Zencastr
00:00:00
00:00:01
Speed1x
Format
Share
Embed
Report

Risk in the Middle Market

The Market That Moves America
The Market That Moves America

131 plays · Feb 8, 2018

NCMM Executive Director Tom Stewart and special guest Phil Renaud from the Risk Institute discuss how the middle market can navigate and avoid risk.

Transcript

Speaker: Reconnaissance, resilience, recovery. Put them together and you have a recipe for managing risk. Welcome to The Market That Moves America, a podcast from the National Center for the Middle Market, which will educate you about the challenges facing mid -sized companies and help you take advantage of new opportunities.

Speaker: Hurricanes and fires, political change, technological disruption that transforms industries. Middle market companies face all kinds of risks. Some of them threaten the very life of a company. How can they identify those risks, protect themselves, and build resilience?

Speaker: Let's find out. I'm Tom Stewart. I'm the executive director of the National Center for the Middle Market at the Fisher College of Business at the Ohio State University. We're the nation's leading research center focusing on the concerns and needs of mid -sized companies, which account for the middle third, a third of private sector employment and GDP and the lion's share of economic growth. It is indeed the market that moves America.

Speaker: The National Center for the Middle Market is a partnership between Ohio State and SunTrust Bank's Grant Thornton LLP and Cisco Systems. With me today is a special guest, Phil Renaud, who is the Executive Director of the RISC Institute at the Fisher College of Business. Phil, glad to have you. Thanks, Tom. Good to be here.

Speaker: I'm happy to talk about risk in this day and age, affecting middle market companies. Indeed. Well, tell us about the risk institute, first of all. I mean, you're across the hall from me, but... Other than that, yeah, we're... Aside from that. We're a relatively new center here at Ohio State, about three, three and a half years old, and we're approaching 30 members, and six founding members are included in the Risk Institute.

Speaker: Among those nationwide, EY Ernst & Young, Huntington Bank, Battelle, the obviously OSU, and AON are our founding members. And what's the mission of the risk? We focus on enterprise risk management.

Speaker: risk as it impacts an enterprise. So within that - So it's the risk that would involve a CEO and a board and the top leader - Correct. If this is the stuff that is across the whole enterprise that really needs to be run, get the C -suite attention. Right. So we're focusing on risks involving strategy, risks involving the operational side of the business, certainly, and those risks that are insurable.

Speaker: Right. So we just did a survey of 1 ,000 middle market companies. Those are companies with revenues between $10 million and $1 billion a year, about three categories of risk. We looked at strategic risk, operational risk, and digital risk in particular. Strategic, we focused on. We met things like macroeconomic changes, changes in ownership, disruptive technology, large forces like that.

Speaker: operations, meaning business continuity issues from things like hurricanes, supply chain disruption, and similar events, and digital, including both cybersecurity breaches and the breakdown of IT systems themselves. The first thing that we found is that fully half of the thousand companies we surveyed said that they had been hit by one or more of those in the last two years. Does that surprise you? No, not at all. In fact, I would have suspected it to be even higher than that, Tom, when you think about

Speaker: the impact on business today from any number of different areas. One, technology changing as fast as it is. Two, extreme weather events. Just think about the last couple of months, right? The speed in which weather is upon us and the severity in which those storms are hitting us.

Speaker: And weather events of fire as well. And fire, exactly right. And we're now with the still as we record this, you know, just before Christmas, we are still seeing fires out of control in Southern California. And San Fran and LA area as well. And the speed of supply chain at risk as well. The dynamics of how we move product. The size of the ships in which product is contained on those.

Speaker: to the extent that there's a weather event, the amount of product that could be harmed because of that weather event goes, grows geometrically. And of course, actually you think about that. We had major storms in the Southeast and some of the biggest ports. I think Savannah is on its way to being the biggest port in the United States. I think Long Beach may still be, but just think about that and think about being a company that depends on those ports for your goods coming in or your goods going out. Absolutely.

Speaker: Think about the large ports of Seattle, Long Beach, Savannah, Newark, on the East Coast. Any one particular event, a strike in Long Beach, could disrupt significant commerce in this country. So let me start. Let me dig into digital a little bit, because if I think back to my own knowledge of

Speaker: of risk and enterprise risk management, the phrase emerging, I think, about 15 or 20 years ago. Is that probably about right? Digital wasn't on the horizon. I mean, we did talk about the breakdown of computer systems in the back office, but cybersecurity risk, I mean, it's a couple of things that we found. First of all, 17 % of companies said they'd been hit by some digital problem in the last two years. That number seems low because we know

Speaker: It takes about 205 days before a company knows it's been hit if it's been attacked. Exactly right. And I think that is low from our side of the street. Very low. I did a little bit of research prior to sitting here. And I think of companies that are—

Speaker: You know, our namesake of major, major institutions here, Intercontinental Hotels, Dun & Bradstreet, the IRS, Gmail, Brooks Brothers, Blue Cross, Verizon, on and on. I think sometimes mid -sized companies think

Speaker: Those evil hackers with the black hats, they're going after the JPMorgan Chases or the Targets. They're not going after this. No, absolutely not. They're going after everyone. Just look at the list of companies that have been impacted in 2017. You know, either have been hacked or you don't know you've been hacked.

