Masaryk University Faculty of Economics and Administration Field of study: Business Management BEHAVIORAL PATTERNS AND SKILLS INCREASING ORGANIZATIONAL RESILIENCE Bachelor Thesis Supervisor: Author: Mag. Dr. Eva GATARIK Patrik SKIP A L A Brno, 2018 XMOÉCO^' M A S A R Y K O V A UNIVERZITA Ekonomicko-správní fakulta Student: Obor: Název práce: Název práce anglicky: Cíl práce, postup a použité metody: Rozsah grafických prací: Rozsah práce bez příloh: Literatura: ZADANÍ BAKALÁRSKE PRACE Akademický rok: 2017/2018 Patrik Skipala Podniková ekonomika a management Vzorce chování a dovednosti posilující resilienci organizace Behavioral patterns and skills increasing organizational resilience Cílem práce je zjistit vzorce chování a s nimi spojené znalosti a dovednosti potřebné pro zvládnutí nečekaných událostí. Na základě existující literatury a kvalitativní studie resilientního a neresilientního chování ve vhodně vybrané organizaci bude identifikován specifický soubor chování, znalostí a dovedností podporující resilienci organizace. Kromě toho bude identifikován a popsán soubor organizačních předpokladů (podmínek a procesů) podporující uplatňování tohoto chování, znalostí a dovedností na úrovni jednotlivců a týmů. Součástí práce bude popis metody sběru dat, jejich analýza, souhrn zjištěných výsledků a diskuze. Podle pokynů vedoucího práce 35 -45 stran WHITE, Harrison C. Identity and control : a structural theory of so-cial action. Princeton, N.J.: Princeton University Press, 1992. xix, 423. ISBN 069100398X. WEICK, Karl E. Making sense of the organization. 1st pub. Maiden: Blackwell Publishing, 2001. xii, 483 s. ISBN 0-631-22319- 3. Vedoucí práce: Pracoviště vedoucího práce: Datum zadání práce: 6. 2. 2017 WEICK, Karl E. Making sense of the organization.. Chichester: Wiley, 2009. viii, 300. ISBN 9780470742204. EASTERBY-SMITH, Mark, Richard THORPE and Paul JACKSON. Management and business research. 5th edition. London: Sage, 2015. xvi, 377. ISBN 9781446296585. WEICK, Karl E. and Kathleen M . SUTCLIFFE. Managing the unexpected: resilient performance in an age of uncertainty. 2nd ed. San Francisco: John Wiley & Sons, 2007. xii, 194. ISBN 9780787996499. HAMEL, Gary and Viktor JUREK. Na čem dnes záleží : jak vyhrát ve světě neustálých změn, dravé konkurence a nezastavitelné inovace. 1. vyd. Praha: PeopleComm, 2013. 311 s. ISBN 9788090489066. WEICK, Karl E. Sensemaking in organizations. Thousand Oaks: SAGE Publications, 1995. xii, 231. ISBN 9780803971769. Social science research : from field to desk. Edited by Barbara Czarniawska. 1st pub. Los Angeles: SAGE, 2014. x, 175. ISBN 9781446293942. The Oxford handbook of organization theory. Edited by Haridimos Tsoukas - Christian Knudsen. Oxford: Oxford University Press, 2003. xxi, 644. ISBN 9780199275250. The SAGE handbook oforganizational behavior.. Edited by Julian Barling - Cary L. Cooper. London: SAGE, 2008. xxiii, 749. ISBN 9781412923859. The SAGE handbook of organizational research methods. Edited by David A. Buchanan - Alan Bryman. Los Angeles: SAGE, 2009. xxxvi, 738. ISBN 9781446200643. WEICK, Karl E. The social psychology of organizing. Second edition. New York: McGrawHill, 1979. ix, 294. ISBN 0075548089. Mag. Dr. Eva Gatarik Katedra podnikového hospodářství Termín odevzdání bakalářské práce a vložení do IS je uveden v platném harmonogramu akademického roku. V Brně dne: 8.4.2018 Name and surname of the author: Master's thesis title: Department: Master's thesis supervisor: Master's thesis date: Patrik Skipala Behavioral patterns and skills increasing organizational resilience Department of Corporate Economy Mag. Dr. Eva Gatarik 2018 Annotation The part of this thesis is literature review on the organizational resilience and its two big theories, High-Reliability Organization and Resilience Engineering, based on which the set of research questions was made. These research questions were tested on the Nuclear Power Plant to show and propose behavioral patterns and skills that help to foster resilience of the organization. The results highlights those patterns and skills other organizations shall use to help build the resilience of their own organizations and enterprises. Keywords High Reliability Organization, Resilience Engineering, monitor, anticipate, respond, learn, organizational resilience Declaration „1 certify that I have written the Bachelor's Thesis Behavioral patterns and skills increasing organizational resilience by myself under the supervision of Mag. Dr. Eva Gatarik and I have listed all the literary and other specialist sources in accordance with legal regulations, Masaryk University internal regulations, and the internal procedural deeds of Masaryk University and the Faculty of Economics and Administration." Brno, Author's signature Table of Contents Introduction 10 1 What is resilience 1 1 1.1 Definition of resilience 11 1.2 Recognition of resilience in action 12 1.3 Individual - Group - Organization 13 2 High Reliability Organization 15 2.1 Definition and roots of High Reliability Organization 15 2.2 Normal Accident Theory vs. High-Reliability Theory 16 2.3 Characteristics of High Reliability Organizations 16 2.4 Mindfulness I 7 2.4.1 Preoccupation with failure 19 2.4.2 Reluctance to simplify 19 2.4.3 Sensitivity to operations 20 2.4.4 Commitment to resilience 20 2.4.5 Deference to expertise 21 3 Resilience Engineering 22 3.1 Introduction to Resilience Engineering 22 3.2 The abilities of Resilience Engineering 23 3.2.1 The ability to monitor 23 3.2.2 The ability to anticipate 23 3.2.3 The ability to respond 24 3.2.4 The ability to learn 24 4 Research Methodology 26 4.1 Research Subject 26 4.2 Methodology 26 5 Findings 28 5.1 The ability to monitor 28 5.2 The ability to anticipate 28 5.3 The ability to respond 30 5.4 The ability to learn 31 6 Discussion 33 6.1 Limitations 33 6.2 Further Research 34 Conclusion 35 References 36 List of figures 42 List of abbreviations 42 List of appendices 43 Appendices 43 Introduction Events of the last two decades remind us that a natural as well as human-made disasters and crisis can be devastating and occur far more frequently than previously expected or foreseen and show us the vulnerability of modern infrastructures to the forces of nature (Everly Jr., 2011). The reason of the human-made errors and disasters was very often the relentless pursuit of "better, cheaper, faster" leading toward decisions that erodes safety margins without realizing the increased risks (Woods, 2003). Therefore, companies have started paying more attention on Business Continuity Management (BCM) in the recent years. B C M focuses both on potential threats identification and the management of the unexpected events. Moreover, the ability to resist events and disruptions contributes to the competitive advantage of the organization. As Charles Darwin said, "It's not the strongest species that survive, nor the most intelligent, but the most responsive to change." However, it's quite a theoretical concept. Prior to the events of 2008, Seville (2008) joked that "resilience is the new black". Everywhere you turn, the word resilience just keeps cropping up. It seems that resilience is being presented far and wide as a shining goal for the future. In the first part of this thesis, literature review on the resilience is conducted, its definition and recognizing resilience in the real world, plus the literature review on the High Reliability Organization and Resilience Engineering concepts as the two theories on providing advice on how to achieve greater resilience in a practice. In the second part of this thesis, the methodology for empirical research will be described as well as a set of the research questions will be created based on the theory for the resilience. For the purpose of this thesis, the High Reliability Organization (HRO) will be selected for the empirical research. HROs are seen as Phoenix, not only they survive damages but take advantages of it, develop themselves and are born again as Phoenix from the ashes. However, HROs normally receive attention only when things go wrong. General description of HROs is simply organizations operating with low failure rate while potential error of usually low probability could initiate high consequences events. Furthermore, HROs are known for their strong mindfulness through the five principals they work with. HRO is not all or nothing matter (Hopkins, 2007). It's the system where what they do every day is what they do in an emergency. Afterwards, the qualitative research via semi-structured interviews with the representatives of the organization is to be conducted and the study of available documents of the organizations, too, to identify and determine behavioural patterns and skills of the organization increasing organizational resilience and managing unexpected events as well as to identify those patterns and skills on the individual, group and organizational level of resilience. In the end, discussion and summary of the thesis is made with the given limitations of the thesis. For the purpose of the empirical research, this thesis combines both reviewed resilience theories, the High Reliability Organization and Resilience Engineering concepts, and provide results and examples of behavioural patterns and skills increasing organizational resilience of the organization. The given results may help other organizations to achieve resilience and, therefore, competitive advantage, too. In the world of the uncertainty and risky decision making leaders, propose of the organizational resilience may contributes to those organizations. 10 1 What is resilience In today's point of view, resilience is consider as a factor of competitive advantage (Hamel & Jurek, 2013). Over the past years, noticed especially in the last two or three decades, businesses and academic have become aware that the certain organizations respond better to disruptions and negative situations than the other organizations, even organizations from the same area of business. Those organizations can be described as being more resilient. Faster and more quickly the businesses and enterprises are able to adapt to sudden and/or substantial changes in their environments or field of operation, it's more easy for them to seize or sustain competitive advantage. Some of those organizations exhibit this adaptation to changes with a minimal interruption to their functions and operation. Organization's resilience, in fact, has critical effects for its competitive position, profitability, and so on. However, not only does the resilience of the organization depends on the organization's capabilities alone but is dependent on all stakeholders of the organization, too. No organization is an island. Resilience of each of the organization is directly related to its customers, suppliers and distributors, laws and regulations, and whole competitive market as well as to resilience of its sector and, essentially, to the resilience of the nation, too. The organisation is also dependent on and also contributes to the individual resilience of its staff and the resilience of the communities they live in (Hillson, 2016). Couple of problems emerge in examining the association between the resilience itself and organizational processes (Boin & van Eeten, 2013). Firstly, it's not clear what exactly resilience is, therefore, definition is necessary. Secondly, it's quite hard to actually recognize resilience in action. We literally don't know when we see resilience. Instead, if an organization survive some kind of crisis or catastrophe we only assume that resilience must have been there. 