Acme Co Business Continuity Program Proposal

Valid until: Aug 27, 2023
Proposal ID: 20230724-36783
Version: #

Proposal Accepted

Accepted on Aug 25, 2023

Proposal Expired

Expired on Aug 27, 2023

strictly private and confidential

Acme Co Business Continuity Program Proposal

Presented to Joe Bloggs of Acme Co

Introduction

Dear Rachel,

Re. Risk Management & Documentation review 2023

Thank you for the opportunity to provide Forte Health with a proposal for two risk workshops and documentation review.

Forté Health has identified the need to conduct an update of their business continuity program to ensure the appropriate level of preparedness in the event of a business disruption. This includes the following elements:

  • Business Continuity framework
  • Business Impact Analysis
  • Business Continuity Plans
  • Business Continuity Training

To ensure that Forté Health personnel are able to respond effectively in the event of a disruption, Fixinc also proposes to conduct activities to validate the data in Business Continuity Plans and build awareness of how to use these tools amongst key personnel.
All activities are performed by highly qualified and experienced consultants.


Fixinc provides unparalleled expertise to leading organisations and are widely recognised as the market leaders in the business continuity and crisis management fields. With extensive experience collaborating within IT environments, Fixinc has gained a deep understanding of Canberra Data Centres’s environment, enabling us to provide unmatched expertise to top organizations. This has resulted in our recognition as market leaders in the domains of incident and crisis management. Some of our recent clients include:

  • NEXTDC
  • PLANB
  • NTT Global Data Centres
  • Optus
  • Singtel
  • University of Technology Sydney

Alyssa, at Fixinc our passion is centred around empowering people to confidently tackle any challenge, it’s our way of helping you build a resilient future. To this end, we guarantee a highly professional and practical outcome that will provide you with the assurance that Canberra Data Centres has the appropriate measures in place in the event of a business disruption.
Thank you for the opportunity to submit this proposal and I look forward to the opportunity of working with you soon. Please do not hesitate to contact me if you have any questions.

Ollie Law
Co-Founder & Managing Director

A summary of this proposal.

program objectives

Developing your resilience

By facilitating this program of work, Fixinc aims to improve both the effectiveness of Acme Co corporate resilience, as well as the confidence of key stakeholders that your new program meets relevant best-practice standards.
 
Validation of a fit-for-purpose program, based on a clear understanding of recovery priorities and dependencies, and supported by strong engagement, training and testing will help to meet stakeholder expectations and deliver a high level of confidence in Acme Co resilience capabilities.
 
The following is an overview of our recommended approach.

items

Project Engagement

This is an opportunity to introduce the Fixinc team who will be running the project to the Canberra Data Centres project sponsors. The meeting will confirm the scope and key business continuity priorities.

Prior to a formal engagement meeting, Fixinc will review all of Canberra Data Centres existing business continuity documents to assess the level of preparedness and compliance with key standards. This includes risk assessments, Business Impact Analysis worksheets, Business Continuity Plans and any recent training, testing and exercising documentation.

Fixinc will then facilitate an engagement meeting with key representatives from Canberra Data Centres to verify the review scope and key business continuity priorities.

When evaluating the existing program, Fixinc will identify strengths that can be further capitalised on to build greater resilience and weaknesses that need to be addressed to ensure a robust capability exists within the organisation.

items

Business Impact Analysis and Threat Assessment

During the BIA meeting, Fixinc will review the current BIA templates provided by the business unit representative. After the meeting, the business unit representative will have the opportunity to review the findings with their business unit leaders and finalise the BIA.