Speaker: And one of the things that's going on in that business, and we talked about this on an earlier edition of his podcast, is that the rise of ransomware means that they're just going out after anybody and just saying, send me 100 Bitcoin, and it doesn't matter how big.

Speaker: Well, some research done by a firm called Control Risk Group, which is a major that thinks about ransomware and extortive crime, for example, had a study. And in 2007, zero percent companies reported having any extortive attempts on them.

Speaker: In 2017, when they looked at it again, 28 % of the companies... Three out of ten companies have got that black screen saying, send us money, or... Exactly. And that's not isolated to large companies. That's companies across the map.

Speaker: One of the things that I think is interesting in our survey, 50%, 49 % recognized it as extremely or very challenging, which is to say the alarm bells went off. Emergency, emergency, emergency. But they also said, two thirds of them said they cleaned things up within a month. And 60 % said they recovered fully. So this seems in this category of risks to be

Speaker: a total fire drill, or a five -alarm fire, but one that you can put out if you're well prepared. You can put out if you're well prepared. I mean, if we think about some of the recent events—let's take Equifax, which impacted 143 million consumers. Including me, I assume you. Including me.

Speaker: We think about what's the root cause of that the root cause of was failure to apply a patch to their system So there's a little event Failure to provide a patch had a massive consequence to every one of us virtually There's a recent event eBay

Speaker: on December 10th actually, just a couple of days ago, that involved an interface with Google on how that interface failed and in some respects some very sensitive purchasing data get out in the general public. So again, how business is transacted in the case of Equifax, how I'm protecting my business with patches that are prescribed, and in the case of eBay and Google, how I'm transmitting this information between one another.

Speaker: So if you go beyond, I mean, the cyber risk is one. Of course, it's changing all the time as the technology is changing and people are playing catch up. Some of the more classic areas of operational risk, some of the things that we've mentioned, the supply chain disruptions and things like this.

Speaker: It feels like there is a pretty good body of knowledge about how to prepare for these risks to, I guess, prevention, mitigation, and recovery. When you think about that body of knowledge,

Speaker: What do companies forget? What is the most common mistakes that companies make, saying they should have done this, they knew they should have done it and didn't? I'll call it failure to prepare or failure to be resilient. A couple of good examples in my world prior to coming to the university.

Speaker: was doing some work for a number of middle market companies. And one middle market company had been using a vendor. This is a tier one supplier to make its final product for 25 years or more. And when we looked at the root cause of this particular event, which was a fire at a factory in Asia,

Speaker: spoke to leadership saying, had you done anything to prepare for the inevitable challenge that may exist with that particular vendor, the answer is, why would I? They've been doing work for us for 25 years.

Speaker: So it's that failure to be resilient. It's the failure to think about what are the options to think of alternative suppliers. So my light switch has always turned on. Why should I bother this? Why should I worry? The lights are on. They're working today. In this particular case, they had tools and dyes, raw material, work and process. They had it all.

Speaker: because they were a key event for 25 years. So if I'm, you know, some of these guys, just in this case, the story you're talking about is a midsize company, but in some cases, you know, a big company, a Procter and Gamble can have backups, can have backup data farms, can have all of the alternatives. I'm a $50 million company.

Speaker: Can I—how do I afford that? I mean, I know one answer is you can't afford not to have it, but how do I make—how do I identify that stuff which I absolutely have to spend on no matter how cheap I am? Well, I mean, one tool that we use or would suggest is I refer to it as a director's risk assessment. So every year,

Speaker: go through your organization and prioritize things that could impact your business. Some of those could be operational, some of those could be strategic, some of those could be cyber, on and on. They could even be leadership risks. It could be an aging workforce, for example.

Speaker: or a particular group that may retire. We were working with a firm of recent and we're talking to them about this aging workforce and the statement was made that 60 % of their IT staff

Speaker: is approaching retirement in the next five or so years. 6 -0, 60%. So think about that. Think about that as a risk to your business. You know, it's interesting in mid -sized businesses, especially, you know, private and often family -held businesses, a private business is often founded by a bunch of buddies. Yeah. You know, we all went to business school together, we're all golfing buddies, whatever it is. And the result is,

Speaker: We're all about the same age. And we've been working together now for 20, 30 years. And suddenly, we're beginning to realize that it's not just, we're all getting old. We're all getting old. And we haven't actually built the talent, succession, and diversity. And that turns into an enterprise risk. It's an enterprise risk. And it's a growing risk. I think of just risk management, for example.

