Insights from Control Risks and Standard Chartered

This episode of Ground Truth examines enterprise security in an era of converging risk, where cyber, physical, operational and geopolitical threats increasingly cascade across interconnected systems. The conversation explores where safety and security begin, why boards need to reframe AI risk and the capabilities that will define the most resilient organisations over the next five years.

Listen and subscribe to Ground Truth

Key takeaways

  • Enterprise security starts with leadership. The most resilient organisations treat security and resilience as business-wide responsibilities, not standalone functions. Success depends on bringing together security, operations, technology and risk teams around a shared view of enterprise risk.
  • Security culture is a critical component of enterprise resilience. Organisations are stronger when employees at every level are empowered to identify risks, raise concerns early and take ownership of security and resilience outcomes.
  • Organisational resilience is built before a crisis occurs. Scenario planning, stress testing and intelligence-led decision-making help organisations identify vulnerabilities, strengthen preparedness and improve crisis response.
  • Security should enable business growth and decision-making. When embedded into strategy, enterprise security helps organisations enter new markets with confidence, support innovation, strengthen resilience and build stakeholder trust.
  • Trust is the outcome of effective security and resilience. Customers may never see the intelligence, planning and controls behind the scenes, but they experience the benefits through reliable services, effective crisis management and business continuity during periods of disruption.

What to watch

  • AI as an enterprise risk, not just a technology issue

    As AI becomes embedded in business processes, leaders will need clearer visibility into the dependencies, workflows and risks that accompany it, from security and operations to governance and compliance.

  • Growing reliance on third parties

    Increasing dependence on technology providers, cloud platforms and external partners is creating new vulnerabilities. Understanding and managing third-party and concentration risks will become a key resilience challenge.

  • Greater focus on critical dependencies

    Future-ready organisations will have a clearer understanding of the technologies, suppliers, people and processes that underpin their most important services. Mapping these dependencies will become increasingly important for resilience and business continuity.

  • From crisis response to continuous preparedness

    Organisations are likely to invest more heavily in continuous testing, simulations and scenario exercises, shifting resilience programmes from reactive crisis management to ongoing preparedness.

  • Concentration risk is emerging as a major resilience challenge

    As organisations become increasingly dependent on a small number of cloud providers, AI platforms and technology partners, resilience will depend not just on protection, but on maintaining flexibility, reducing single points of failure and preserving the ability to switch providers when disruption occurs.

Read the podcast transcript

Redefining security and resilience for the modern enterprise 00:00 – 02:38

Caspar: Hello, and welcome to Ground Truth, the podcast from Control Risks. This is the place to hear the latest insights on how organisations across the world are optimising their use of strategic intelligence and becoming more secure across the world. I'm your host, Caspar Leighton. 

In this episode, I'm going to be asking what being safe, secure and resilient means for a global organisation today. 

And I'll be hearing the perspective of a senior executive from a global bank and one of Control Risks leading experts on enterprise security. 

Typically, matters of safety, security and resilience come into sharpest focus when something goes wrong. A control risks. We spent more than 50 years helping organisations reduce such risk. What going wrong looks like is changing and fast. 

Enterprise security used to be about cyber physical security, resilience or crisis management and typically all sitting in separate functions as organisations become ever more dependent on technology suppliers, data people, and of course, AI, these risks are converging. 

The real challenge for leaders now is to manage them as an interconnected system, not a collection of separate issues. 

I'm delighted to be joined by a representative of an organisation that does just that, with a bit of help from Control Risks. For the last four years, Shelley Boland has been the Global Head of Corporate Real Estate and Services for Standard Chartered. Standard Chartered describes itself as a global bank connecting corporate, institutional and affluent clients to a network that offers unique access to sustainable growth opportunities across Asia, Africa and the Middle East. 

Shelley, thanks so much for joining us. Tell listeners a bit more about your role at Standard Chartered. 

Shelley: Thank you so much for the invite. So, I've been at Standard Chartered for over 11 years now. And as you mentioned, I head up the global function for our corporate, real estate and corporate services. This is overseeing the corporate population in terms of offices, branches, data centres. 

So, there's over 1200 sites around the world. And we operate in circa 54 markets. As you mentioned in the opening, we've got a heavy presence in Africa, Asia, Middle East, Pakistan. But we also offer services to customers throughout Europe as well as the Americas. 

And the role that our team plays is really to provide those services and facilities that shape every moment. 

Whether you're a colleague that comes into our environments every day, whether you're a client that is banking through our client centres or whether you're a stakeholder at or to our facilities. So, end to end accountability for those areas across the organisation. 