A clear understanding of the {clientname} key priorities and dependencies are essential to build effective business continuity strategies.  To achieve this, Fixinc will develop a Business Impact Analysis (BIA) through the facilitation of consultative interviews with business unit representatives.
For each area of the Oganisation that undertakes the BIA, outcomes of the BIA process will include confirmation of:

  • All mission-critical functions
  • Allowable outages and recovery timeframes for each critical function
  • Resource requirements and critical dependencies

As part of the BIA process, Fixinc will also facilitate a threat assessment for {clientname} using our proprietary threat forecasting tools to assess relevant business continuity vulnerabilities and plausible disruption scenarios that may impact critical business functions, as identified in the BIAs. This will include:

  • Identification and categorisation of disruption related threats.
  • Review of likely causes, existing controls and potential impacts.
  • Prioritisation of all identified risks based on likelihood and impact ratings.
  • Grouping and prioritisation of risks into key disruption scenarios.

items

Project Engagement

This is an opportunity to introduce the Fixinc team who will be running the project to the Canberra Data Centres project sponsors. The meeting will confirm the scope and key business continuity priorities.

Prior to a formal engagement meeting, Fixinc will review all of Canberra Data Centres existing business continuity documents to assess the level of preparedness and compliance with key standards. This includes risk assessments, Business Impact Analysis worksheets, Business Continuity Plans and any recent training, testing and exercising documentation.

Fixinc will then facilitate an engagement meeting with key representatives from Canberra Data Centres to verify the review scope and key business continuity priorities.

When evaluating the existing program, Fixinc will identify strengths that can be further capitalised on to build greater resilience and weaknesses that need to be addressed to ensure a robust capability exists within the organisation.

items

Incident Management Exercise

The Incident Management Plan should not be considered final until it has been thoroughly validated. The validation process should not only apply to the plan but also to the individuals who will be implementing it. Fixinc will deliver a realistic, thought-provoking exercise for the {clientname} Incident Management Team.

Exercise Planning

Fixinc, in collaboration with {clientname}, will hold a planning session to determine the extent of the scenario exercise, establish exercise goals, and review critical performance metrics. This will guarantee that the exercise program meets the expectations of stakeholders and provides benefits to everyone involved.

After the planning meeting, Fixinc will draft an exercise plan for {clientname} that outlines all necessary information for the exercise program, including:

• Exercise objectives

•Exercise methodology

• Exercise scope and scale

• Communications

• Roles and responsibilities

• Resource requirements

• Timeframes and timescales

• Internal exercise participants

• Performance criteria

Exercise Development

Fixinc will establish and arrange all necessary components for {clientname}'s exercise program, including:

• Selection and development of the preferred exercise scenario.

• Creation of exercise schedules that outline all inputs and interactions during the exercise.

• Involvement of both internal and external participants in the exercise.

• Selection and briefing of exercise volunteers.

• Conducting briefings for participants in the exercise.

resilience maturity

Maintenance Program

Take your corporate and personal resilience to the next level by running an annual maintenance program with Fixinc. Build a strong, positive culture of resilience.

On completion of all activities, it is recommended that Acme Co commence an annual maintenance program to meet best practice standards and ensure that Acme Co maintains a continuous program of improvements.
 
The proposed services have the objective of consistently improving Acme Co capabilities and resilience, while also ensuring that the program adheres to the latest best practice standards. This approach guarantees that you will be suitably prepared in the event of an emergency, meet stakeholder expectations, and safeguard your initial investment in establishing a business continuity program. The following activities are recommended:

Service
Start time
End time
Initial Activities
  • Annual engagement meeting with key stakeholders.
  • Provision of annual maintenance schedule .
  • Development of annual exercise strategy.
January to March, 2025
March 2028
Mid Year Health Check
  • Annual BIA review interviews to update BIA and Threat Landscape.
  • Full review and update of all business continuity related documentation.
  • Distribution of revised plans (soft copy).
April to June, 2025
June 2028
Annual Activities
  • 1 x 45-minute business continuity awareness session.
  • 1 x 3-hour annual Crisis Leadership training session.
  • 1 x 3-hour annual Crisis Scenario Exercise.
  • Provision of post-exercise reports.
  • Provision of revised soft copy BCP documentation.
  • Management and maintenance of business continuity related training records.
  • Provide executive/board presentations as required.
  • Provision of Annual Assurance Statement.
July to September, 2025
September 2028
on-call coverage

Advisory Board

Four of the very best supporting you through the tactical, operational, and strategic response to an event, anywhere in the world, at any moment.

how it works

Four senior resiliency professionals available any time, guiding you through any disruption, anywhere in the world at the click of a button.