1.1 Definition of resilience Not only academics were in need of defining resilience but governments as well. Whilst they are facing and handling threat of terrorism, cyber-attacks, natural disasters, crisis and many more the U.S. government (2010) defined resilience as "the ability to adapt to changing conditions and withstand and rapidly recover from disruption due to emergencies". On the other hand, British Standard (2014) defined organizational resilience more specifically as "ability of an organization to anticipate, prepare for, and respond and adapt to incremental change and sudden disruptions in order to survive and prosper". Resilience doesn't stop at a simple adaptation level, but as Masten (2001) points out resilience derives from human adaptation systems in forms such as self-regulation, relations to caring support, and drive for nature to be effective. Luthans (2002) simplify resilience as the positive psychological capacity to rebound from adversity, prevent, minimize or overcome the damaging effects of adversity (Grotberg, 1997), and increased responsibility. Hans Selye's study of stress conclude observation that, 'it is not what happens to you that matters, but how you take it. In other words, it is the capability at every relevant level of organization to react promptly, decisively and effectively to unforeseen and unexpected changes and unpredictable forces, even chaotic disruption and challenges (Popplewell, et al, 2010). Furthermore, it is the ability to bounce back quickly from adversity and, in fact, to bounce forward strengthened and more resourceful with quickness, grace, determination and accuracy (Vogus & Sutcliffe, 2007; Denney, 2008). Resilience is often described in many organizational studies as the maintenance of positive adjustment, desirable functions and a high level of performance and outcomes in the midst of strain under challenging conditions. "Challenging conditions" is simply specific interruptions 11 of the normal that can include disconnected errors, crises, and shocks, uncertainty, conflict, failure and disruptions of routines as well as risks like competition, stress, and strain, while environmental pressures mount, threats arise and uncertainties deepen (Lengnick-Hall, et al, 2011). Sutcliffe and Vogus (2003) say that resilience is "the continuing ability to use internal and external resources successfully to resolve new issues" as they argue resilience is capability that develops throughout processes from continually managing of the risks. Therefore, resilience can be defines as well as the ability of an organisation to survive a crisis and thrive in a world of uncertainty (Hillson, 2016). Wildavsky (1991) ads that resilience is also status of being vitally prepared for adversity which requires improvement in overall capability of the organization. As a matter of fact, organizations should be continuously improving ability to investigate, learn, and to act without prior knowledge to the events. Even though, resilient organizations believe they can readily cope with a wide range of abnormalities they are still endeavouring to foster their ability to do so. In other words, they know their knowledge and skills are imperfect but can become more perfect over the time by learning from events and near misses (Vogus & Sutcliffe, 2007). So resilience is not only the ability to rebound from adversity but also state of possessing knowledge of organization's conditions, situation, vulnerabilities and current capabilities and being able to make proper strategic decisions. Quick responding to a one-time crisis is not what strategic resilience is striving for; it's not only about rebounding from adversity to the normal state. What the strategic resilience is up to is being continuously anticipating and adjusting everything that can weaken the performance of the business; possessing the capacity to shift prior to the case for change becomes desperately obvious (Hamel & Valikangas, 2003). 1.2 Recognition of resilience in action As mentioned above, we simply cannot see resilience in the action. Being resilient is not a status that can be achieved and would mean success. Being resilient is about facing all challenges, both anticipated and unanticipated events as well as event that we simply don't know about yet. We can say it's confident of society's and organization's ability to address the Black Swan events. It's proactive and resolute approach of the organization to thrive in those conditions (White, 1992). Therefore, resilience is relative and changing with a given circumstances and challenges. No two events are exactly the same and same applies to resilience. Resilience applied for one situation may not be sufficient to other challenges over the time (Sutcliffe & Vogus, 2003). On the other hand, we can easily see result of resilience. Resilient organizations absorb the strain of bad outcomes and continue to function with collected new knowledge from experiences to reference in the future events. Those organizations does not lose control of what they do even in adversity and are still able to continue and rebound back (Weick & Sutcliffe, 2007). In other words, resilience allow people to produce success when failure threatens. And those people play crucial role in organizations to become resilient. It's up to people to quickly and effectively react and respond to changes while enduring minimal stress (Mallak, 1998). Resilience mainly provides insight into how organizations repeatedly accomplish desirable outcomes amidst adversity and strain. This processual approach distinguish organizations that survive from those that fail (Miller, 1993), or in another words, resilience provides insight into how organizations continually achieve desirable outcomes facing significant barriers to adaptation or development (Sutcliffe & Vogus, 2003). Resilient organizations act and exhibit similar features like High Reliability Organizations (HROs) that operate in extremely trying conditions and face serious and complex risks but 12 experience few to no errors, by possessing an "intelligent wariness" (Reason, 1997). Definition of resilience significantly overlap with the definition and characteristic of HRO while a key concept of HRO is resilience as they relentlessly prioritizing safety over performance. There is a clear link with Resilience Engineering that tries, as name ascribes, to design resilience within the organization through four abilities (to anticipate, to monitor, to respond and to learn). Both High Reliability Organisations (HRO) and Resilience Engineering (RE) are closely related concepts to achieve safely in environment of dynamic complexity or even in chaotic contexts as they synthesize safely and the core business. These organizations continually ask what is happening, never assuming complete understanding of the situation. Weick and Sutcliffe (2007) say, "resilience encourages people to act while thinking or to act in order to think more clearly". John Boyd describes this as continuous OODA loop process as observe, orient, decide, and act. Figure 1 Diagram of a decision cycle known as the Boyd cycle, or the OODA loop Unfolding Circumstances" Outside, Information Observe Implicit Guidance" & Control Orient Decide Implicit —Guidance& Control Act Feed Forward Action (Test) Unfolding Interaction With Environment Feedback- -Feedback- Feedback- Unfolding Interaction With Environment I Source: Boyd, John R. (1996) The Essence of Winning & Losing 1.3 Individual - Group - Organization Resilience can be seen from the three different levels, the individual level, the group level, and the organizational level, while neither organizational resilience is not the sum of group resilience nor group resilience is the sum of individual resilience (Sutcliffe & Vogus, 2003). Individual resilience is developed as individuals of organization have gained experiences sufficient enough to achieve success and create self-efficacy as motivation for future success and effort (Masten & Reed, 2002). Bonanno (2004) sees individual resilience as an optimistic system laden with positive emotion while some others argue that optimism is dangerous because it create blind spots. People shouldn't believe their knowledge is perfect but see it as imperfect and always try to enhance their resilience. Resilient organizations should do everything they can to avoid this kind of arrogance and bullheadedness (Schulman, 1993). However, the resilient organizations are seen as hopeful systems as the hope is essence of those organizations. They believe in the organization's capabilities to use knowledge effectively to cope with the unexpected events (Groopman, 2004), while emotions enable to detect weak signals when they are still emerging (Klein, 2002). Those organizations developed this feature more by recognizing and handling those weak signals as valuable even when it means to stop production to prevent a potential error (Hollnagel, et al, 2006). As mentioned above, group resilience is not the sum of individual resilience but it's more about complementing individual resiliencies that determine the group resilience. Experiential 13 diversity and shared belief in mutual capabilities to achieve the desired outcome is what is needed for the groups within the organization. Teams and groups consisted of people with broad range of experiences may be better at combining existing knowledge, skills, and abilities because action and cognition are linked (Weick, et al, 1999; Tsoukas & Knudsen, 2003). Moreover, teams focused on acquiring new skills and mastering novel situations are more likely to cope with challenging conditions easily and exhibit better performance over the long term (Wood & Bandura, 1989). The individual's perceptions and beliefs in their collective efficacy affect they input for the group endeavour and also determine how long the group persist in the situations when collective efforts fail to present quick outcomes (Wood & Bandura, 1989). That's because efficacy influences a group's vulnerability as well. Organizational resilience aims to enhance couple of processes inside the organization, such as the ability to learn and to learn from mistakes, the capability of restoring efficacy via quickly process feedback and movement of knowledge, and creating and possessing resources that are available to cope with events in the moment as they arise (Schulman, 1993; Barling & Cooper, 2008). Organizational resilience level derives from processes that intensify and increase mindfulness and the capability in the new ways based on mindfulness and conceptual slack. Mindfulness advance the ability of organization to recognize and properly respond to unexpected and potentially threatening events before they escalate out of control (Weick, et al., 1999). Conceptual slack is the variety in the analytical perspective combined with the willingness to question the current situation by the members of the organization (Weick, 1993). Conceptual slack could be also described as empowerment for the new solutions to emerge. 14 2 High Reliability Organization 2.1 Definition and roots of High Reliability Organization The theory of the High Reliability Organization (HRO) was developed at the University of California, Berkeley in 1980s by research group of Todd LaPorte, Gene Rochlin, and Karlene Roberts. They examined, for instance, aircraft carriers, the fire incident command system, and nuclear power operations. The Federal Aviation Administrative's Air Traffic Control systems is considered to be the first HRO with its development and research lasting for almost a whole century (O'Neil & Kriz, 2013). The initial of HRO theory was to make an organization stronger. Roberts (1990) proposed HROs as a subset of hazardous organizations that have enjoyed a record of high safety over long periods of time while maintaining consistent performance. Subsequently, Roberts made up question for its identification; "how many times could this organization have failed resulting in catastrophic consequences that it did not?" If the answer is on the order of tens of thousands of times the organization is "high reliability" (Roberts, 1990). In other words, HROs operate in complex, high-risk domains for serious accidents or catastrophic failures that can endanger multiple constituents or simply the costs of failures are extremely high (Hales & Chakravorty, 2016). The concept of high reliability is closely connected to health care, due to its complexity of operations and the risk, errors of which may incur severe losses and lead even to dead of people. That is one of the reason why it's not only important but as well as interesting to examine the HRO concept of proper management to mitigate or fully avoid such events. However, researchers have put more emphasize on the dynamic nature of producing reliability. While possessing the ability of the organization to interact in the real time with uncertainty or threats as proactive (anticipation) and reactive (feedback) processes are vital parts of HRO, those organizations put more importance on constantly seeking for improvement of reliability by both anticipating and preventing possible errors and failures and dealing quickly with errors in their earlier stages (Weick, et al, 1999; Schulman, 1993; Roberts, 1990; Rochlin, 1993). Therefore, HROs are defined as reliability-seeking rather than reliability-achieving organizations. Effective management of both hazard and probability is what distinguish reliability-seeking organizations, not their absolute errors or accident rate (Rochlin, 1993). As the result, high reliability has come to mean that (1) high risk and high effectiveness can coexist; (2) some