Zbyněk Vallo

  • Senior Consultant in Cybersecurity
  • EY Czech Republic

Senior Consultant in Cybersecurity at EY, specializing in Governance, Risk & Compliance (GRC), DORA and NIS2 regulations, and Information Security Management Systems (ISMS) based on ISO 27001. Prior to joining EY, he worked at the National Cyber and Information Security Agency (NÚKIB), where he was involved in the preparation and execution of national and international cybersecurity exercises. He holds the ISO/IEC 27001 Lead Auditor and Lead Implementer certifications and contributes to projects focused on regulatory compliance and enhancing digital resilience, particularly within the financial sector.

Sessions

  • When BCM Becomes a Spreadsheet: Lessons Learned and Practical Paths to Resilience

    Many organizations have Business Continuity Management (BCM) frameworks in place, yet few achieve their intended purpose. BCM often evolves into a complex spreadsheet maintained by a single individual, producing limited value for decision-making and resilience management. This presentation explores where and why this approach breaks down, showing how growing volumes of interconnected data can gradually undermine Business Impact Analysis (BIA), risk management, and recovery planning. Drawing on practical experience from projects across banking, government, and critical infrastructure sectors, we will share key lessons learned in designing a sustainable BCM ecosystem, including the management of assets, BIAs, risks, and recovery plans. The session will also discuss effective approaches to impact criteria, risk appetite, and the critical role of executive sponsorship in ensuring long-term BCM success. Finally, we will present a practical and cost-effective approach to modernizing BCM without relying on large-scale GRC platforms, including the use of lightweight applications and modern rapid-development techniques. The objective is to share real-world experience, highlight common pitfalls, and provide inspiration for building a BCM framework that genuinely supports organizational decision-making and resilience rather than merely satisfying compliance requirements.