The Advisory Board will support and cover Acme Co's tactical, operational, and strategic response to any incident, 24/7, anywhere in the world. Our four advisors focus on these three core activities and the response to an incident that's unique to you by utilising existing plans and our in-house F24 app. The Advisory Board's #1 aim is to get you back to business-as-usual as efficiently and effectively as possible.

01 hour
max response time from Fixinc.
04 advisors
on call at any given time.
portal

An intelligent portal.

Built in-house in partnership with FACT24, you will gain access to the most innovative and intelligent incident response and management portal available.
Detailing date and time of premium coverage
Details of the disciplines and support we offer you
Status of your post incident reviews and / or annual review
Activation SLAs, Management of event, Technology solutions
Signature and date verification by Fixinc with contact details
learnings

Relevant Standards.

All Fixinc services strictly adhere to best practice benchmarks and standards. These will be agreed during the stakeholder engagement process and may include:

ISO 22301:2019

Societal security – Business Continuity Management Systems - Requirements.

Business Continuity

'Good Practice Guidelines 2018'

BS11200:2014, Crisis Management

Guidance and Good Practice.

ISO 31000
Risk Management

Principles and guidelines.

AS: 3745

Planning for Emergencies in Facilities.

Industry specific legislation

standards, and codes of practice.
schedule

Timeframes & Resources

Fixinc will provide a detailed development schedule prior to commencement of work, outlining key project milestones and completion dates. Indicative timeframes and Acme Co commitments are below:

Stage

Project Engagement

This is an opportunity to introduce the Fixinc team who will be running the project to the Canberra Data Centres project sponsors. The meeting will confirm the scope and key business continuity priorities.
1 week

Proposed start date: w/c .

Stage 2

Business Impact Analysis and Threat Assessment

During the BIA meeting, Fixinc will review the current BIA templates provided by the business unit representative. After the meeting, the business unit representative will have the opportunity to review the findings with their business unit leaders and finalise the BIA.
1 hour meetings per business unit / 1 hour BIA meetings with key managers

Proposed start date: w/c .

Stage

Project Engagement

This is an opportunity to introduce the Fixinc team who will be running the project to the Canberra Data Centres project sponsors. The meeting will confirm the scope and key business continuity priorities.
1 week

Proposed start date: w/c .

Stage 4

Incident Management Exercise

The Incident Management Plan should not be considered final until it has been thoroughly validated. The validation process should not only apply to the plan but also to the individuals who will be implementing it. Fixinc will deliver a realistic, thought-provoking exercise for the {clientname} Incident Management Team.

Review and approve exercise plan.

Review and approve scenario and run sheet.

Attend 3-hour desktop scenario exercise.

Review and approve post-exercise report.

3 hours

Proposed start date: w/c .

about us

Program Team.

The Acme Co program will be co-run by a Fixinc Principal Consultant or Director and supported by our highly-experienced Business Continuity and Crisis Management professionals of which have extensive experience in program development and implementation.
 
Unlike how other consultancies charge clients, the people listed below are the people who will work on your program and constitutes part of the investment for Acme Co.

Brad Law of Fixinc
Brad Law
Co-Founder & Global Head of Consulting
Brad will act as your main program contact and consultant from start to finish. Whilst other consultants with other backgrounds will join the program from time to time, it's Brad who oversees the progress and direction as well as making the final decision on what is shared with you. His focus is on ensuring you are comfortable with everything we're sending you as well as the outcome of your Fixinc program.
Bio

Brad is the Global Head of Consulting within the Fixinc Consulting practice and also oversees our entire Advisory Board. He has over 25 years of Business Continuity and IT commercial experience, working across Asia, UK, Europe, New Zealand and Australia. Brad is responsible for the management and implementation of numerous business continuity and crisis management projects across a variety of industries, including not-for-profit, telecommunications, technology, government, financial services, education, infrastructure and utilities.