organizations perform better under the very trying conditions, (3) and that it takes intensive effort to do so. Weick pointed out that other researchers were focused too much on the unique structural features of HROs while he noticed that these organisations also think and act differently and has reconceptualised HROs as the "mindful" organisations (Weick & Sutcliffe, 2001). They are also known for processes such as knowledge creation that helps maintain their hazardous nature (Farjoun, 2010; Leveson, et al, 2009), because they realise the clue to understand reliability and what makes organization more reliable is to understand how to create new knowledge while facing danger (Milosevic, etal, 2015). In another words, HROs are common to teach their people to anticipate, recognize and respond to a variety of problems and encourage and empower them to act fast and in the best way (Roberts & Bea, 2001). That is a main reason of having fewer accidents than non-HROs as they manage unexpected events better, which by definition can't be planned and prepared for. Reliability takes an important point of view. Reliability is the ability of any organization or system to control or mitigate error that affects an output. Most of the organizations, unlike the HROs, seek success, performance and take reliability as organization operation or outcome of the organizational invariance rather than prioritization of safety, careful attention to design and 15 procedures, a limited degree of trial-and-error learning, programme and technological redundancy, decentralized decision-making, continuous training often through simulation, use of specialized personnel, internal overlap, use of structural resiliency and strong cultures that create a broad vigilance for and responsiveness to potential accidents (Weick, et al, 1999; Roberts & Bea, 2001; LaPorte & Consolini, 1991; Roberts, 1990; Perrow, 1999; Rochlin, etal, 1987; La Porte, 1994; Sagan, 1993). A slide difference in understanding reliability in HROs is between Marais and Weick. Weick (1999) and Schulman (2004) sees reliability as a result from a continuous management of fluctuations in job performance and human interactions while Marais (2004) sees reliability as a systems function. As Schulman (2004) says the essence of resilience is the hidden ability to maintain or regain a dynamically stable state, which allows it to continue operations in the presence of a continuous stress while Sutcliffe and Vogus (2003) adds that this ability provide even positive adjustments. Reliability is achieved by collective requisite variety which is higher when people trust each other (Weick, 1987). 2.2 Normal Accident Theory vs. High-Reliability Theory On the other hand, this theory has also its critics. For instance, it is difficult to think of any low reliability organisations (Marais, et al, 2004). There is plenty of organizations that could fail catastrophically on daily basis or the organization could undergo a major accident every day and still count as highly reliable. In order to avoid such as misunderstandings La Porte (1996) have also defined FIROs in a less precise way, as hazardous systems that produce "nearly accident free performance". Charles Perrow's Normal Accident Theory (NAT) goes against HRO theory. Perrow (1984) hypothesized that systems characterized by tight coupling and interactive complexity, regardless of the effectiveness of management, will inevitable suffer by accidents as they often can't be foreseen or prevented. In case of error or failure, Perrow (1999) suggests, that organization should rather (1) abandon systems where risks outweigh reasonable benefits, (2) make the system less risky despite significant effort if possible, and (3) enhance self-correction or self-organization within systems. Perrow's theory has been described by some theorists as pessimistic view in contrasts with the more optimistic view of the HRO theory that organizations can operate safely despite the hazards of complex systems. Despite his theory that all organizations would eventually suffer by accidents, Peerow points out that some organizations were remarkably good at avoiding them (Perrow, 1984). On the other hand, the HRO accepts that no organization can fully foresee all risks, but they are able to recognize those risks and even to stop them in time before the risks become tangible. Notwithstanding the huge differences between NAT and HRO theory, both of them share focus on the social and organizational safety. NAT is, in fact, the environment of HRO. Therefore, HROs can be defined as organizations which have fewer failures than expected (Roberts, 1990; Weick & Roberts, 1993; Perrow, 1984). 2.3 Characteristics of High Reliability Organizations Through the years, researchers revealed some key characteristics of HROs that limit the frequency and impact of accidents or failures. Those include managerial factors of communicating and sharing the big picture and adaptive forces as they are becoming a learning organization (Grabowski & Roberts, 1997). Those organizations talk the bigger picture of what they seeks to do, as well as they want everyone within the organization to communicate openly through all levels how they fit in the big picture (Roberts, 1990; Roberts & Bea, 2001). This creates and allows to develop "culture" of shared attitude toward the reliability that allows decisions to migrate even toward lower ranking members. They are also known for "trail-anderror" learning for future success and avoiding accidents, and most importantly, learning from 16 near misses that are not only used as a source of learning but as well as the information about the health of the system (Weick & Sutcliffe, 2001; Marais, et al, 2004). For instance, HROs even make failure actions again to know how to interrupt it (Sutcliffe, 2011). However, as no two accidents are exactly alike, the HROs actively seek to know what they don't know. The HROs train personnel to recognize and respond to abnormalities, empower them to act, pursue quick learning and make available all knowledge related to the problem to everyone and design redundancy in order to catch problems early and not to be immediately stopped when certain parts fail (Roberts & Bea, 2001; Dalen, et al, 2009). In other words, those organizations recognize costs of failures and benefits of reliability. Moreover, they expect their system and sub-systems to fail as the HROs know that people and system will sooner or later make mistakes and become vulnerable. Therefore, they are preparing for inevitable so that they can minimize the impact of failure. On the other hand, the HROs also have in common many characteristics with high-performing organizations such as highly trained-personnel and their continuous training, frequent evaluations and inspections and highly motivational and effective reward systems (Schulman, 2004). Another important characteristic of the HROs is process of knowledge creation. Not only does it allow organization to stable potential errors prior it happens but also built processes to recognize potential clues to failure (Milosevic, et al, 2015). On the other hand, knowledge creation process seems to be paradoxical. Weick (1969) says that HROs can both believe and doubt their past experience while Schulman (2004) claims that the past performance cannot determine the future safety. From this point of view, there is no safe organization, just reliability-seeking organizations (Milosevic, etal, 2015; Weick, et al, 1999; Schulman, 1993; Roberts, 1990) as was already stated before. It is also paradoxical in the way that people within the HROs must thrust in their current knowledge but, on the other hand, they have to challenge them as it may not be appropriate for a new event. HROs enact mechanisms of cognitive processes to accomplish reliability which are underdeveloped in non-HROs where people tend to focus on success and efficiency rather than failure and reliability (Weick, etal, 1999). HROs know what to do and what not to do (Milosevic, et al, 2015). Informational richness is highest when people work face-to-face and decrease when not (Weick, 1987). People within the HROs are elucidated that they can never fully achieve full knowledge (LaPorte & Consolini, 1991). HROs "seek an ideal of perfection but never expect to achieve it. They demand complete safety but never expect it. They dread surprise but always anticipate it. They deliver reliability but never take it for granted. They live by the book but are unwilling to die by it" (Weick, et al, 1999). 2.4 Mindfulness As stated before, Weick and Sutcliff (2001) found out not only do the HROs have a unique structure but think and act differently. HROs' policy is to use mindful organizing for both the unexpected as well as the expected events. Mindfulness is a flexible state of mind in which we are actively engaged in the present, continually evaluate the environment, noticing new things even the smallest details, and sensitive to the context (Weick & Putnam, 2006), opposed to the decision-making systems where a simple assessment or data analysis leads toward the decision for a plan and continue no further. Mindful question is not what decision to make but what meaning is appropriate so we can figure out what decision we need to make (Weick, 1987). Mindfulness in the HROs is a persistent mindset that accept possibility of imperfection of knowledge. People act less mindfully when they rely on past categories (Weick & Putnam, 2006). Not only leaders but other organizational members need to pay more attention to shaping 17 the social and relational infrastructure of the organization for mindful organizing (Weick, etal, 1999). Mindful conceptualizing can improve coordination (Weick & Roberts, 1993), reduce the likelihood and severity of organizational accidents (Weick, et al, 1999), produce creative solutions (Langer, 2005), heighten adaptation (Vogus & and Welbourne, 2003), and reduce stress (Davidson, etal, 2003). Mindfulness improves the ability to act on chaos and unexpected threats before they escalate out of control, Sutcliffe (2011) called that the mindful action, and both increases the comprehension of complexity and loosens tight coupling (Weick, et al, 1999). Mindfulness involves interpretive work directed at the weak signals (Vaughan, 1986; Weick, 2009), differentiation of received wisdom, and refraining, all of which can enlarge what is known about what was noticed. Langer (1989) argues that mindfulness has three characteristics: active differentiation and refinement of existing distinctions, creation of new discrete categories out of the continuous streams of events that flow through activities and a more nuanced appreciation of context and of alternative ways to deal with it. Essence of avoiding significant failures has developed mindfulness within the HROs and they exhibit a few common features (Weick, 2001). As HROs are aware of imperfection of their system and knowledge, they continuously work on anticipation of events, meaning they try to figure out what should come (Weick, 1979). Not only does anticipation refers to the prediction but to prevention of undesirable or unexpected events and potential dangers before the damage is done, as well. It makes it even harder to anticipate as the events can take three different forms: when expected event fail to occur, when the event that was not expected occur and simply when the unthinkable event happens (Weick & Sutcliffe, 2007). As they acknowledge their own imperfection they are implementing policy of containment referring to the capacity to cope with unanticipated or unexpected dangers after they have become tangible, learning to bounce back (Weick, et al, 1999). HROs manage the unexpected through five processes: (1) preoccupation with failures rather than successes, (2) reluctance to simplify interpretations, (3) sensitivity to operations, (4) commitment to resilience, and (5) deference to expertise. Together these five principle form a collective state of mindfulness (Weick & Sutcliffe, 2001). The HRO principles aid to build and sustain healthy safety cultures. Expectations and routine can create blind spots and initial of unexpected events and become unmanageable (Weick, 1995), while anticipation and containment help the organization to maintain resilience via mindful organizing (Weick & Sutcliffe, 2007). High reliability is grounded in efforts to organize in ways that enhance people's alertness and awareness across the organization to details and call for responding that are processes of collective mindfulness which are indicated by 5 HRO principles (Weick, et al., 1999). This principals and mindfulness provides insight into how High-Reliability Organizations work and achieve their reliability. In fact, they are not high-reliability organizations, rather organizations that do high-reliability organizing (Weick & Sutcliffe, 2007). Three element of anticipations: 1) Preoccupation with failure 2) Reluctance to simplify 3) Sensitivity to operations Two elements of containment: 4) Commitment to resilience 18 5) Deference to expertise Figure 2 Mindful infrastructure for high reliability PROCESSES Prsaccupaton ywilh Faiure * Reluctance to Simplify Interpretations ^^^^^Sv. CapaHiHy to Discover Senahwily la Operations Wiidh*ie33 — — R e l i a b i l i t y ^ ^ ^ ^ Manage Une(*ectEd ^ - ^ ^ Eyents Commilmem to Resilience - " ^ Urpderapecifcstion of Structures Source: Weick, Karl E., Sutcliffe, Kathleen M. & Obstfeld, David (1999) Organizing for high reliability: Processes of collective mindfulness. 