, cyber-attacks, technological failures, and other unforeseen incidents. This Business Continuity Plan (BCP) has been developed to provide a systematic approach to minimize the impact of such disruptions on the company’s operations, employees, stakeholders, and customers.

This document outlines the procedures and measures to be taken before, during, and after a disruptive event to ensure the restoration of essential business functions within the shortest time possible. It also ensures compliance with relevant regulatory requirements and industry best practices.

Objectives of the Business Continuity Plan

The primary objectives of ABNT Global’s BCP are to:

  • Protect the company’s critical operations, assets, and resources.
  • Minimize downtime and financial loss during disruptions.
  • Ensure the safety and well-being of employees, customers, and stakeholders.
  • Restore normal operations as quickly as possible following a disruptive event.
  • Maintain clear communication with stakeholders throughout the recovery process.

Scope and Coverage

The scope of this BCP includes the following:

  • All core operations, services, and activities critical to ABNT Global’s business, including project management, customer support, finance, human resources, and IT systems.
  • All physical assets, including office locations, production facilities, IT systems, and equipment.
  • Protection and continuity of employee work arrangements, including remote work capabilities and access to necessary resources.
  • Ensuring communication with customers, suppliers, employees, and stakeholders is maintained.
  • Ensuring that key suppliers and service providers have their own continuity plans, to avoid disruption of services and supplies.

Risk Assessment

A comprehensive Risk Assessment is conducted periodically to identify potential threats that could disrupt business operations. These risks include:

  • Natural Disasters: Earthquakes, floods, fires, and other weather-related events.
  • Cybersecurity Threats: Hacking, ransomware attacks, data breaches, and system failures.
  • Technological Failures: Power outages, IT infrastructure failures, and communication system breakdowns.
  • Pandemics or Health Crises: Events like COVID-19 or other health-related emergencies that may affect workforce availability and operations.
  • Supply Chain Disruptions: Interruptions from key suppliers or vendors due to economic, geopolitical, or logistical issue.

Each identified risk is evaluated based on its probability and potential impact, and mitigation strategies are developed accordingly.

Business Continuity Strategies

ABNT Global has developed the following strategies to ensure business continuity in the event of a disruption:

  • Data Backups and Recovery: Regular backups of all critical business data are performed and stored offsite or in secure cloud services. Recovery procedures are tested periodically to ensure timely restoration of systems and data.
  • Alternative Work Arrangements: The company has established remote work policies and provides employees with necessary tools (laptops, communication systems, etc.) to work from home or alternative locations in the event of office closures.
  • Communication Protocols: Clear communication protocols are established to ensure that all stakeholders (employees, clients, suppliers, etc.) are informed in a timely manner. These include email alerts, phone systems, and dedicated communication channels during disruptions.
  • Emergency Response Procedures: The company has designated an emergency response team (ERT) responsible for managing and coordinating responses to incidents. The ERT is trained to assess the situation, activate recovery plans, and ensure the safety of all personnel.
  • Critical Supplier Management: ABNT Global maintains strong relationships with critical suppliers and verifies their own continuity plans. In the event of a disruption, alternate suppliers and contingency plans are in place to ensure the continued supply of goods and services.

Recovery Plan

The recovery plan is designed to restore essential operations within a defined period, based on the severity of the disruption. The following are key recovery strategies:

  • Recovery Time Objectives (RTO): Aiming for the recovery of critical business functions within predefined timeframes.
  • Recovery Point Objectives (RPO): Defining acceptable data loss for critical systems to ensure that data restoration is aligned with business needs.
  • IT Systems Recovery: Deployment of cloud-based services and backup systems to minimize downtime. IT teams are equipped with resources and protocols to restore system access swiftly.
  • Business Operations Recovery: Teams are pre-assigned roles and responsibilities to facilitate the quick recovery of functions such as finance, HR, and customer support.
  • Alternative Facilities: Agreements with alternative office spaces and remote work systems are in place, ensuring that business operations can continue with minimal disruption.

Plan Testing and Exercises

The effectiveness of this BCP is tested periodically through simulated business
continuity exercises and disaster recovery tests. These tests evaluate:

  • The readiness of employees and teams to respond to disruptions.
  • The recovery time for critical systems and services.
  • The efficiency of communication protocols and systems.

Test results are reviewed, and the plan is updated as necessary based on lessons learned
from these exercises.

Plan Maintenance and Updates

This Business Continuity Plan is a living document that is reviewed and updated regularly to ensure it remains relevant in addressing new and emerging risks. The plan is reviewed at least annually or after any major business change (such as new systems, processes, or office relocations).

Changes to the plan are communicated to all relevant stakeholders, and key employees receive training and guidance on any updates.

Roles and Responsibilities

The following individuals and teams are responsible for ensuring the implementation and activation of the BCP:

  • BCP Coordinator: Oversees the development, implementation, and testing of the BCP.
  • Emergency Response Team (ERT): Coordinates on-the-ground actions and decisions during a disruption.
  • IT Department: Responsible for IT systems recovery and data restoration.
  • Human Resources: Ensures the safety and well-being of employees, including alternative work arrangements.
  • Communications Team: Manages internal and external communications during a disruption.

Conclusion

ABNT Global Sdn Bhd is committed to the resilience of its operations and ensuring that critical business functions continue in the event of a disruption. This Business Continuity Plan is integral to maintaining the trust of our clients, partners, and stakeholders and to ensuring that ABNT Global remains a reliable and robust partner in all business dealings.

Table of Contents