He is highly experienced in all aspects of the business continuity lifecycle and designed the unique 'Tungsten Diamond' diagram for Fixinc. His experience stretches through policy development, business impact assessments, strategy development, business continuity plan development and implementation and facilitation of business continuity training and scenario exercises. Brad brings strong business strategy, workshop facilitation, project management and analytical problem-solving skills with a visible passion for assisting organisation build their resilience capabilities.

​Prior to working for Fixinc, Brad served 15-years with the British Army as a tank commander, seeing 2 tours of activity duty where he was awarded with the Northern Ireland Clasp for Operation Banner and NATO Medal for Yugoslavia during the Bosnia conflict. During this time he was a communications and cold weather survival instructor and has had extensive incident response experience fighting terrorism and supporting organisations such as Médecins Sans Frontières and UNHCR.

Brad’s business continuity and incident management qualifications were put to the test during the 2011 Christchurch earthquakes, whilst working for the Christchurch Polytechnic Institute of Technology (Now recognised as Ara). He initiated and ran two incident management cells for the February 2011 and June 2011 earthquakes, ensuring services could be established in temporary sites within a week of the disaster.​

Brad holds the Business Continuity Institute (BCI) CBCI training qualification and has trained many students in the certification course on behalf of the BCI. He also held the award of Business Continuity Consultant of the year for Australasia in 2015.

Read full bio
Ollie Law of Fixinc
Ollie Law
Co-Founder & Managing Director
Ollie will be helping with the administration and analysis of your project, ensuring that the correct information is gathered and reviews of your documents are in order and documented correctly. As an operational assistant, Ollie also runs the quality assurance of our overall programs. He will also act as a key contact at the beginning and end of the programs.
Bio

Ollie brings over a decade of industry experience in digital marketing and product development, with specific expertise in no-code solutions and application automations. His experience has enabled him to design and develop digital marketing campaigns that drive commercial market opportunities on mass-scale, and identify emerging applications to support internal organisational and end-user experiences. Career highlights include positions with Centrica (British Gas), Jaguar Land Rover, and Accounting Web, where he built competitive and disruptive marketing campaigns supporting Xero in their introduction to the UK market.

Ollie is a multi-business owner and entrepreneur, with a passion and focuses on converting 'old-school' methods into modernised, competitive solutions. Ollie brings valuable experience working across a number of private and government entities within the UK and Europe, Asian, and Australia and New Zealand.

He is the majority shareholder, founder and Managing Director of Fixinc Solutions (Fixinc Directory), Co-Founder and Managing Director of Fixinc Consulting Partners (Fixinc Advisory Board), and co-Director of the Fixinc Group.

Read full bio
our founders

A father and son, on a mission.

Fixinc was founded by Brad and Ollie Law in 2017. The pair experienced first-hand the results of practitioners failing their clients when they were needed most. They developed the Consulting Practice, Advisory Board, and Directory to help organisation have premium support at any moment. With a combined three decades in the industry, the father and son duo bring a powerful balance of technology expertise and senior executive level consulting to a fresh and impactful service.
12 yrs
in the industry together
250+
Businesses serviced together
Ollie Law and Brad Law Fixinc Directors
our values

A simple approach to resiliency.

Learn more about us here

We are playing the infinite game. No one supplier can be the best, but organisations should have access to the best solutions. Our passion for the industry and careful management of deep relationships with fellow practitioners and industry bodies places us as a premium supplier. Our programs speak for themselves, set upon three simple approaches:

Community

Build meaningful connections.

Communication

Integrety and honesty.

Corporate sustainability

Don't just advertise it, do it.
rewards

Fixinc Loyalty Program

Your loyalty and commitment to us should be rewarded. That's why every program or activity you do with Fixinc earns you points that goes towards money off your next invoice, or complimentary work like an exercise.