The rise of converging risk 02:38 - 03:38 

Caspar: And I'm also joined by James Owen, who's a partner at Control risks. James leads our Digital Risks practice globally. James, what do you spend your time helping our clients to achieve? 

James: Most of my time, Caspar is spent helping organisations to manage convergence risk, which is essentially helping them to understand how cyber, operational risk, technology risks, geopolitics all effectively interact with one another and come together, and how disruption can flow through organisations through all of those intersection points. 

Organisations today rely on a complex network of people, suppliers, data, AI increasingly. So, helping organisations to look at security risks on an enterprise level is becoming increasingly critical. Rather than looking at risks through a siloed or overly narrow approach.  

Why security starts with leadership 03:38 – 05:44 

Caspar: Understood. Shelley, of course, being safe, secure, resilient is absolutely brand critical for an organisation like Standard Chartered. Where does enterprise security begin for you? 

Shelley: Yeah, for me, it starts with that leadership accountability. I think that you must have a clear understanding that security and resilience is part of how the bank operates versus reliant on one department, you know, called security. And for us, it's less about the organisational chart, but it's where the work needs to be done. 

And that's why when you're looking through the emerging risks and the things that we're dealing with on that global landscape now, it has to be an integration of the teams that come together around operations, business continuity, the technology team, the real estate team and our supply chain, all in service of the clients and the colleagues. 

As you mentioned, for a bank trust and our brand and reputation is paramount. And part of that is that confidence that we're taking care of your assets, we're taking care of your investments, we're taking care of our colleagues. And therefore, something like enterprise security is going to be a mindset within the organisation, less about, you know, guards and cards and how we actually turn up in that posture every single day. 

Caspar: So, James, looking at other organisations that control as well with what's your sense of how well leaders are managing to, make this shift of integrating perhaps the, you know, cyber physical security, resilience, insider risk, third party risk, bringing all those pieces together in a way to actually becomes that cultural cross organisation function that, you have cited as so important. 

James: I think it's easier said than done. I think a lot of organisations are looking at risk in a much more joined up way than they were before, but I think many are still structurally finding it difficult to do that because it is a difficult aspiration to achieve very, very simply. 

I think actually financial services is further ahead than most other sectors in this reguard, and that's largely because regulation has required banks historically to map their dependencies, that critical services. 

Caspar: Right. Everyone's looking at them. Right? 

How risk cascades across the enterprise 05:44 – 07:53 

James: Exactly. And ultimately, to test more rigorously, so we can see the impacts of the way the regulation has supported those efforts there. We ourselves see that, for example, in the work that we do with the regulator in Hong Kong, where last year we ran a typhoon-based scenario, for the Hong Kong Banking and Monetary Authority in this city. 

That was an effort to focus on testing the resilience of the financial services sector, but with a physical security scenario that then played out very much in terms of the cyber, the operational and the broader financial impact of that on the sector as a whole. And that is a pattern that we see more broadly. Wasn't long ago that we saw, for example, in the United States last year, specifically in Chicago, where the failure of a cooling system within a data centre had a direct impact on the ability of financial exchanges in the United States to operate. That has a major impact that then follows on in terms of the way that organisations, manage that AI enabled services that were themselves dependent on that, data centre. So, you know, we see lots of challenges facing organisations. I think financial services is further ahead, but ultimately, still many organisations, the escalation points and the ownership is still quite siloed. 

Caspar: Right. 

James: I think the solution to that, just to pre-empt question, you might ask me, is not then to create one extra big, gigantic security function. Ultimately it is to make sure that everyone is looking at the same picture. It is about sharing intelligence and trying to encourage a culture of joining the dots within an organisation as a whole. I would say. 

Caspar: And Shelley, has that experience been for you as Standard Chartered? Because I imagine you've got the typhoon guys. You've got the cyber security guys. And that interesting example that the exercise you took people through in Hong Kong last year. How's it been for you bringing these, I suppose, fairly culturally, quite disparate parts of the organisation together so that they're all, to coin of cliche, singing from the same hymn sheet. 

Building one ecosystem from disparate teams 07:53 – 10:10 

Shelley: Yeah. And we were part of the control risk event, there in Hong Kong. And in actual fact, Control Risks has come in with our senior leaders and run those types of scenarios and really helped us test our response and where we would course correct. So, to your point, again, it's less about one big security department. And for us, it's that we've got an ecosystem that comes together across all those areas. And so that way we can look at risk from a total perspective. 

I think the other thing is that you've got to embed risk and security in right from the beginning in when you're making decisions about which markets to enter, which products and services to launch. And that's where, for example, while we might have good intelligence within the organisation, a partner like Control Risks can come in and can give us that global perspective, blind spots that we might not necessarily have access to information that could actually pivot some of our decision. 

