Geopolitical Risk in Vendor Management — The New Reality - ZServiceDesk Blog

Geopolitical Risk in Vendor Management — The New Reality

Geopolitical Risk Is No Longer a Checkbox — It's a Central Driver of Vendor Decisions The New Risk Reality Geopolitical risk has largely been a check box item in organizations' IT risk management documents, until now . As geopolitical tensions hit an all-time high with the tariff wars as well as the ongoing Russia-Ukraine and Israel-Palestine conflicts, the theoretical frameworks are now being widely tested in the real world . The Microsoft Suspension: A Warning Trigger No risk management framework and business continuity plan would have prepared Nayara Energy (an oil refinery company backed by Russia's Rosneft) for the sudden suspension of Microsoft's cloud services following the EU sanctions on Russia. This one incident might be an exception pointing to one extreme, but nevertheless a warning trigger . Why Geopolitical Risk Matters Sanctions and Trade Restrictions Sanctions, tariff wars and trade restrictions are impacting nearly all geographies . These risks will increasingly wield stronger influence on CIOs' decisions around how they assess their vendors, draw up contracts and conduct audits . Hidden Risks A company may appear operating solely within one jurisdiction but might have a parent company or key investors subjected to regulations from a different country . Service Suspension Bans on technology companies serve as clear examples of services being abruptly restricted due to regulatory actions . Integrating Geopolitical Risk into VRM Vendor Assessment : Evaluate geopolitical exposure of technology partners  Screen vendors and their parent companies for sanctions  Evaluate connections with sensitive regions  Assess vulnerability to sanctions  Evaluate dependencies on other potentially high-risk third parties  Continuous Monitoring : Stay informed of evolving global regulations  Use threat intelligence feeds and news monitoring  Use specialized risk assessment platforms for real-time alerts  Monitor sanctions lists and political risk indices  Contractual Protection : Stronger vendor contracts covering data access, suspension triggers and emergency continuity  Very strong force majeure clause to include geopolitical aspects  Options to pause services or promptly terminate if vendor is sanctioned  Vendor Diversification : Avoid over-reliance on a single vendor from sensitive regions  Enlist alternative vendors for critical services  Identify plan B vendors upfront  The Strategic Shift "Vendor risk can no longer be assessed solely from a technical or procurement perspective. Geopolitics must be a central consideration in organizations' digital infrastructure decisions" . Proactive Strategies Vendor Diversification: Avoiding over-reliance on a single vendor from sensitive regions helps ensure operational resilience . Plan B Vendors: "For critical services, identify a plan B upfront. This could be a different vendor or an internal capability. If geopolitical risks are elevated and have the potential to impact your suppliers, proactively engage with your identified plan B vendors" . Collaboration: Collaborate with legal, policy, risk and procurement teams to co-own vendor onboarding and risk mapping . Conclusion Geopolitical risk is no longer a peripheral issue for CIOs. Organizations must integrate geopolitical risk into assessments, contracts and monitoring to ensure business continuity . Action Items for Your Organization Integrate geopolitical risk into vendor assessments Screen vendors and parent companies for sanctions Review and strengthen vendor contracts Diversify critical vendors Identify plan B vendors Monitor geopolitical developments continuously Geopolitical Risk Is No Longer a Checkbox — It's a Central Driver of Vendor Decisions The New Risk Reality Geopolitical risk has largely been a check box item in organizations' IT risk management documents, until now . As geopolitical tensions hit an all-time high with the tariff wars as well as the ongoing Russia-Ukraine and Israel-Palestine conflicts, the theoretical frameworks are now being widely tested in the real world . The Microsoft Suspension: A Warning Trigger No risk management framework and business continuity plan would have prepared Nayara Energy (an oil refinery company backed by Russia's Rosneft) for the sudden suspension of Microsoft's cloud services following the EU sanctions on Russia. This one incident might be an exception pointing to one extreme, but nevertheless a warning trigger . Why Geopolitical Risk Matters Sanctions and Trade Restrictions Sanctions, tariff wars and trade restrictions are impacting nearly all geographies . These risks will increasingly wield stronger influence on CIOs' decisions around how they assess their vendors, draw up contracts and conduct audits . Hidden Risks A company may appear operating solely within one jurisdiction but might have a parent company or key investors subjected to regulations from a different country . Service Suspension Bans on technology companies serve as clear examples of services being abruptly restricted due to regulatory actions . Integrating Geopolitical Risk into VRM Vendor Assessment : Evaluate geopolitical exposure of technology partners  Screen vendors and their parent companies for sanctions  Evaluate connections with sensitive regions  Assess vulnerability to sanctions  Evaluate dependencies on other potentially high-risk third parties  Continuous Monitoring : Stay informed of evolving global regulations  Use threat intelligence feeds and news monitoring  Use specialized risk assessment platforms for real-time alerts  Monitor sanctions lists and political risk indices  Contractual Protection : Stronger vendor contracts covering data access, suspension triggers and emergency continuity  Very strong force majeure clause to include geopolitical aspects  Options to pause services or promptly terminate if vendor is sanctioned  Vendor Diversification : Avoid over-reliance on a single vendor from sensitive regions  Enlist alternative vendors for critical services  Identify plan B vendors upfront  The Strategic Shift "Vendor risk can no longer be assessed solely from a technical or procurement perspective. Geopolitics must be a central consideration in organizations' digital infrastructure decisions" . Proactive Strategies Vendor Diversification: Avoiding over-reliance on a single vendor from sensitive regions helps ensure operational resilience . Plan B Vendors: "For critical services, identify a plan B upfront. This could be a different vendor or an internal capability. If geopolitical risks are elevated and have the potential to impact your suppliers, proactively engage with your identified plan B vendors" . Collaboration: Collaborate with legal, policy, risk and procurement teams to co-own vendor onboarding and risk mapping . Conclusion Geopolitical risk is no longer a peripheral issue for CIOs. Organizations must integrate geopolitical risk into assessments, contracts and monitoring to ensure business continuity . Action Items for Your Organization Integrate geopolitical risk into vendor assessments Screen vendors and parent companies for sanctions Review and strengthen vendor contracts Diversify critical vendors Identify plan B vendors Monitor geopolitical developments continuously  
Read More 13 Mar 2024
The Five Whys — The Simplest and Most Effective RCA Technique - ZServiceDesk Blog