Money off

Every dollar you spend at Fixinc will transfer into points that also have a monetary value to them (reducing costs on future quotes).

Extra services

Use your accumulated points for unique activities like a virtual training & exercise, or a plan / program review.
Introduction
Onboarding with Fixinc
At Fixinc, we value efficiency. Following our initial meeting, expect a comprehensive proposal in as little as 30-minutes, with a follow-up discussion scheduled for the following week. Our flexible process accommodates any necessary adjustments, ensuring a customised program is ready for signing in just three weeks. For those eager to start sooner, we can expedite the process, typically initiating Stage 1, Engagement in only four weeks from your first contact.
Discovery Call

45 to 60 minutes

45-minutes with your stakeholders or relevant program contacts is all we need. We will share how implementation works with us, provide an idea on how we'd run your program (or overcome your problems), then provide a valuable Q&A for both parties.

Proposal

30 minutes

We do our preparation ahead of the call and can gather a lot of understanding of the sort of program scope you will need just from your initial note to us. Our clever internal tool helps us put a comprehensive proposal together to you in less than 30-minutes. Happy to go ahead? Use our digital signature tool to lock it in.

You are here
Adjustments

Within 1-week. 30-min call.

During our discovery call, we'll book our next meeting with you a week from now. This will give you time to review the scope and compile questions with us.

New Version

1 hour

If there are any changes, we can make these immediately after the call and reissue you a new version of your proposal (archiving the original).

Engagement Meeting Booked

1 week

After signing digitally via the online proposal, we'll have your engagement meeting booked in with a senior consultant or program manager within a week.

First steps
Engagement
During the engagement phase, you have the chance to get acquainted with your project team here at Fixinc, and validate the essential milestones linked to your project, leading to potential key outcomes such as:
Confirmation of project scope.
Development of implementation plan.
Assigning roles and responsibilities.
We will also begin onboarding you, like uploading important documents onto our secure server, adding you to your unique client portal, and arranging financials.

“Our resilience consultants are available to shoulder the burdens of your project, ensuring timely and cost-effective delivery. Here, you'll have a chance to meet them and build meaningful relationships."

Brad, Global Head of Consulting and co-Founder

Let's start
Program Implementation
Our Program Implementation process is a collaborative journey. We work closely with your stakeholders to assess and study your organisation's existing plans and programs, fostering strong internal relationships. We ensure every project member is crystal clear on their responsibilities and the program's expected outcomes, delivering a roadmap for success.
Review current documents.
Analysing organisational products and services.
Review the current threat environment.

Developing a comprehensive business resilience plan across your organisation requires a fundamental understanding of your organisation's products and services, and the critical business functions that support them. This knowledge is crucial to ensure a holistic approach to business resilience and is a process Fixinc take extremely seriously.

faqs

Make sure your clear on everything we're offering.

Integrity and strong communication are part of our values, if anything is missed below, contact us.
When will the program start?
We can typically start a program within a week or two, however, we're ready to start as soon as you are able to get the team together for the engagement meeting.
How long does a program take?
This is dependant on how many modules you require, but on average our programs are 43% quicker than the current industry standards. We see medium size programs wrap up within two months.
Can I pause a live program?
This rarely occurs, but if it is a requirement, we recommend a limited suspension to maintain commitment and momentum of the work and your people’s investment. If you suspect a pause in program delivery is imminent, please let us know as soon as possible.
Do you have an office in our region?
We are currently based in Australia and New Zealand with a Kuala Lumpur office opening in late 2024. However, we have successfully serviced and completed programs around the world. We do this either virtually or travel to your location if it’s necessary. Clients are only charged for domestic travel if within our three core locations.
How many resources will I need for this program?
At Fixinc, our aim is to do the heavy lifting for you. This will limit your internal resource requirements to only the necessary people. After the engagement meeting, we will confirm the individuals we believe are required, and how often.
Can we add additional work once started?
Yes, however this is dependent on the program type you’ve started with us. If it’s a separate discipline, we would need to ensure this doesn’t disrupt the current program’s momentum. In either case, we would create a new scope and proposal for you to review, and then add this into your schedule with us.
Do we have to do face-to-face delivery?
No, in most cases, we can do all delivery remotely. In fact, during the covid lockdown period, we honed the processes and standardisation of how we deliver virtually so that the transitions are seamless.
Can you deliver our program next week?
We will make every possible attempt to meet a deadline, however we often see the biggest hurdle being your ability to muster your internal resources and sign off on programs within your timescale. We will work with you and provide some techniques on how to better place an urgent program.
about us