So, we're not just looking at an ecosystem within Standard Chartered. We're also looking at our peers, as well as the insight and intelligence we can get from outside the organisation so that we can make those better-informed decisions. But you're right. It's moving away from what was a traditional guards and card security function, and it's far more integrated now and fused together as one organisation that comes together both from a predictive and proactive perspective. 

So, we don't just come together when there's a crisis. The, the actual secret sauce there is that you're spending time doing that scenario analysis, spending time in the markets and testing those different approaches and responses way earlier from when there is actually something and you're in response mode or you're in reactive mode. So, I think that's a part that Standard Chartered does well. And your example was a good one of stress testing up front where we can, how we would bring together an ecosystem in a lot of different scenarios. 

Caspar: And I imagine all the various security related functions in a firm can understand, in theory, why it's a great idea to, to work together. 

Making enterprise security work in practice 10:10 – 13:01 

But in practice, what are some difficulties you encountered in getting different teams to work together? I sure, they all wanted too, but actually being able to do it, it's another thing, isn't it? 

Shelley: Yeah. Look, a very simple example is we might have an example where we've got a security incident in the workplace and the mindset could be quite okay, I'm going to resolve this. But in actual fact that security incident was in a data centre, which then had an ongoing impact around technology, which then we need to consider how we could settle and trade for our clients. 

So, it's bringing in a skills-based workforce that really has that end-to-end mindset. When they're thinking about the organisation, it's got a client first approach. So how is this actually going to impact the end user, the client that we're ultimately servicing. And then it's in some cases combining adjacent functions so that it is more relevant to be working together. 

One good example is we've brought together a global operations centre that deals with all of our incident management security operations. It sits right next to technology. It sits right next to security. It sits right next to H.R. And it comes together then to think about all the people, all the partnerships and all of the activities that we need to do if we ever needed to trigger, you know, some sort of response or proactively manage that. So that's one real life example within the bank. 

Caspar: And on that technology point is emerging technology making things easier and harder at the same time? 

Shelley: The answer is yes. Absolutely. I think in some ways, and I'll use our example, we've we're starting to use technologies, whether it's AI lived or, autonomous technology that is giving us greater insight, greater information, more predictive intelligence, so that then we can make better informed decisions. 

The flip side of that, it is moving. So quickly and it's so integrated, as I said, that sometimes it is hard to keep up. And that's where, you know, for example, Control Risks is very much part of this process. We're launching a new visitor management system. Now that may sound very basic, but actually what that does is help us manage the identity of guests and help us to manage their experience through the organisation. But then Control Risks has been able to come in and consult or that around different areas and technologies that might be able to add value in the event that you needed to trigger some sort of business continuity as a result. But ...  so, it's both supportive, but it's hard to stay ahead of the pack. 

AI and the acceleration of connected risk 13:01 – 15:09 

Caspar: And James, that bit about, all parts of the organisation being more and more connected with this emerging technology that really raises the risk of, well, the word I use would be contagion. You have a may have a slightly less scary word for it, but really it's that piece about if a problem emerges somewhere as risk, starts to impact one part of the company pretty quickly. It starts to wash up on the shores of another department and can leapfrog and leapfrog and grow. 

James: Yeah. I think contagion risk might be an apt term. I probably use more cascading risk and we've seen that I think for a long time, particularly in cyber. So, we're almost now ten years away from the big WannaCry and NotPetya attacks, which were the first, I think, introduction to the general public around the idea that a cyber-attack can move seamlessly, across national borders, across organisations and sectors. 

I think the challenge today is that the density of connections has significantly increased and gone beyond where we were certainly ten years ago and even just five years ago. Technology, infrastructure, supplies, data flows, and business processes are today so interdependent, that actually, you know, again, weakness in one part of, of the system can actually flow through into another part very quickly. 

So, a physical event can become a digital event rapidly, likewise vice versa. So, a power or water outage or a cut undersea cable, can create big challenges if you're running a data centre. Likewise, a cyber attack on a production unit can cause significant physical, real-world consequences. And we have seen that absolutely. Now, that transition from cyber to kind of kinetic impact in the digital world, I think what AI is doing, it's effectively intensifying the convergence that we're seeing here, because AI depends on and cuts across all of these systems, all of these connections. 

The Boardroom Challenge of AI Risk 15:09 – 17:15 

Which makes it challenging then when the board asks the question, so what is our AI risk? Because they will get a different answer depending on who they're talking to typically within the organisation. A chief information security officer, a chief security officer, a head of risk, a head of government relations will all have a slightly different perspective on that AI risk and what it is. 