The Five Whys — The Simplest and Most Effective RCA Technique

Most Teams Stop at Why #1 — How the Five Whys Uncovers the Real Root Cause What Is the Five Whys Technique? The "5 Whys" technique is used in the Analyze phase of Six Sigma DMAIC methodology and is recommended in many other RCA techniques . It is one of the simplest tools to use and is easy to complete without statistical analysis . By repeatedly asking "Why?", layers of symptoms are explored, which can lead to the root cause of a problem . How to Perform a Five Whys Analysis Step-by-step process : Write down the specific problem: Writing helps to formalize the problem and describe it completely. It also helps a team focus on the same problem. Ask why the problem happens and write the answer down below the problem: If the answer does not identify the root cause, ask "Why?" again and write down that answer. Loop back until the team agrees that the problem's root cause is identified: This process may take more or fewer times than five iterations. When to Use the Five Whys The 5 Whys tool is most useful when : Problems involve human factors or interactions You need a quick, simple analysis You're working without statistical tools You need to build consensus on root causes The 5 Whys in Practice Example from a six-sigma context : Problem: Parts are measuring out of specification Why? Part not installed correctly Why? Employee skipped an operation Why? Work environment too dark Why? Poor lighting Why? Light bulbs burned out Without the 5 Whys: The employee may have been retrained With the 5 Whys: The light bulbs were replaced, preventing recurrence Common Mistakes to Avoid Mistake Impact Solution Stopping too early Addresses symptoms, not root causes Keep asking "Why?" Asking the wrong "Why" Follows wrong path Focus on the problem, not a symptom Blaming individuals Creates defensiveness, misses system issues Focus on systems, not people One "Why" per level Misses multiple causes Explore each branch Not validating May miss the true root cause Test hypotheses The "5 So What" Analysis A step beyond the 5 Whys analysis is the 5 So What analysis : The "So What" analysis is useful to identify prioritizing potential solutions or corrective actions. By asking "So What" in response to the impact of a potential solution, the team will reach maximum impact . Example : Potential solution: Retrain the seed placement team So What? They could still violate the SOP Further solution: Allow more time, retrain the team, and increase oversight So What? Any violation would be detected before data collection Combining 5 Whys with Ishikawa Diagrams The Ishikawa Diagram is helpful in diagramming the 5 Whys process : Use the Ishikawa diagram to identify potential causes Use the 5 Whys to dig deeper into each potential cause Each time a cause is identified, use the 5 Whys to dig deeper  Conclusion The Five Whys is the simplest and most effective RCA technique. By asking "Why?" multiple times, teams can identify root causes that would otherwise remain hidden. The key is to keep asking until you reach a cause that can be addressed. Action Items for Your Organization Train your team on the Five Whys technique Create a Five Whys template Practice with real problems during team meetings Document the results of Five Whys analysis Validate that identified root causes are genuinely addressable  
Read More 07 Mar 2024
Change Is Personal — Designing Hyper-Personalized Change Journeys - ZServiceDesk Blog

Change Is Personal — Designing Hyper-Personalized Change Journeys

Headline: Employees Experience Change Differently — Why One-Size-Fits-No-One Is the Problem The Personalization Imperative Change isn't just organizational—it's personal. Just as airline passengers may land at the same destination but recall the journey differently, employees experience change in ways shaped by their roles, contexts, and engagement . The Expectation Gap In today's world, people have come to expect personalization everywhere—in the products they buy, the content they consume, and the experiences they choose. That same expectation now extends into the workplace. Employees want change that feels as intuitive and relevant as the technologies and services they use every day . Yet most change approaches still rely on one-size-fits-all tactics that overlook differing motivations, mindsets, and needs. The Data Gap While more than two-thirds (67%) of leaders believe it is important to customize the design and experience of work and workforce practices based on worker skills, behavioral patterns, motivations, passions, and work styles, only 7% of leaders are taking action . Hyper-Personalization The next evolution of change is hyper-personalization: change journeys that adapt dynamically to each person's role, readiness, and response . What hyper-personalization looks like: Personalized change journeys based on role, readiness, and previous experience Messaging adapted to leaders' voices Real-time feedback and behavior-based coaching Action prompting tailored to individual needs  Personalization in Practice Example: Field Representative Coaching A field representative preparing for a customer conversation might turn to a coaching chatbot—not for scripted answers, but for a space to experiment. The representative could roleplay different scenarios, refine their message, and receive personalized feedback based on their tone, approach, and confidence level . Instead of static learning, the experience becomes a personalized dialogue that builds skill, confidence, and ownership . Meeting People Where They Are Personalization in change isn't about giving everyone the same toolkit—it is about meeting people where they are. When an organization's learning and support initiatives adapt to an individual's context, employees gain the freedom to experiment, practice, and grow with confidence . Conclusion By using AI to offer hyper-personalized change journeys, organizations can open the door to personal change so people tune in instead of tuning out . The future of change is not about doing more of the same—it's about doing different things for different people. Action Items for Your Organization Map employee personas for change audiences Develop personalized change journeys for different roles Use AI to recommend content based on role and progress Measure engagement and adoption by persona Design change experiences that meet people where they are
Read More 05 Mar 2024
From SLAs to XLAs — Measuring Problem Management Success in the Experience Era - ZServiceDesk Blog