Client References.

Fixinc has compiled the most relevant referals we have permission to share with Acme Co. If you are unable to contact them, please let us know.
 
We aim to find a balance between similar programs and similar industries. However, this is subject to which of our clients are happy to be contacted.

Brigid Wiliams
Business Continuity Manager
021 1348 534
brigidwilliams72@gmail.com
AIA
Business Continuity Program

The scope of the program was to deliver a Business Continuity Program to AIA Head office, Auckland in line with Executive and Board level requirements.

All training and work was done on-site.

Phase 1:

  • Facilitate a Business Impact Analysis (BIA) meetings and deliver BIA report.
  • Develop Master Business Continuity Plans for each AIA Head Office.

Phase 2:

  • Deliver Business Continuity Training for Business Continuity Teams.
  • Deliver Business Continuity scenario exercises for Business Continuity Team.

Phase 3:

  • Deliver incident management training.
Shaun O’Mara
Head of Security & Emergency Management
(+61) 438 009 893
shaun.omara@uts.edu.au
University of Technology Sydney
Business Continuity Program

The scope of the program was to deliver a Business Continuity Program review across 13 Faculties and Business Units at the Sydney Campus.

The program was delivered on site and via remote meetings.

Phase 1:

• Facilitate Business Impact Analysis (BIA) meetings and deliver BIA report.

• Update Business Continuity Plans for each Faculty and Business Unit.

Phase 2:

• Deliver Business Continuity training for BC Teams.

• Deliver Business Continuity scenario exercises.

Contact us

Speaking to our team.

No matter your program scale or duration, our team prioritise clients on a program with Fixinc. When you join us, we'll ensure you always have a direct line of communication.

Email

Email me directly via the address below.
ollie@fixinc.org

Accounts

For anything invoice related.

Phone

Mon-Fri from 9am to 5:30pm.
(+64) 027 955 8000(+64) 0800 349 462
quote

Your Investment with Fixinc.

Fixinc is able to provide competitive pricing that is up to 30% lower than the industry average. We are able to do this through low overheads, utilising our contract based Advisory consultants, and the use of automated technology (like this proposal).

Investment

All prices listed are in NZD and show any applicable taxes or fees below.

Item
Investment
Valid until
Project Engagement
August 31, 2023
Specifications
  • 30 minute engagement meeting with project sponsors.
  • Provision of soft copy project schedule.
implementation commitment
Responsibility
Business Impact Analysis and Threat Assessment
August 31, 2023
Specifications
  • x10 BIA meetings.
  • Provision of softcopy BIA documentation.
implementation commitment
Responsibility
Project Engagement
August 31, 2023
Specifications
  • 30 minute engagement meeting with project sponsors.
  • Provision of soft copy project schedule.
implementation commitment
Responsibility
Incident Management Exercise
August 31, 2023
Specifications

• Development of exercise plan.

• Setup of exercise, creation of scenario and development of run sheets.

• Onsite facilitation of 1x 3-hour desktop exercise.

• Provision of 1x Fixinc facilitator and 1x offsite support resource for injects.

• Provision of hot debrief.

• Provision of post-exercise report and recommendations.

implementation commitment
Responsibility
Total investment
with tax
with tax
with tax