2.4.1 Preoccupation with failure Everyone within the organization is aware of and thinking about the potential for failure. People hunt for lapses and errors, even small ones, knowing it may be the precursors to larger failures, and report problems in the early phases, while they are small and do no harm, which requires certain level of trust. People need to be sensitive to early signs of errors and failure, and do not underestimate them (Weick & Sutcliffe, 2007). All personnel within the FIRO are constantly questioning the status quo, whether things are different, if they miss something or if there is a need to make adjustments as they understand that the new threats and errors emerge regularly from situations no one thought about before. Therefore, FIROs have developed systems for reporting near misses, process disturbances and small failures. Near misses, as well as all errors, disturbances and failures, are viewed here as opportunities to learn about systems issues and potential improvements (Weick & Sutcliffe, 2007; Hines, etal, 2008; Chassin & Loeb, 2013; Rochlin, 1999). On the other hand, critics have argued that warning signals are simply viewed as background noise, and are only obvious in retrospect, until they're disclosed by an accident or failure of the system as it is often not possible to recognize their magnitude in advance (Perrow, 1982). To respond to weak signals with a weak response has become the overwhelming tendency. Mindfulness maintain the capability to see the significance of weak signals and to give strong responses (Weick & Sutcliffe, 2001), therefore, mindfulness can be seen as direct impulse at weak signals (Weick, etal, 1999). 2.4.2 Reluctance to simplify Weick and Sutcliffe (2001) state that simplifications increase the likelihood of eventual surprise. Therefore, FIRO encourages people to look further into the events, not to rely on given information but to have critical view toward a received wisdom, to reject simple approaches and do not explain problems, instead they conduct root cause analysis. Labels and cliches can stop one from looking further into the events. Ground for this principal is that all humans are fallible and that scepticism improve reliability (Weick, et al, 1999). People in HRO resist simplifying because they understand their work is complex and dynamic (Weick & Sutcliffe, 2007). They simplify less and try to see as much as possible. 19 In pursue to notice more, HROs employ more people to double check on claims. Cost cutting organisations treat such people as redundant and see redundancy is the enemy of efficiency. On the other hand, redundancy is vital in the HRO for the collection and interpretation of information. Many researchers and literature say a lot about redundancy. It's defined as the ability to provide backup in operations for the execution of a task if the primary unit fails or falters (La Porte, 1996; LaPorte & Consolini, 1991; Marais, etal., 2004). Although redundancy is the most common method to improve reliability not just in the HROs but also in the nonHROs, too, the problem to choose between good and bad redundancies is hard to solve (Sagan, 1994). Awareness of other redundant units can decrease system's reliability as it leads unit to shirk off because it is assumed that someone else will take care of the problem (Sagan, 1994). Marais (2004) argues that redundancy encourages risk taking. Weick (1987) presents examples when trainings may lead to accidents not to reliability. Designed redundancy in organizational structures can provide the slack needed for the system itself to mitigate levels of risk, as redundancy may provide the needed buffer as fuzzy organizational roles and responsibilities are clarified (Grabowski & Roberts, 1997). 2.4.3 Sensitivity to operations People in the HROs strive to maintain a high awareness of operational conditions, mainly because they are able to understand operational complexity of the organization that is commonly referred to "the big picture" or "situation awareness" (Khorsandi & Aven, 2013; Weick & Sutcliffe, 2007). Hales (2016) talks about the sixth HRO aspect of "fast, accurate, and robust information systems" but in the fact it's just that organization successfully builds the big picture. HRO perceive a context of the current state, and that means that people understande what is going on around them and how their work might be related to the safety of the organization (Weick & Sutcliffe, 2007). Moreover, they put great effort to recognize the implications of the present situation for the future. Not only should the front line operators be highly informed about operations and possibilities how operations can fail and how to recover them again, but managers must be sensitive to operation, too. Especially, by encouraging their employees to report on their experiences and situations. The organization can't develop the big picture of operations if people refuse to speak up so system knows less than it needs to know to remain effective. HROs are attentive to the front line, where the real work gets done (Weick & Sutcliffe, 2007). 2.4.4 Commitment to resilience The basic characteristic of the HRO is not that it is error-free, but that errors and crisis don't disable the organization. A commitment to resilience is, in fact, a commitment to learn from errors, not to avoid error altogether, and eventually to implement it through fast feedback system (Wildavsky, 1991). HROs are not disabled by those events, instead they mobilise themselves in special ways to be able to deal with them while they even improve functioning of the organization. Moreover, it's the ability to recover or bounce back from untoward events, to learn from mistakes, to quickly process feedback and flexibly rearrange or transfer knowledge and resources to deal with situations as they arise (Sutcliffe & Vogus, 2003). Weick and Sutcliffe (2007) warn that the commitment to resilience is not easy to maintain because you have to keep learning without knowing beforehand, neither don't know what you will be learning nor how you'll use it. To sustain or not to reduce your adaptability while making adjustments is the biggest challenge. People in HROs are aware of the system's possibility for failure, therefore, they foster ability to identify potential safety threats as soon as possible so 20 they can either respond prior to the safety problems cause damage or mitigate the seriousness of the undesirable event (Weick & Sutcliffe, 2007). 2.4.5 Deference to expertise People in HROs understand that the most knowledgeable people about the work are actually the front line operators, lower ranking members of the organization and those are the people that possess the greatest knowledge of the crisis or emergency situation, not the people with the highest rank or status. Therefore, deference to expertise refers to the ability of the organization to change the chain command structure from authority to subordinates with expertise when it's necessary. That means that the front line operation knowledge of the system and situation is considered as more relevant in the crisis situations than expertise of experts not involved in the production process (Weick & Sutcliffe, 2007). HROs create structure of both centralized and decentralized organization at the same time as error-shift is an important concept to identify errors and control both frequency and magnitude within the system as soon as possible which could help to sustain a high level of safety performance (O'Neil & Krane, 2011). Hierarchical rank is subordinated to expertise and experience. It is tough to solve issue of autonomy and interdependence but it is important as a chain is only as strong as its weakest link (Grabowski & Roberts, 1997). Researchers have noticed that very high tempo of operation leads to "migrate" decisions to the people with the greatest expertise or knowledge about the event. Typical example of this can be found in patterns in flight operations on aircraft carriers (Marais, et al, 2004; O'Neil & Krane, 2011). Deference to expertise results is de-emphasis on hierarchy and puts emphasis on learning as much as possible about potential safety threats. Everyone in the HRO is expected to share concerns, therefore, all members should feel comfortable to speak up about potential safety problems (Weick & Sutcliffe, 2007). In fact, this create information flows throughout the organization so people in lateral positions receive information faster than they would get it by the flow of chain of command, and therefore, authority for taking the decision migrate to the places where decision needs to be done more quickly. 21 3 Resilience Engineering 3.1 Introduction to Resilience Engineering Businesses and organizations are threatened not only by diverse dynamics of their surrounding and environment as they need to adapt to it, but by variability within their own systems as they need to manage it perpetually. Moreover, another threat comes from so called complex risks which is the result of growth of organizational systems, as they are becoming even more complex and are being even more dependent on the other systems and organizations. As a result, when those complex systems fail and mishaps occur, tendency was to ascribe the failure to human error, but on the other hand, researches from early 1980s on how complex systems had failed showed that people actually benefit to system's safely through their ability to adapt to unplanned situations and changes (Hollnagel, etal., 2006; Leveson, 2002). In pursue to create safely practices that are sufficient to cope with these issues, Hollangel, in response to the cause-and-effect principle (the idea that accidents must have a cause), developed the concept of cognitive systems engineering. General idea is that we cannot understand what goes wrong if we do not know what goes right, that if we want to understand how failure happens, firstly, we have to understand how success is obtained, in fact, how people learn and adapt for safety of the systems in a world fraught with hazards and multiple goals (Cook, et al, 2000). Systems are expected to have internal as well as external variability as performance is never stable. Therefore, to study what goes right, the organizations should study what makes the system work when performance variability is in the norm (Hollnagel, 2016). Resilience Engineering (RE) is a proactive approach. It does not rely only on the calculations of failure probabilities or on learning from failures as conventional risk management approaches do (Woods, 2003; Conrow, 2003), rather it looks for ways to create processes that are robust yet flexible while they actively try to enhance the ability at all levels of the organizations to monitor risks and organizational decision making, and to use resources proactively in the face of disruptions or ongoing production and economic pressures (Leveson, 2002; Hollnagel, 2004; Woods, 2006). RE does not consider failures as a breakdown or malfunction of a normal system. On the other hand, success is defined as the ability of individuals, groups, and organizations to "create foresight", monitor, and anticipate changing risk profile prior to the failures happen and cause harm as well as the ability of a complex sociotechnical system to recognize and adapt to those unexpected changes or absorb them (Madni, etal., 2009; Hollnagel, etal, 2006). Accordingly, failure is seen as the temporary or permanent absence of this ability to adequately adapt to perturbations or to cope with real world complexity as a result of web of ongoing interactions and adaptations with given finite resources and time (Hollnagel, etal, 2006; Madni, et al, 2002; Westrum, 2006). Resilience engineering is design methodology and construction of systems with the capacity of resilience (Fairbanks, et al., 2014) that is defines as "the intrinsic ability of a system to adjust its functioning prior to, during, or following changes and disturbances, so that it can sustain required operations under both expected and unexpected conditions" (Hollnagel, et al, 2006; Hollnagel, et al, 2011). This definition clearly emphasizes the ability to continue functioning, rather than simply to react and recover from expected as well as unexpected. Therefore, individuals and organizations must always adapt their behaviour and responses, and adjust their performance to the current conditions (Senge, etal, 1999; Madni, etal, 2002), and because of the finite time and cognitive and physiological resources such adaptations cannot be expected to be optimal, it's inevitable that such adjustments are approximate (Madni, et al, 2009). 