And therefore the board, as a result of that, will be dealing with information more in fragments than based on a kind of joined up, coherent overview of what that risk looks like as a whole. And I think that does talk to the need to look at AI risk less as a special category and more just as another risk, but one that cuts across the organisation as a whole, where you need to understand what is your AI workflow dependent on? What can it access? What can it trigger as a process within your organisation and get across those types of organisations before worrying too much about looking at it in any one spot. So I guess looking at the overall risk, including AI at that operational model level as opposed to simply as a technology issue 

Shelley: It might be slightly additive. The other one now that we're organisations, operating models are in a lot of partnerships, is this third party risk. And what we're doing then with the whole ecosystem, when you're looking at supply chain. So, to your point, there may be a downstream impact. But because of the nature of the operations on how we service colleagues and clients, it has a direct impact on our ability to recover the business or deliver those priority services. So, I think again at that top level of the organisation now they want to see that end-to-end risk profile. And then you've got these new emerging areas such as AI such as third party. That is naturally coming to the forefront because of the changing nature of these, the way we're able to run these global systems. But it's becoming, more and more of a priority at that top table, which is positive. 

Security as an enabler of growth, not just a cost centre 17:15 –18:00 

Caspar: Yeah. I mean talking top table and the tenor of this conversation so far is, seems to me to be still very much around security stopping bad stuff happening. And I know something that security directors, for example, have struggled with historically is, being something more in the cost centre, something more than a block in an organiaation. You can't do that. No, you can't do that because that'll happen. Because that'll happen. Where are we? Maybe I'll come to you first on this change. Where are we on that journey of, being able to sell in enterprise security to senior leadership as an enabler, as something that will actually promote growth rather than just stop the flood? 

James: Absolutely. I think that is really critical, quite obviously. And it talks to the need to ensure that security is both visible but also seamlessly embedded within the culture of the organisation in my view. I think resilience really starts with a simple philosophy. If you see something, say something and that is on everyone in the organisation to work with in terms of kind of sending through those early warning signals to a business where it isn't always needed to rely on the crisis or security teams to do that. 

Building a "see something, say something" culture 18:00 – 21:07 

So that's about building a culture that encourages people to speak out, to say something if they spot, for example, unusual supplier behaviour, or if there is an unexpected result from an AI tool. Speak out. But that requires an organisation to empower people and for people to know that they will be heard. The opposite to that is obviously where they don't think they'll be heard. And the organisation will be all the weaker because of that. So, I think that kind of importance around building culture, where security is both visible, but also embedded is really critical. 

Caspar: Are you getting people speaking up at Standard Chartered? 

Shelley: Yeah. Look, it goes back to my culture point. We're, an organisation that, you know, culture is absolutely in the centre of this, and, you know, through our operational excellence program that we run, it's that mantra, see it, own it, solve it. And we also then want an organisation where people feel comfortable to use a judgment. They can speak up earlier but also then they have a sense of responsibility and they're accountable. 

And that's why it also goes back to your earlier question is, it's that mindset when you're looking at the skills profile to bring in the organisation, it's everyone from the frontline teams that are dealing with customers every day. But it's also right through to our leadership team that feel like this is, the DNA in the organisation, not to hinder. But if you get the timing around the predictive and the proactive approach, there will be a number of examples that show actually the speed to market is a lot less by doing that upfront due diligence, especially if I reflect on Standard Chartered, we are in some of the most diverse markets around the world, you know, particularly with a strong presence in Asia, Africa and Middle East. We have to do that up-front due diligence and think about the ‘what if’ scenario. We're not going to get it right. There are things happening now that I could never have predicted. But I think that then shows that the bank's willingness to think about those elements so that we can support the business as we go into those markets, develop those products, or launch those services. But it's got to come from the culture. 

Caspar: So, a lot of this is about people within Standard Chartered making the change, being proactive, adopting new ways of working. How do the clients experience this new security posture? 

How Security Builds Trust and Confidence 21:07 – 24:16 

Shelley: Yeah, I think there are two things, you know, do you want a client to, have something that's quite visible? Or do you want a client as part of their journey for it to be integrated? I think it needs to be both. If I look at the Standard Chartered footprint, as I mentioned, how we operate and support our clients in a secure and confident way in our markets, in Africa versus Asia versus Europe is very different. 

So, we need to be able to flex and localise. A client should not need to understand every control that is behind their visit or their interaction, but they do need to make sure that experience is something that differentiates us from service. It continues to build trust with the organisation and in many cases, some of the, more, diverse locations we do want a physical posture. We do want a physical representation of security, and that gives people confidence. But I would say for our clients, we are going to demonstrate that it's integral to their experience and part of our DNA through how we show up and how we perform. And that's really what matters, that sentiment to our customers. 

Caspar: James, how have you seen this in other types of organisations that Control Risks has worked with? 

James: So Control Risks, just because of our DNA as a company and what we do, we often see a lot of organisations operate under a lot of pressure and stress, often in the midst of a crisis. And I think trust for an organisation with its customer is earned best when they manage that crisis or that situation effectively, where they are clear in that communication, where the customer doesn't see the underlying controls and methodologies that underpin that response to whatever the issue may be, but where they continue to receive a seamless service, where the critical services of the organisation remain intact. So, I think that trust is best seen often when an organisation is under pressure, or in the midst of a, of a crisis. 

That is where an organisation gets to execute against the escalation routes that it's defined, the response plans that it's tested, most effectively. And where all of that preparation, effectively gets executed, and where their reputation, integrity, even if actually it's been a damaging issue that they've been running through, actually is maintained ultimately with their clients or customer. 

Caspar: Yeah. And of course, by that point, the whole issue is being taken up and out of security functions. And it’s the CEO who's on the line there and it's critical for the entire organisation. I'm wondering obviously, we've been talking about a rapidly changing situation. We're not at a point where anything standing still.  

The Future of Resilience: Dependencies, AI and Concentration Risk 24:16 - end 

In five year's time, that you both got good answers for this, what do you think organisations that are getting most of this right, most of the time, will be doing that will that they're still resilient, safe and secure for the future. 

Shelley: Well, five years time ... There's probably some core ingredients that you should have, depending on what environment we’re in. I think back to the earlier point, is that you should treat resilience as a strategic capability and that this is not just a response function, and therefore it is something that, you know, you engage when something's going wrong and that you're part of that strategic advice right from the beginning. It's a thought process in the decisions you’re making throughout the organisation, not just you need a good crisis to sort of prove that team really is a value add. 

So, it's hard because they're often the unsung heroes. You know, in many cases, it's what we manage to avoid, is going to really give us the edge. But this response function, they'll have clear ownership, will have much stronger data and intelligence, I think, particularly through, some of the emerging technology. We will be in a hybrid model, will use more partnerships, such as a Control Risks that can bring in the outside as well as augment the inside that we have. You’ll have an integrated team so it won't just be, you know, 4 or 5 different departments and it will be client centric. You know, our clients in five years time are going to be dealing with the financial services environment that's going to look very different. So, it's going to need to be led by those client needs. And then how we can respond to those client needs in a timely and relevant manner. 

So those would be the few things that, I'd be thinking about if I was looking to, to put this organisation together in the next few years. 

Caspar: Great. And James, horizon scanning is a thing we like to talk about a lot of Control Risks. I'm suggesting your answer might include that expression. 

James: Possibly, probably. Caspar. I’ll try and avoid using it now. 

Caspar: Well, it's a good one. We've got to do it. 

Shelley: It is a good one.  

James: I would echo everything Shelly has just said and particularly around looking at resilience as a, as a strategic thing for the organisation. I’d probably emphasize two key points. I think organisations who will be successful in five year’s time will be across the kinds of dependencies they have in the organisation, whether that's technology, people, data critical services. 

They'll know where their dependencies are, and they'll know how to respond to issues or risks that start to cascade across them from a disruption point of view in a more joined up, and coherent way than perhaps they do now, to echo a lot of the themes that we've been talking about in this session. And I think the other main area is organisations who will be successful will be managing their concentration risk a lot more effectively. 

So when you think about AI, cloud, digital infrastructure, all of this is highly concentrated in the hands of a very small, highly concentrated group of providers. Managing that concentration risk, I think, moving forward from a resilience point of view is not just about protection, it's also about choice. It's about the choices that you make as an organisation. In some cases, you may not need to switch provider or large language model, for example. But in some cases you may need to. And the organisations that are able to switch provider to isolate a dependency, where there is an issue, I think will be more successful than the ones who are very much aligned to a singular way of working, or a singular route where they have little option but to stick with the same provider. So, I think managing that dependency risk and that concentration risk is going to be, a real marker of success in the future for organisations. 

Caspar: There we are. So that's about all we've got time for in this conversation. Shelly Boland, Head of Corporate Real Estate and Services at Standard Chartered. Thank you so much for sharing your insights and experiences. 

It's been really interesting to hear what you've achieved and will go on to achieve at Standard Chartered and James Owen, thank you so much for taking part in this edition of The Ground Truth. And thank you all for listening and watching, however you consume the podcast. We’ll be back in just under a month from now. Do join us then. Bye for now. 

Get in touch

Can our experts help you?