Speaker: in that profession. Many companies call us saying, Phil, can you help us find talent

Speaker: for risk management professionals. They're just not out there, which is what the Risk Institute is about. We're looking to create that talent and that talent pipeline in the next three to five years so that as, and risk is even more dynamic than IT, 70 % of risk professionals are over the age of 50. Seven, zero, 70 % over the age of 50.

Speaker: So it's great for young students coming along because their career path is wide open and rich with opportunity. But it's scary as companies think about contingent planning for risk professionals in their organization or those who can

Speaker: deal with risk, you know, within their business. Now, I may be too small to have a chief risk officer, but I'm not too small to make that director's list of the key risks that I might face.

Speaker: focus on the third one here that we mentioned, which is the strategic risk. The data from our survey were really scary about this. First of all, it was the most common. 27 % of these people, 17 % said they had a cyber risk. We've agreed that's too small. But 27 % of that same group of people said that they had

Speaker: They had been affected by some big strategic risk. It was the most common. It was the most damaging. Only 40 % say they recovered completely from a shock within the last two years, and it's the hardest to prepare for. Only one in three, only one in three said that they were prepared. So these big, hairy, hard to recover from risks came from out of left field. It's also sort of not in the curriculum of

Speaker: track of classic risk management, because you can't ensure against it. No, you can't ensure against it, but you can prepare for it, right? I mean, there's, I talk about two kind of particular areas, business continuity, BCM business continuity management, and probably even more important to that is a term we refer to as CBI, contingent business interruption or contingent business continuity, okay? Those that impact

Speaker: a vendor or those that impact someone that's distant from your firm is perhaps even more important. Because if you're not evaluating the risks that they undertake, and some of those could be strategic as well, some of those could be operational risks, but it's important to kind of have a holistic view of what could impact you, both yourself

Speaker: and your vendors, your key vendors? A guy named Don Sull, who's at London Business School, is an old pal of mine, has a really interesting exercise that he does with companies in which he asks them to think about two different attributes of professional boxers. One is the ability to be agile. The Muhammad Ali felt like a butterfly sting like a bee, the ability to avoid a punch.

Speaker: And the other is something he calls absorptive capacity, which is the ability to stand there and take a punch. And that's sort of George Foreman, right? And very few companies are equally good at both. Very few are Jack Dempsey, right? But he likes to say, put yourself on some grid, on some matrix of agility versus absorptive capacity,

Speaker: And then see what you can do to make your week's hand a little stronger. If you're agile, you don't want to go full bore, absorptive capacity, because you don't want to lose the agility. But what can you do to do a little rope a dope or whatever? First of all, you need to you need to think, think through it. OK, so I can be a small company. I can be a, you know, a P &G, a multi billion dollar organization. But

Speaker: You need to think about this director's risk assessment tool, I would say, or risk assessment tool in general. That forces you to think about what are the areas that perhaps I'm weakest at. What are the areas that at least I can absorb a punch?

Speaker: or what are the areas that I'm particularly good at, okay? And sometimes when we put it down on paper and we start thinking about it, it's very revealing. It's very revealing. We had some friends of ours at SunTrust, one of our sponsors, that in the aftermath of the hurricanes in Florida who discovered that there were a number of their clients who, you know,

Speaker: did not know what was in their loan covenants or in their agreements with their banks to basically, I need credit. Am I ready? Do I have a line of credit ready? So that's an example of an absorptive capacity. Do you have a good line of credit or do you have cash in the bank? What can you do so that you can take on the next 30 days? Exactly. I mean, think about flood insurance, this Houston event. It was very eye -opening.

Speaker: First of all, flood insurance deals with what I call the 1%, the 1 % event, and that is the 100 -year floodplain.

Speaker: Which seems to happen every three or four years these days. Exactly right. But what happened in Houston? The 100 -year floodplain became the 500 -year floodplain, which is a 0 .2 % probability of event. But all these people down in Houston now are faced with not the 100 -year event, but the 500 -year event.

Speaker: Well, and also, even if it's 0 .2%, if it happened to me, it's 100 % for me right now. And so in some way, I have to be prepared for it. Right. And a lot of those people, nor was the federal government thinking about this, because the flood maps had not been updated. That's an interesting thing. A recent study showed that 5 .5 trillion in assets and 40 million Americans are at risk of flooding.

Speaker: And this came out after Houston, where people are now scratching their heads going, how could this have been so bad? What did we miss? Well, it's because the maps hadn't been updated. So now the project of updating the maps to make sure that we really know what the risk is and where the event can strike is particularly important. One of the things that I'm taking from this conversation is that there's real value, first of all, in thinking about

Speaker: these three types of risk, including always the talent element that underlies all of them, because you can have a disruption problem or an IT problem that is a talent problem, and the supplier and vendor problem, my ecosystem problem. But to sort of actually step back from today's business, say, wait a minute.

Speaker: You know, what could come from out of left field, what could hit us, what could, you know, what, what, what Uber could Uber us or what other disruption could happen and get your mind free there. And then start thinking about, what can I ensure?

Speaker: What can I absorb? Well, first of all, what must I protect? There's always a burning building. One of the things I've got to take out of it. What have I got to protect? But what can be insured and replaced? Where can I build redundancy?

Speaker: And basically start working those things down so that then I say, what is the amount that I just have to be able to be resilient about? And sort of narrow the problem. Resilience goes well beyond what I can ensure, okay?

Speaker: So let me give you a good example on cyber insurance. Okay. Cyber insurance today, the market for cyber insurance five years ago was virtually non -existent. Now it's in high demand. Okay. A middle market company can expect to pay for a million dollars worth of coverage, about $10 ,000. So 10 ,000 per bill. It's a lot of money.

Speaker: That tells you how prevalent the attacks are. Exactly right. So it's a law of probability. So if I've got a high probability, then my cost is going to go up. But you think about in order to get that cyber insurance, I'm going to expose my business to a lot of audit. All right. So they're not giving the 10 ,000 a mil away just to give it away. They're going to they're going to research how prepared you are, how resilient you are.

Speaker: What steps have you taken? Have you installed the proper patches? Do you have a proper department? Do you have skilled people, etc., etc., focused on that? So the demand for cyber insurance is growing exponentially. Because of the events that have taken place, the pricing of that coverage is growing as well.

Speaker: So it's something that people have to really start paying attention to. But let me go back a step. To be resilient doesn't necessarily cost you money. It's time and preparation. So that example of the factory that I've been doing business for 27 years and everything is okay,

Speaker: Had I taken some steps back or this business taken some steps back and looked at, yeah, I've got all my eggs in one basket here. Would it make sense to look for an alternative supplier? That alternative supplier could be in another region. Okay. So let's take Fukushima, for example. That event took just about everybody out in that one area. So I could have had an alternative vendor 10, 20 miles down the road. I'm still impacted.

Speaker: But if I have another vendor in another geographic region, then perhaps that's a smart thing to do. It builds some resilience. It builds some capacity in my business to also assist me to recover quickly. Let's take supply chain and the speed at which supply chain moves today.

Speaker: No one's really creating warehouses any more product, are they, Tom? Right? Where I can go to a shelf and pull off 25 particular widgets. The supply chain moves so quickly that it's just in time, whether it's steering wheels to the big auto manufacturer or some other component, electronic component to, let's say, a middle market company.

Speaker: But what happens, these large shipping container boats? These boats hold upwards of 4 ,000 containers. They might hold your year of supply, yeah. Well, that's my point. That could be a whole year of supply. It's very efficient to move product on one boat because the cost goes down geometrically.

Speaker: But if I hit a tsunami on the way, and I lived through that when I was with a large retailer, we had our entire swimsuit line. Swimming with the fishes, right? That was swimming with the fishes and literally could have bet the business. You know, it was that sensitive. So we think about it. Yeah, it was efficient to move it on one boat, but perhaps it would have been smarter if we divided it into three boats.

Speaker: Do you know, we're just about out of time, but what I'm hearing is really interesting, and naturally what thinks about—we've been talking about strategic risk, operational risk, and particularly about digital risk.

Speaker: But I'm hearing a theme that you might call about the three R's, the reading, writing, arithmetic of risk, and one might be reconnaissance. And really getting a wide view of all three of these, right? Reconnaissance, one might be resilience. How do you build excess capacity, extra vendors, the financial resilience you might need?

Speaker: And third is recovery. And that recovery is gonna go a lot better if you actually have thought through what's gonna happen and have your playbooks for, and so will resilience. I mean, so we'll deal, if you have your playbooks and realizing the unthinkable, if you think about the unthinkable, you can make some plans for it and start recovering from it. And if you can think about reconnaissance, resilience, and recovery, maybe this risk animal can be,

Speaker: if not completely tamed, at least caged and domesticated from time to time. So with that, I want to thank you Phil Rineau, who's the Executive Director of the RISC Institute at the Ohio State University Fisher College of Business, who is here to talk to us about how middle market companies can understand and cope with

Speaker: the risks that they face. And I'd like to thank you for listening to The Market That Moves America. Never miss a new episode. Subscribe to the podcast on iTunes, Stitcher, Google Play, or wherever fine podcasts can be found. And you can subscribe and learn more about us at our website, middlemarketcenter .org. Thanks very much.

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Recommended