22 Both Resilience Engineering and High Reliability Organisation concepts are closely related approaches on risk management with novel vision. Not only tries RE to manage those complex risks and unforeseen situations by creating more adaptive organizations and processes to maintain their essential mission but may also strengthen systems continuity by putting safety management processes and the core business together, working hand-in-hand. Moreover, RE accept variance and deviations from normal as a normal dynamic phenomenon and not as danger as most of the other safety theories do. Like HRO, the concept of Resilience Engineering is most relevant in contexts that are complex or chaotic. 3.2 The abilities of Resilience Engineering Resilient organization is expected to possess the ability to survive and recover from the unexpected perturbations, disruptions, and operational environment degradations and that cannot be engineered simply by introducing more procedures, safeguards, and barriers. Instead adding another concept to the existing vocabulary of resilience, Resilience Engineering propose a completely new vocabulary. Resilience Engineering is a paradigm for safety that focuses on how to help organizations to cope with complexity under pressure to achieve success (Hollnagel, et ah, 2006). However, in a today's world of uncertainty, and the finite time and resources, safety isn't property the organization possess, rather it is a characteristic of system's performance created through proactive resilient processes and shows itself only by the events that do not happen. Therefore, RE requires a continuous monitoring of system performance and the ability to create foresight to be able to cope with complexity and maintain control in the face of ongoing disruptions in both the short-term and the long-term view (Hollnagel, et ah, 2006; Woods, 2005). Thus, RE must address these principles to develop capabilities at all levels of the organisation to have the ability to monitor, anticipate, learn, and response (Madni, et ah, 2009; Hollnagel, et ah, 2006). Even though those four basic abilities are cornerstone for resilience they must be seen together rather than separately, because RE looks at how the organisation functions as a whole (Hollnagel, etah, 2006). 3.2.1 The ability to monitor The ability to monitor consist of monitoring organizational decision-making to assess the risk and intervene in face of variation and challenges. Organization knows what to look for that could seriously affect the organizational performance in the short-term. However, it's essential to monitor not only its own performance but the environment, as well. Complexity makes unpredictable variations even more likely to occur as it's consider as a normal. Therefore, it's vital to continuously improve the ability to 'recognize early warnings' or 'precursors' of threats (Hollnagel, etah, 2006) that closely corresponds with the first principle of HRO (Preoccupation with failures). This requires organizational mindfulness that recognize importance of those unforeseen and often ambiguous variations (Weick & Sutcliffe, 2007). Monitoring may detect a developing situation in time before consequences are too serious and the organization may response before the event happens. On the other hand, it's extremely difficult to justify the intervention prior to the event, even though it's more difficult to intervene after the situations affect the organization and become more complicated and costly. 3.2.2 The ability to anticipate The ability to anticipate looks for developments further into the future, as organization knows what to expect and gets ready for long-term threats and opportunities, or changing operating conditions. Anticipation is about determining how the environment is expected to change and 23 what actions to take in the present to promote the future (Madni, et al, 2009). In fact, it's the ability to manage something before it happens by analysing the environment and preparing for changes such as regulations, customer demand, and so on, therefore, the organization create situation awareness and bigger picture as the third principle of HRO says (Sensitivity to operations). It takes certain amount of risk to anticipate, because acting prior to the event happens may be wasting of the effort, and therefore, wrong. On the other hand, acting after the even happens may require a larger, and usually more ineffective, response (Hollnagel, etal, 2006). Not only is knowledge just experience but also the ability to go beyond experience and to expect more than just the obvious, and not simply accept given as fixed (the second principle of HRO, Reluctance to simplify). So called requisite imagination inevitably colours organization's anticipation and preparation which is a sine qua non for resilience (Westrum, 1991; Adamski & Westrum, 2003). 3.2.3 The ability to respond The ability to respond'is the ability of socio-technical systems to take immediate actions against function variability, to know what to do and how to respond to both regular and irregular conditions, changes, and disturbances in effective ways (Hollnagel, etal, 2006). This requires prepared actions ready to be activated, or simply by adjusting current mode of functioning to the new circumstances and the ability to use available capacity and resources (Madni, et al, 2009). Systems need to be prepare for responding to unforeseen situations to reduce or prevent threat, because failure to do so may lead to the death of the system. Reacting to the events require the abilities to anticipate, to monitor, and to respond. Anticipation is required to react prior to the event, while monitoring determines what kind of reaction or intervention is needed, and responding is necessary to implement the reaction. Moreover, with the unforeseen variance comes lack of time to consult those disturbances with a higher manager or an expert. Therefore, this ability requires that the first-line operators to be empowered to take action and influence the process while adequate real-time information and technical means are available to them at the time of disturbances, too (Hollnagel, et al, 2006). This exactly match the fifth principle of HRO (Deference to expertise). 3.2.4 The ability to learn The ability to learn is the ability to learn from good as well as from bad consequences. Organization should know what has happened and why as those events may occur again in the future and should be able to learn from experience from past events. Education and training programmes are important tools of the organization so work can be more productive and safe, as well. This direct the system to monitor the proper signs, signals, and symbols as they know what to look for as well as it leads to the adjustments and the modification of responses based on the experience. In fact, every unforeseen situations that occur implies new experiences and the system can learn from what has already happened. Errors resulted from the dealing with complexities of hazardous processes, near misses, misunderstandings, or overconfidence in the safety systems are inevitable part of businesses that serve as great learning opportunities, however, it's also important to learn from successes, not only from failure. Learning requires an organizational environment that encourages the reporting of incidents, near misses, disturbances, and so on (Wreathall, 2006). This is essential part of learning as all available knowledge of the operations, environment, and funcioning of the organization is shared. By accepting organizational own imperfection and showing eagerness and willingness to learn, the 24 organization commits to the resilience based on the fourth principle of HRO (Commitment to resilience). 25 4 Research Methodology The aim of this thesis is to find out and determine behavioural patterns and skills of the specific organization increasing organizational resilience and managing unexpected events as well as to identify those patterns and skills on the individual, group and organizational level of resilience. Therefore, a set of research questions were made. The questions are based on the literature review on two closely related theories on resilience. Research Question no. 1: Is the ability to monitor built within the organization? Research Question no. 2: Is the ability to anticipate built within the organization? Research Question no. 3: Is the ability to respond built within the organization? Research Question no. 4: Is the ability to learn built within the organization? 4.1 Research Subject The research was conducted in the Mochovce Nuclear Power Plant (NPP) in Slovakia. The Mochovce NPP was chosen because the NPP is one of the most typical example of HRO (alongside health care and aviation). Pursuant to the Act No. 541/2004, "nuclear safety shall mean technical conditions and capability of the nuclear installation of transport equipment, as well as capability of their operating staff to prevent uncontrolled release of radioactive substances or ionizing radiation to the working or natural environment and the ability to prevent events and to mitigate consequences of events in nuclear installations or during transport of radioactive materials", defined by the Nuclear Regulatory Authority of the Slovak Republic. Nuclear power plants have a firm place in the global energy mix and their role is increasing with the reduction of fossil fuel reserves. Nuclear power plants emit no greenhouse gas into the atmosphere. In this way, the NPPs annually contribute to C02 emission reduction by 800 million tonnes worldwide and by 15 million tonnes in Slovakia. Without nuclear-generated electricity, emissions in the E U would increase by two-thirds. The nuclear power plants are the pillar of the Slovak power industry, supplying over 50 % of electricity to the grid and contributing to international commitment of Slovakia in reducing the greenhouse gas emissions. The Unit 1 of the Mochovce NPP have supplied electricity to the grid since the summer of 1998, the Unit 2 since late 1999. The completion and construction of the Unit 1 and 2 involved top West-European companies in addition to the Slovak, Czech and Russian industry. Moreover, extensive safety design programmes were involved in the construction as well as the international evaluations of The World Association of Nuclear Operators, International Atomic Energy Agency, and more confirmed high safety level of the reactors in Slovakia. Construction of Units 3 and 4 is in the final stage and the reactors shall be introduced into operation at the end of 2018 or 2019 respectively. Design modifications of the Mochovce units have passed through a design evolution and were approved by the Nuclear Regulatory Authority of the Slovak Republic as well as by the international experts, too. The upgraded plant design meets or even exceeds current international nuclear safety standards. Moreover, independent international Safety Board of six leading international nuclear safety experts has reviewed the design, as well. 4.2 Methodology Given the nature of the information needed, the semi-structured interviews with the open questions was used in a qualitative research as a primary source (Czarniawska, 2014) as it 26 provides opportunity to respond to given situation, opinions and answers of the respondents as well as to respond to the new ideas that derive from the interview (Merriam, 2009; Buchanan & Bryman, 2009; Easterby-Smith, etal., 2015). Additional source included internal documents, historical books and annual reports of Mochovce NPP, such as Annual Operation and Safety Reports of the Mochovce Nuclear Power Plant and reports of the General overhauls, teaching materials, presentations and leaflets of Slovak Power Plants and Enel Group, and the annual Reports on activity of Nuclear Regulatory Authority of Slovak Republic and Safety of Nuclear Installations in Slovak Republic. These documents were used as a secondary source. A formal interviews with the general manager of the Mochovce NPP and the NPP primary circuit start-up specialist were conducted within a one month period. Therefore, different educational and occupational background was secured. The interview with the general manager of the Mochovce NPP was structured into four parts and the whole interview was audiorecorded for the purpose of gathering all relevant and important information for this thesis. Each part was oriented on one of the ability that was proposed by the research questions the resilient organization should possess. The semi-structured interview took up to 2 hours and the questions were tailored to the needs of the thesis, see Appendix 1: Questions for Interview. The questions were based on the Holistic Safety Sample Questions presented by Hollnagel (2013). Afterwards, series of sessions with the NPP primary circuit start-up specialist were scheduled two times a week for a period of four weeks. The semi-structured interviews were conducted during the first three sessions. A couple of sessions were used to discuss the annual reports and teaching materials of the Mochovce NPP. Final three sessions were to discuss other relevant details and problems as well as the final version of the analysis. Each of the meeting took between 90 and 150 minutes in length. 27 5 Findings 5.1 The ability to monitor Over the years, as the technology has evolved, the process has evolved, too. In the past, employees created their own procedures and guidelines based on what they thought was the best and correct to do. In the energetics and power engineering, it has become globally accepted that it's necessary to standardize these processes so the new regulations were made. In fact, it was something like "to do list" or "check list". It's sequence of operations what to do and what to check, set in numerical order and employees simply follow those steps and tick those steps as they are done in correct order. Especially, after the Chernobyl disaster, it was put more emphasis on these regulations as they were not followed in Chernobyl that resulted in the disaster. Therefore, the most serious problem was that employees of Chernobyl were going the wrong way even without knowing they were going the wrong way. Each and every technology has its own parameters and a designer of the technology that sets it to function in a specific way also sets the possible deviation of the parameters from normal. As there is tens of thousands different parameters and data to monitor and check non-stop, it is physically impossible for human being to do so. Therefore, all the technology is monitored by an automatic control system that inform workers about deviation from normal or errors with the visual light signalization, and moreover, if the deviation is too big, not only light signalization is used but warning by horn is used too, to emphasize the urgency of the situation even more. It goes still more and more toward the IT sector that most of the operations is actually software. Each parameters are recorded individually, for instance, once per shift, hour, day or week. Moreover, each technology and its parameters are regularly being tested, so time schedulefor tests is made to verify whether all the machines and systems work correctly. Each and every component from the NPP is regularly and intentionally simulated with the given deviation to find out how the system works in the disruptions and simulates the correct procedures how to correct the errors, too. For example, back-up diesel engines are running once in a while as an alternative to energy while the nuclear reactor is switched off. 5.2 The ability to anticipate Slovak Power Plants have a highly hierarchical structure. Each and every employee and manager knows their rights and obligations on their work position and to whom there are functionally superior and subordinate. The hierarchical structure is built from very beginning by training and selection procedure. The employees are not chosen randomly and training of the future employee may last from one month to even one year. The time varies depending on the work position, of course. After undergoing the training programme, so called internship follows, where the future new employee is assigned to other experienced and older employee to watch the current employee doing the job. The future new employee is, in fact, without the right of manipulation and is making a picture how will help increase group resilience as the future new employee and can observe the how people rely on each other. Just after the training and the internship, the future new employee has to pass exams of operating rules to show knowledge and capabilities what to do. The new employee may start work in the NPP just after passing those exams. The training of cadres is properly sophisticated as it should be clear to everyone in the NPP what they can afford to do and what they cannot. It would end up catastrophically otherwise. Moreover, all people accepted for work in the NPP must undergo personality and psychological tests to show capabilities of creating situational awareness. Therefore, all the employees are aware what to do, so in fact, people working within the group 28 rely on each other to do their work as is supposed to. All those steps are to ensure that every employee foster group resilience while testing resilience of each individual employee and how they fit to the entity. The situational awareness is also supported by regular trainings, for instance, employees directly involved in production process must pass State Examination that consist of tests and oral examination of theory, Physics problems to solve and simulator, plus every employee has to go on the simulator at least 2 times a year (depends on the rank; higher the rank, more often to do the simulator a year). Constant improvement of the individual resilience is vital for resilience organization as the NPP is. The Mochovce NPP prepare for the future problems by analysing and preparing of all components and technology. The organization is constantly testing all of it, moreover, even every software has to be tested regularly, as the NPP depends on its reliability. Every provider and designer of security system must provide documentation of testing, while every security system has two redundancy to make it 100% mutually interchangeable and fungible. A tripleredundancy design means that each plant's safety system is actually replicated into three redundant, independent and fully-separated subsystems, each of them being fully capable of performing the required safety function. All redundancies are regularly tested by switching off one of the system and putting the other ones into the try out mode, to test its own processes and functions. In every moment, it's clear which one of the redundancy systems is superior to the others, while it is always possible to set which of those system is the superior one. All of those systems are prepared and tested to be ready at will and capable to cope with the events to foster resilience on the organizational level. Therefore, actual preparation for future problems is via the simulation and analysing of the reports, accidents, deviations from normal, disruptions, and near misses, too. The power plant has a full scope simulator able to reproduce plant performance and behaviour for effective training. Near misses are important part of processes within the NPP. All of those near misses are evaluated and made example of to train and prepare other employees what to do and how to act when the event repeats again in the future. Limits and conditions of NPP operation is the basic document for the operation of nuclear installations approved by The Nuclear Regulatory Authority of the Slovak Republic that provide records of all the components and technologies and their importance as well as the amount of the time they are allowed to be out of the service. For instance, for repairs or maintenance, that the system would work correctly and appropriate even without them, thanks to the triple-redundancy design and other safety systems. Every violations against the limits and conditions is relatively serious error and is reported to The Nuclear Regulatory Authority of the Slovak Republic or event to hiternational Atomic Energy Agency in Vienna. One of the goal of the simulations is also to find the roots of the problem. One thing is to solve problems, which is usually done by the automatic control system, but more important for the NPPs is to find the roots of the problems and remove the problem. Therefore, there is a group of the specialists, such as the daily specialists that speculate, search and debate about the possible roots of all the problems. This is done by continuous training programmes and regularly repeated simulations. It's up to daily specialists to evaluate and respond to the processes and how they are tested and updated. Just after the discovery of the roots, the specialists can remove it while reconsidering all the risks. Right after the Fukushima accident, stress tests were conducted to analyse extraordinary external events, such as earthquakes, floods, and impacts of other events that might result in the loss of the NPP safety functions and systems. The stress tests revealed no deficiencies requiring immediate action. 29 5.3 The ability to respond Standard in the power engineering is that the automatic control systems respond first while employees as human factor know what the system is supposed to do in case of disruption or deviation. Especially, in the first moments of disruption events, there is too many sound warning and signalizations that risk of human error is relatively large. Therefore, the processes are set up in the automatic control system so when disruption or deviation event occurs, the system is supposed to run automatically. The system signalize abnormal state of the components or technology before it respond, just to inform operators about the situation, followed by the signalization of all actions while rebounding from the deviation till the situation is returned to the normal state. All processes of the system work on the trend of continuous starts. In case that the automatic control system fail to correct disruption or deviation, employees interfere into the process and replace the automatic control system. Employees are educated and trained for recognizing when those automatic control systems fail to run the process as well as the systems warn employees that the automatic control system did not run. It is important to create list of possible or potential future events, such as potential incidents and accidents, with the set of prepared responses to correct those abnormalities and disruptions. In the Mochovce NPP, it's called the emergency regulations. Groups of experienced employees that have already worked in the plant for many years made up scenarios and events that can happen and how to respond to them and what to do to correct them. Those group are formed from different operators, employees and managers so experiential diversity ensured to foster resilience on the group level. All of the made up scenarios and events are tested on the simulators in various situation that are not know to people who are running simulations as those situations are made up by other employees from different management level. Emergency exercises, such as simulation of complete evacuation, sirens in the towns, SMS to the mayors, and so on, are regularly repeated that also tests them for preparedness in case of real emergency. Purpose of the emergency regulation is that in the time of event, those regulations are read and people are answering on the questions from the emergency regulation that leads toward the solution. In fact, it works as a decision tree and employees goes by answering those questions. This is a frame for solving all the problems and errors in the NPP. In other words, the NPP does not really expect to occur something unthinkable of. They are preparing for unexpected by simulating all the technology in the various modes and situations, real or unreal, but they can't be prepare for the events nobody ever thought of or heard of. Example of Fukushima disaster says that they obeyed all the emergency regulations correctly, only problem was that the tsunami wave was 3 meters higher than what they were prepared for. This creates problem for all the NPPs, in fact, for all the technology. The problem to find balance between establishing an acceptable level of risk (for instance, preparing for huge tsunami wave that can happen once in 10 000 years) and economic costs. For instance, nuclear radiation is common in the NPP, however in some places and rooms the radiation may be bigger. Therefore, Mochovce NPP uses ALARA principle (As Low As Reasonably Achievable). This principle ensures that the radiation exposure inside and outside the power plant is As Low As Reasonably Achievable and well below the limits set by the legislation. Example of A L A R A is that workers are sent to those places with increased level of radiation exposure only for certain amount of time (for instance, one hour and not whole shift or day), because they know that during that period of time the amount of radiation exposure the workers suffer in the given time is acceptable and does not endanger employees' life. Each and every work procedure in the NPP has its level of 30 accepted and acceptable risk set by rate of risk and appropriateness of benefits of the technology. 5.4 The ability to learn It became extremely obvious just after the Three Mile Island accident that the system for employees to easily and confidently report deficiencies with plant or equipment is necessary. Worldwide philosophy that human being cannot be punished nor penalized for reporting its own fails, bugs or mistake, was accepted. As it may often be almost impossible to find out what's happened if the own mistake is denied or neglected, reporting of those bugs and errors is not penalized in the NPP. The NPP accept the common truth that to err is human, but on the other hand, denying, rejecting or even concealing the error is punishable. This is application to the process of so called Safety Culture that it's better to admit and confess the error or bug so the system can find out the source of the error and operational procedure shows what to do after the error of human factor. Sometimes, the rule safety first within the NPP organization feels that safety is more important than the work itself, because every employee is also father, husband, grandparent, and so on, and wants to come back home alive. Therefore, the plant offers several possibilities how to report discrepancy, uncertainties, bugs or mistakes such as circular, report books (both electronical and handbook), Non-Conformity Report (NCR), while Security Technicians always try to come up with various of methods of reporting, all of which are part of internal computer network. For instance, if an employee (no matter the rank or work position within the organization) sees some oil leak without knowing whether it is normal state or error, the employee reports this to NCR and doesn't try to repair it as the employee may not know either how to fix it or if the event is normal. It's up to daily specialists to evaluate all those reports and regularly check and watch all the automatic control system reports. The daily specialists examine all the reports with the relevant people, such as employees that are most experienced and know the most about the specific component or designers of the component or technology, evaluate them and make final statement of the report. At the end, the person who reported the bug or error receive the feedback about the given report with the statement. In case, the person think that the statement from the daily specialist is not sufficient enough or not clear to understand, they start communication with the daily specialist till the problem is solved and clarified. This feedback procedures foster resilience on the individual level as the individuals are better prepared and informed about the cases. In fact, the rule in case of fast automatic emergency reactor scram says that reactor cannot be switched on until the cause of the reactor scram is clarified and problem is solved. It is, sort of, the same principle as the aviation system used in the past, when the error was discovered on one of the plane, all other planes of the same model and type were ordered to land until the cause of the error was discovered and problem solved on all the planes, not only the first one. The same principle works in the power plants. The emergency committee makes statement if the cause is clarified enough or solved adequately. Moreover, the statement and the results are introduced to everyone within the organization via e-Learning to inform and notify them about the conditions of the events and the new measures can be taken after the event. This processes foster organizational learning and resilience on the organizational level. Therefore, the overall awareness of the employees is improved. Moreover, Shift supervisors and daily specialists can inform about the events also other institutions, such as Ministry of Health, town mayors or International Atomic Energy Agency (IAEA) in Vienna, based on seriousness and type of the event. 31 At the end, the biggest problem may be how to convince people to report all those bugs and errors. Shift supervisors and daily specialists try to come up with different type of motivational programmes how to motivate employees to report, such as meal vouchers. However, in the reality in the NPP, employees are chosen based on personality tests and psychological tests as well as they are systematically trained, therefore, they would be against themselves if they did not report the bugs and errors. The idea is: "What if I do not report this problem and I'll need that component later? Firstly, I want to survive. If I survive, others survive too. The same with Occupational Safety and Health (OSH) rules. I do not need to wear helmet but I want to come back home alive and healthy." Therefore, non-compliance of OSH rules is penalized. Firstly, a yellow card as warning, secondly, a red card that means dismissal. Moreover, the NPP creates opportunities for employees and managers to meet regularly and discuss the design of processes and maybe to find better ways to make work processes safer. Everyone must to take part in OSH training at least once a year, part of which is an open discussion. The problem may occur when the employees are not used or too shy to ask questions. That's the reason why all instructors and Security Technicians that lead the discussions are trained to be communicative enough to make people feel comfortable to take a part in the discussion. Those seasons are organized that top management level meets lower management level, usually on the national level, than it goes down the levels to the meeting within the plants where the plant management meets its employees. They call it the cascade. It's primarily created to provide everyone with the most appropriate feedbacks from the discussions. Besides that, IAEA in Vienna gathers all the reports, event information, near misses, and so on, from all the power plants based on the international agreement. Therefore, all the plants can learn from the events, not only the one plant. This way, all information are shared and knowledge is spread through all the power plants. Thus, Training Centre evaluates all the event and accidents that happened, even from different country or continent, makes presentation and creates and prepares for the discussion. 32 6 Discussion So what is the outcome of this thesis? Simply, the research proves that a chosen High-Reliability Organization has all the abilities (ability to monitor, to anticipate, to respond, and to learn) of Resilience Engineering theory built within the organization as expected. The result was highly expected because both theories are closely connected and provides insight on building resilience in very similar ways as already presented in the literature review as well as the Mochovce NPP operate in highly hazardous environment and it's necessary to possess all those abilities. As many researches before, like for instance, researches on Federal Aviation Administration by O'Neil and Krane (2011) and O'Neil and Kriz (2013) or researches on healthcare by Hines, et al. (2008) and Hales (2016), the research of this thesis highlights procedures, ways of learning and teaching systems within the organization, and so on, that foster organizational resilience. A real success would be if other organizations, like business organizations, would be able to apply those processes, patterns and skills into their operations and businesses so their organizational resilience would thrive in their own environment. First and foremost, a system for reporting should be created within the organizational internal network, while reporting of the problems should be easy, straightforward and people should be encouraged to do so. This way, all reports circulate through the organization so people within the organization, even from the furthest position, can actually see that is going on and can learn and be informed about those situations, similar to the NCR being part of internal network in Mochovce NPP. Next, a group of people should be selected who are the most skilled, informed, and versed in the organizational processes and operations. These groups should be tasked for creating a list of possible events, updating and continual testing these lists to be relevant. Moreover, the list of responses to those event should be prepared to be able to react to the events. The groups should also work with the reports from the internal network to evaluate relevancy for further learning from the reports, as daily specialists do in Mochovce NPP. At the end, as the organizations are becoming even more complex, it starts to be impossible for human being to check all the data from the organization, therefore, a system for continuous checking should be created while any deviation must be signalized to the employees. The automatic control system in Mochovce NPP is built in the organization to do so. Last but not least, redundancy of safety systems should not be depreciated by any organization as resilience is becoming bigger competitive advantage on a daily basis, therefore, any neglectful event can result in a loss. 6.1 Limitations Finally, this thesis has some limitations, as well. Firstly, it would be more effective for the organizations that want to find out the behavioural patterns and necessary skills for organizational resilience to demonstrate all the abilities on real case study of accident, however, the Mochovce NPP did not suffer any significant disruptions nor accidents. However, the limitations of the methodology may be the biggest problem of the thesis. Not only were the interviews conducted only with two persons, but only the limited documents and reports were provided (the publicly available ones). Neither a quantitative research was conducted to verify relevancy of the given information throughout the organization. 33 6.2 Further Research On the other hand, the thesis is focused on the HRO typology of organizations, which limits the results of the behavioural patterns and skills only on this type of organizations. Future empirical research should focus on behavioural patterns and skills increasing organizational resilience of the non-HRO. Therefore, some business organization that exhibits elements of the resilience should be the target for the further research on what patterns and skills increasing resilience those organizations possess and its comparison. Moreover, as both FIRO and RE theories were studied for decades and many researchers proved their relevancy to achieve resilience in a highly complex, risk and hazardous nature, it would be interested to see results of implementing the processes of those organizations from a risky environment as the FIROs are to the business organizations that are threatened in a different ways. 34 Conclusion The intension of this thesis was to analyse the chosen resilient organization and identify the behavioural patterns and skills of organization that increase organizational resilience. In the beginning of the thesis, it was clarified how a resilience is defined, how can we recognize resilience in the real world, and how is a resilience created within the organization on different levels. Afterwards, literature review on two of the theories on the organizational resilience was presented, as High Reliability Organisations (HRO) and Resilience Engineering (RE) are two closely related concepts to achieve safely in the real world's conditions of complexity and chaos. For the empirical analysis, the Mochovce Nuclear Power Plant as the HRO was chosen and the set of the research questions was created based on the abilities of RE. For the purpose of this thesis and its goal, the semi-structured interviews with the general manager of the Mochovce NPP and the NPP primary circuit start-up specialist were conducted. Empirical analysis of the Mochovce NPP confirms each of the research question suggested by the theory of HRO and RE. The analysis provides evidences that all of the abilities (the ability to monitor, to anticipate, to respond, and to learn) are built within the organization and shows how the individual, group and organizational resilience within the organization foster overall organizational resilience. This research contributes to the literature and organizations looking for ways how to foster resilience by demonstrating and highlighting behavioural patterns and organizational skills increasing organizational resilience. This thesis also connects two big theories on the organizational resilience. 35 References BS 65000:2014. Guidance on organizational resilience. London: British Standard, 2014. ADAMSKI, A. & WESTRUM, R. The Fine Art of Anticipating What Might Go Wrong. In: Handbook of Cognitive Task Design. Mahwah, NJ: Lawrence Erlbaum Associates, 2003, pp. 193-220. BARLING, J. & COOPER, C. L. eds. The SAGE handbook of organizational behavior. London: SAGE, 2008. ISBN 10: 1412923859. BOIN, A. & V A N EETEN, M . J. G. The Resilient Organization. Public Management Review, 2013, 15(3), pp. 429-445. BONANNO, G. A. Loss, Trauma, and Human Resilience. American Psychologist, 2004, 59(1), p. 20-28. BUCHANAN, D. A. & B R Y M A N , A. eds. The SAGE handbook of organizational research methods. Los Angeles: SAGE, 2009. ISBN 10: 1446200647. CONROW, E. H. Effective Risk Management: Some Keys to Success. 2nd ed. Reston, V A : American Institute of Aeronautics and Astronautics (AIAA), 2003. ISBN 10: 1563475812. COOK, R. I., RENDER, M . & WOODS, D. D. Gaps in the continuity of care and progress on patient safety. BMJ, 2000, 7237(320), p. 791-794. CZARNIAWSKA, B., ed. Social science research : from field to desk. Los Angeles: SAGE, 2014. ISBN 10: 1446293947. DALEN, B. V , SLAGMOLEN, B. & TAEN, R. Mindful Organizing: How to Manage Unexpected Events and Unwanted Processes (Apollo 13). Nijmegen: Apollo 13, 2009. ISBN 10:9081385720 DAVIDSON, R. et al. Alterations in brain and immune function produced by mindfulness meditation. Psychosom Medicine, 2003, 65(4), pp. 564-570. DENNEY, D. Living in Dangerous Times: Fear, Insecurity, Risk and Social Policy. Social Policy & Administration, 2008, 42(6), pp. 557-559. EASTERBY-SMITH, M., THORPE, R. & JACKSON, P. Management and business research. 5th ed. London: Sage, 2015. ISBN 10: 144629658X. EVERLY JR., G. S. Building a Resilient Organizational Culture. Harvard Business Review, 2011. FAIRBANKS, R. J. etal. Resilience and resilience engineering in health care. Jt Comm J Qual PatientSafi 2014, 40(8), pp. 376-383. FARJOUN, M . BEYOND DUALISM: STABILITY AND CHANGE AS A DUALITY. Academy of Management Review, 2010, 35(2), pp. 202-225. GRABOWSI, M . & ROBERTS, K. Risk Mitigation in Large-Scale Systems: Lessons from High Reliability Organizations. California Management Review, 1997, 39(4), pp. 152-161. GROOPMAN, J. The anatomy of hope: How people prevail in the face of illness. New York: Random House: New York, 2005. ISBN 10: 0375757759. 36 GROTBERG, E. H. The International Resilience Project Findings from the Research and the Effectiveness of Interventions. In: B. BAIN & I. C. o. P. A. Convention, eds. Psychology and education in the 21st century : proceedings of the 54th annual Convention International Council of Psychologists, Banff, Alberta, Canada, July 24-28, 1996. Edmonton, Canada: ICPress, 1997. pp. 118-128. HALES, D. N . & CHAKRAVOTRY, S. S. Creating high reliability organizations using mindfulness. Journal of Business Research, 2016, 69(8), pp. 2873-2881. HAMEL, G. & JUREK, V. Na čem dnes záleží : jak vyhrát ve světě neustálých změn, dravé konkurence a nezastavitelné inovace. Praha: PeopleComm, 2013. ISBN 13: 9788090489066. HAMEL, G. & VALIKANGAS, L. The Guest for Resilience. Harvard Business Review, 2003, 81(9), pp. 52-63. HILLS ON, D. The Risk Management Handbook: A Practical Guide to Managing the Multiple Dimensions of Risk. s.LKogan Page, 2016. ISBN 10: 0749478829. HINES, S. et al. Becoming a High Reliability Organization: Operational Advice for Hospital Leaders. Rockville, MD: Agency for Healthcare Research and Quality, 2008. ISSN: 1520- 9229. HOLLNAGEL, E. Barriers and Accident Prevention. Aldershot, UK: Ashgate, 2004. ISBN 10: 0754643018. HOLLNAGEL, E. Resilience engineering Building a Culture of Resilience. s.l.:s.n, 2013. HOLLNAGEL, E. Resilience Engineering: A New Understanding of Safety. J Ergon Soc Korea, 2016, 35(3), pp. 185-191. HOLLNAGEL, E., PARIES, J., WOODS, D. D. & WREATHALL, J. Resilience engineering in practice: A guidebook. Farnham, UK: Ashgate, 2011. ISBN 10: 1409410358. HOLLNAGEL, E., WOODS, D. D. & LEVENSON, N. Resilience Engineering: Concepts and Precepts. Aldershot, England: Ashgate, 2006. ISBN 10: 0754649040. HOPKINS, A., 2007. WP 51 - Theproblem of defining high reliability organisations. Canberra: National Research Centre for OHS Regulation. CHASSIN, M. R. & LOEB, J. M . High-reliability health care: getting there from here. Milbank Quarterly, 2013, 91(3), p. 459-490. Khorsandi, J. & AVEN, T. A risk perspective supporting organizational efforts for achieving high reliability. Journal of Risk Research, 2013, 17(7), pp. 871-887. KLEIN, R. J. T. Climate Change Vulnerability Assessments: An Evolution of Conceptual Thinking. Climatic Change, 2002, 75(3), p. 301-329. L A PORTE, T. R. A Strawman Speaks Up: Comments on The Limits of Safety. Journal of Contingencies and Crisis Management, 1994, 2(4), p. 207-211. L A PORTE, T. R. High Reliability Organisations: Unlikely, Demanding and at Risk. Journal of Contingencies and Crisis Management, 1996, 4(2), pp. 60-71. 37 L A PORTE, T. R. & Consolini, P. M . Working in Practice but Not in Theory: Theoretical Challenges of "High-Reliability Organizations". Journal of Public Administration Research and Theory, 1991, 1(1), pp. 19-48. LANGER, E. J. Minding matters: The consequences of mindlessness-mindfulness. In: L. Berkowitz, ed. Advances in experimental social psychology. San Diego: Academic Press, 1989. pp. 137-173. LANGER, E. J. On Becoming an Artist: Reinventing Yourself Through Mindful Creativity. New York: Ballantine: Ballantine Books, 2006. ISBN 10: 0345456300. LENGNICK-HALL, C. A., BECKB, T. E. & LENGNICK-HALL, M . L. Developing a capacity for organizational resilience through strategic human resource management. Human Resource Management Review, 2011, 21(3), pp. 243-255. LEVENSON, N . G. A New Approach to System Safety Engineering. Cambridge, M A : Aeronautics and Astronautics Massachusetts Institute of Technology, 2002. LEVENSON, N . G , DULAC, N., MARAIS, K. & CARROLL, J. Moving Beyond Normal Accidents and High Reliability Organizations: A Systems Approach to Safely in Complex Systems. Organization Studies, 2009, 30(2-3), pp. 227-249. LUTHANS, F. The need for and meaning of positive organizational behavior. Journal of Organizational Behavior, 2002, 23(6), p. 695-706. MADNI, A. M., JACKSON, S. & IEEE, F. Towards a Conceptual Framework for Resilience Engineering. IEEE Systems Journal, 2009, 3(2), pp. 181-192. MADNI, A. M., SALASIN, J. & MADNI, C. C. 5.4.1 ProACT™: Process-aware Zero Latency System for Distributed, Collaborative Enterprises. INCOSE International Symposium, 2002, 12(1), p. 783-790. M A L L A K , L. Putting Organizational Resilience to Work. Industrial Management, 1998, 40(6), pp. 8-14. MARAIS, K , DULAC, N . & LEVENSON, N . Beyond normal accidents and high reliability organizations: the need for an alternative approach to safely in complex systems. MIT Eng. Syst. Symp. 2004. MASTEN, A. S. Ordinary magic: Resilience processes in development.. American Psychologist, 2001, 56(3), pp. 227-238. MASTEN, A. S. & REED, M . Resilience in development. In: C. Snyder & S. Lopez, eds. Handbook of Positive Psychology. New York: Oxford U Press, 2002. pp. 74-88. MERRIAM, B. S. Qualitative Research: A Guide to Design and Implementation. San Francisco: Jossey-Bass, 2009. ISBN 10: 0470283548. MILLER, D. The architecture of simplicity. Academy of Management Review, 1993, Volume 18, pp. 116-138. MILOSEVIC, I., BASS, A. E. & COMBS, G. The Paradox of Knowledge Creation in a HighReliability Organization: A Case Study. Journal of Management. 2015. 38 O'NEIL, P. D. & KRANE, D. Policy and Organizational Change in the Federal Aviation Administration: The Ontogenesis of a High-Reliability Organization. Public Administration Review, 2011, 72(1), pp. 98-111. O'NEIL, P. D. & KRIZ, K. A. Do High-Reliability Systems Have Lower Error Rates? Evidence from Commercial Aircraft Accidents. Public Administration Review, 2013, 73(4), pp. 601-612. PERROW, C. Accident at Three Mile Island: The Human Dimensions. In: D. Sils, C. Wolf & V. Shelanski, eds. The President's Commission and the Normal Accident. Boudler: Westview Press, 1982. PERROW, C. Normal Accidents: Living With High-Risk Technologies. Princton, New Jersey: Princeton University Press, 1984. ISBN 10: 046505143X. PERROW, C. Normal Accidents: Living With High-Risk Technologies. 2nd ed. Princeton, New Jersey: Princeton University Press, 1999. ISBN 10: 0691004129. POPPLEWELL, K., HARDING, J., RICARDO, C. & POLER ESCOTO, R. Enterprise Interoperability IV: Making the Internet of the Future for the Future of Enterprise. London: Springer London, 2010. ISBN 10: 1849962561. REASON, J. T. Managing the risks of organizational accidents. s.LAshgate, 1997. ISBN 10: 1840141050. ROBERTS, K. Some characteristics of high reliability organizations. Organization Science, 1990, 2(1), p. 160-176. ROBERTS, K. H. & BEA, R. Must accidents happen? Lessons from high-reliability. The Academy of Management Executive, 2001, 15(3), pp. 70-78. ROCHLIN, G. Defining "high reliability" organisations in practice: a taxonomic. In: K. Roberts, ed. New Challenges to Understanding Organisations. New York : Macmillan, 1993. pp. 11-32. ROCHLIN, G. I. Safe operation as a social construct. Journal Ergonomics, 1999, 42(11), pp. 1549-1560. ROCHLIN, G. I., L A PORTE, T. R. & ROBERTS, K. H. Self-designing high-reliability organisation: Aircraft carrier flight operations at sea. Naval War College Review, 1987, 40(4), pp. 76-91. SAGAN, S. D. Toward a Political Theory of Organizational Reliability. Journal of Contingencies and Crisis Management, 1994, 2(4), pp. 228-240. SAGAN, S. D. The Limits of Safety: Organizations, Accidents, and Nuclear Weapons. Princeton: Princeton University Press, 1995. ISBN 10: 0691021015. SENGE, P. & ROTH, G. The Dance of Change. New York: Doubleday Currency. 1999. ISBN 10:0385493223. SEVILLE, E. Resilience: Great Concept but What Does it Mean?. Wilmington, USA: Council on Competitiveness - Risk Intelligence and Resilience Workshop, 2008. SCHULMAN, P. The negotiated order of organizational reliability. Administration andSociety, 1993, 25(3), pp. 353-372. 39 SCHULMAN, P. High Reliability and the Management of Critical Infrastructures. Journal of Contingencies and Crisis Management, 2004, 12(1). SUTCLIFFE, K. M . High reliability organizations (HROs). Best Practice & Research Clinical Anaesthesiology, 2011, 25(2), pp. 133-144. SUTCLIFFE, K. M . & VOGUS, T. J. Organizing for Resilience. In: K. S. Cameron, ed. Positive organizational scholarship. San Francisco, CA: Berrett-Koehler Publ, 2003. pp. 94-110. TSOUKAS, H. & KNUDSEN, C. eds. The Oxford handbook of organization theory. Oxford: Oxford University Press, 2003. ISBN 10: 0199275254. U.S. DEPARTMENT, H. S. Quadrennial Homeland Security Review (QHSR) Report, Washington, DC: U.S. Department of Homeland Security, 2010. VAUGHAN, D. Uncoupling: Turning points in intimate relationship. New York: Oxford University Press, 1986. ISBN 10: 0195039106. VOGUS, T. J. & WELBOURNE, T. M . Structuring for high-reliability: HR practices and mindful processes in reliability-seeking organisations. Journal of Organizational Behavior, 2003, Volume 24, pp. 877-903. VOGUS, T. J. & SUTCLIFFE, K. M . Organizational Resilience: Towards a Theory and Research Agenda. Montreal, IEEE, 2007. WEICK, K. E. The social psychology of organizing. 2nd ed. New York: McGraw-Hill, 1979. ISBN 10: 0075548089. WEICK, K. E. Organizational culture as a cource of high reliability. California Management Review, 1987, 29(2), pp. 112-127. WEICK, K. E. The collapse of sensemaking in organizations: The Mann Gulch disaster. Administrative Science Quarterly, 1993, Volume 38, pp. 628-652. WEICK, K. E. