Skip to Content

Resilient Enterprise & Workforce

To protect our people and mitigate the impacts of disruptions, our business assurance and business continuity programs partner across the enterprise to plan for, respond to, and support recovery from a variety of scenarios. Our Business Assurance Office plans for and manages crises that could endanger the life, safety, and wellbeing of Booz Allen people and disrupt business operations.

We engage in proactive risk monitoring, employee outreach, local- and executive-level planning, and stakeholder training to ensure all areas of our firm are prepared for potential threats. As Booz Allen's facility footprint continues to evolve, we leverage workforce data, including home locations, to understand the distribution of our workforce—with an eye to understanding our risks for both recurring known threats, like seasonal natural disasters, and unpredictable events, like acts of violence.

Our 24/7 Global Security Operations Center (GSOC) keeps watch on evolving threats. When real-world incidents occur, our Business Assurance Office provides tactical response leadership to ensure local leaders in our geographically based Incident Command Teams (ICT) have all needed cross-functional support. We leverage the emergency alert system (EAS) to push out emergency guidance and account for the wellbeing of colleagues, and we partner with the Employee Care Center to provide personalized follow-up to support recovery.

Our Business Continuity Program Office maintains and promotes the firm's business continuity management system through business continuity plans, critical business operations recovery strategies, education initiatives, and related exercises to ensure our corporate functions can continue to operate and serve our clients during and following business disruptions. Through this multifaceted approach and close cross-team collaboration during crises, we foster resiliency and protect our business operations, including our people, physical and intellectual property, services, products, and assets. That supports our objective to provide continuous support for our corporate and clients' missions.

Our GSOC and Business Assurance Office monitor global developments and are trained to act in coordination with colleagues from across the enterprise when needed. This matrixed approach helps multiple business functions, including the Security Services, Global Workplace, People Services, and Enterprise Technology Services and Solutions teams, operate as one team to provide consistent and coordinated support for our people.

During the most severe incidents, the executive-level Crisis Management team offers leadership and guidance, facilitates decision making, and prioritizes resources to support our people.

Employee Emergency Preparedness

To make sure our people know what to do when certain emergencies strike, we offer preparedness awareness resources (e.g., topical articles in the firmwide newsletter and intranet, facility signage, on-demand e-learning), and we conduct training and provide recommended outreach messaging for local office leadership to cascade through our ICT program. Booz Allen also uses the EAS to provide timely, actionable guidance to employees and, when necessary, to account for their safety. Each quarter, we conduct firmwide EAS tests to ensure employees keep their contact information updated. The tests also reinforce a habit of responding promptly to alerts, enabling us to focus manual follow-up efforts during real emergencies on our people who might truly need assistance.

Enhancing Enterprise Resiliency

Resiliency Through Best Practices: In 2023, Booz Allen was recognized with a "Best in Resilience" certification from Everbridge, indicating our organization has met or surpassed benchmarks in key measurable areas, thus demonstrating our commitment to firmwide resilience. The assessment specifically highlighted our strengths in data and analytics, communication, and collaboration. It cited our capabilities to take in a variety of threat intelligence sources, layer on knowledge of the specific locations in which we operate (including homes), assess risks, and implement appropriate response measures.

We build resiliency into our formal global business continuity management system and maintain an active certification for that system, International Organization for Standardization (ISO) 22301:2019. This certification is evidence of our conformance to the industry-neutral best practices identified as necessary to maintain operations during a disruption. In addition, we leverage state-of-the-art technology to enhance the efficiency and effectiveness of our business continuity processes and plans.

Managing Incident Response: Booz Allen employs crisis/incident management, global risk monitoring, and coordinated response to critical incidents, tapping dedicated teams of experts before, during, and after incidents to implement swift, effective solutions that minimize adverse impacts on our people, property, operations, stakeholders, and clients. In FY23, our notable response efforts included supporting the business in Europe during the Russia-Ukraine war and energy crisis, providing guidance and resources from pre-landfall through full operational recovery during Hurricane Ian in Florida, and accounting for employees following the October 2022 crowd crush incident in Seoul, South Korea. We also have technological recovery solutions that protect the firm's valuable information assets, whether in a Booz Allen facility or on the go. See more information on page 47 of this report.

Keeping Our People Safe: We recognize that some parts of the world and specific lines of business may face higher threat levels. Accordingly, our risk matrix requires that subject matter experts review travel to identify high-/elevated-risk locations and certain types of work environments to ensure appropriate safeguards and mitigation plans are in place. We provide our people with location-specific protection and risk intelligence through pre-trip guidance, emergency applications, and tailored communications protocols; monitoring by our 24/7 GSOC; and mitigation, planning, training, and response support.