From SLAs to XLAs — Measuring Problem Management Success in the Experience Era

SLA Compliance Isn't Enough — Why Problem Management Must Focus on Employee Experience   The Limitations of SLAs Traditional Service Level Agreements (SLAs) focus on: ? How quickly incidents are resolved ? Whether service availability targets are met ? Technical metrics of service performance But SLAs have significant limitations: ? They measure technical performance, not user experience ? They can be met while users are still frustrated ? They don't capture the quality of the resolution ? They don't reflect the impact of recurring problems The Shift to XLAs Experience Level Agreements (XLAs) focus on what users actually experience: ? User satisfaction: Were users happy with the resolution? ? Productivity impact: Did the issue affect user productivity? ? Effort: How much effort did the user expend? ? Friction: How smooth was the overall experience? The AI-driven approach to problem management shifts IT operations toward a ticketless future—moving past traditional SLAs to focus on XLAs . How XLAs Transform Problem Management Dimension SLA Focus XLA Focus Measurement Technical metrics User experience Success Meeting targets Positive outcomes Resolution Speed of fix Quality of experience Prevention Incident avoidance Friction elimination What XLAs Measure Experience Level Agreements typically measure: 1. User Satisfaction: CSAT scores and feedback 2. Productivity Impact: Time lost due to issues 3. Effort: How easy was it to get help? 4. Friction: How many interactions were required? 5. Repeat Contact: Did the issue recur? Why XLAs Matter for Problem Management Problem management has a direct impact on employee experience: Problem Management Activity Employee Experience Impact Eliminating recurring issues Reduces frustration and lost productivity Proactive prevention Prevents disruption entirely Known error documentation Faster resolution when issues occur Root cause elimination Permanent fixes, not temporary workarounds Benefits of Moving to XLAs Benefit Impact Better alignment with business Service metrics reflect business outcomes Higher user satisfaction Focus on what users actually experience More effective problem management Root causes of poor experience are addressed Clearer value demonstration Problem management ROI is more visible Improved decision-making Metrics drive the right priorities Conclusion The shift from SLAs to XLAs represents a fundamental change in how we measure service success. In the experience era, problem management is not just about preventing incidents—it's about creating a frictionless, satisfying experience for users.   Action Items for Your Organization ? Review your current problem management metrics—are they SLA-based or XLA-based? ? Define XLAs for key service experiences ? Start measuring employee satisfaction and productivity impact ? Use XLA data to prioritize problem management investments ? Demonstrate the connection between problem management and employee experience  
Read More 21 Feb 2024
The Employee Experience Impact of Service Request Management - ZServiceDesk Blog

The Employee Experience Impact of Service Request Management

Service Request Management Isn't About Tickets — It's About Employee Experience The Connection Between Service and Experience Service request management significantly impacts employee experience and satisfaction. Quick and transparent handling of requests boosts morale and confidence in management . The Connection: Driver Impact Satisfied employees More engaged and productive Engaged employees Higher performance Lower turnover Stable, experienced workforce Employee Experience Success Indicators Quick and transparent handling of requests: Employees feel valued when their requests are handled efficiently Confidence in management: When employees see things get done, they trust leadership Reduced frustration: No more guessing about request status or chasing responses How Service Request Management Affects EX Positive Impact Negative Impact Fast, automated resolution Slow, manual processes Transparent status tracking Requests disappear into the void Consistent experience Different experiences for different departments Easy self-service Complex forms and navigation Supportive, helpful interactions Frustrating, confusing responses Measuring Employee Experience Metric What It Measures CSAT Satisfaction with service NPS Willingness to recommend Effort score How easy was the interaction? Resolution time How quickly was it resolved? Repeat contact Was it resolved the first time? Conclusion Service request management isn't about tickets — it's about people. Organizations that design service experiences around employees will see better satisfaction, engagement, and retention. Action Items for Your Organization Survey employees on their service experience Identify friction points in the request process Design service experiences around employee needs Measure and track employee satisfaction Use feedback to improve
Read More 08 Feb 2024
Tool Sprawl and Incident Investigation Readiness - ZServiceDesk Blog

Tool Sprawl and Incident Investigation Readiness

94% Struggle with Multi-Tool Complexity — Why Fragmentation Is Your Incident Response Enemy The Fragmentation Problem Modern IT environments are fragmented. Organizations use multiple tools for monitoring, alerting, logging, incident management, and communication. 94% of organizations say managing multiple security tools is at least moderately challenging , and more than half describe it as very or extremely difficult. This fragmentation directly impacts incident investigation readiness. When an incident occurs, investigators need to: Correlate events across multiple tools Access data from multiple sources Understand context from multiple systems Fragmentation makes all of this harder. The Investigation Challenge Scenario: P1 Incident A P1 incident occurs. The investigation requires: Information Tool Challenge Alert details Alerting tool Tool A System metrics Monitoring tool Tool B Logs Log management Tool C Application traces APM tool Tool D User impact Analytics tool Tool E Incident details ITSM platform Tool F Communication Chat tool Tool G Investigators need to access 7+ tools to piece together what happened. The Investigation Process Check the alerting tool for what triggered Check the monitoring tool for metrics Check the log management tool for logs Check the APM tool for traces Check the analytics tool for user impact Check the ITSM platform for incident details Check the chat tool for communication Each step takes time. Each tool requires context switching. Each tool has different access, permissions, and interfaces. The Impact of Fragmentation Impact Description Slower investigation Context switching between tools takes time Incomplete investigation It's easy to miss relevant information across tools Inconsistent findings Different tools may have different views of the same event Inefficient communication It's hard to share findings when everyone uses different tools Increased cognitive load Investigators must remember how to use multiple tools Training challenges Teams must be trained on all tools Cost Multiple tools mean multiple licenses, integrations, and maintenance The Fragmentation Root Causes 1. Best-of-Breed Acquisition Organizations acquire best-of-breed tools for specific needs. Each tool is excellent at its function, but integration between tools is poor. 2. M&A Activity Mergers and acquisitions bring together different tool sets. Integration is often difficult and expensive. 3. Tool Sprawl Teams adopt new tools without retiring old ones. Over time, the tool landscape becomes cluttered. 4. Organizational Silos Different teams (monitoring, logging, incident management) adopt different tools. Sharing information across teams is difficult. 5. Short-Term Decision Making Tools are selected for immediate needs, not long-term strategy. The result is fragmentation over time. The Consolidation Trend More than half of organizations are actively pursuing vendor and tool consolidation . Why Consolidate? Benefit Description Faster investigation Fewer context switches More complete investigation All data in one place Consistent findings Single source of truth Easier communication Shared data and tools Lower cognitive load Learn fewer tools Reduced cost Fewer licenses and integrations Better training Focus training on fewer tools A majority believe a unified platform is more effective than point solutions. The Unified Platform Approach What a Unified Platform Provides Capability How It Helps Single dashboard All incident information in one place Correlated data Events from multiple sources are correlated Single workflow Consistent process across incident management Shared knowledge Learning is shared across the organization Integrated communication Incident communication from the platform The Unified Platform for Incident Response Feature Purpose Alert consolidation Alerts from all sources in one place Incident management Track incidents from detection to resolution Communication Internal and external communication Knowledge management Capture and share incident learnings Analytics Track metrics and identify trends Implementation Considerations 1. Assess Current State What tools do you have? What are they used for? Where are the gaps? Where is the overlap? 2. Define the Target State What should a unified platform look like? What capabilities are needed? What tools should be retained? 3. Choose the Platform Options for unified platforms Integration capabilities Migration path 4. Migrate Plan migration from legacy tools Prepare for disruption Train teams 5. Optimize Continuously improve Retire legacy tools Expand capabilities The 61% Protection Expansion Over the next 12 months, 61% of organizations plan to expand AI protections. As AI protections expand, the importance of unified incident response grows. AI incidents require correlated data, consistent investigation, and coordinated response—all of which are harder in fragmented environments. Conclusion: Fragmentation Is Your Incident Response Enemy Tool fragmentation makes incident response harder, slower, and less effective. Organizations that consolidate tools—or integrate them effectively—will be better prepared for incident investigation. The goal isn't to have one tool that does everything. The goal is to have a tool landscape that enables effective incident response. Action Items for Your Organization Assess tool fragmentation: What tools do you have? Where are the gaps? Define integration requirements: What needs to be integrated? Consolidate where possible: Reduce the number of tools Integrate where consolidation isn't possible: Ensure integration Measure investigation speed: Track how long investigations take Plan for AI protection expansion: Ensure your tool landscape can support expanded AI protections  
Read More 28 Jan 2024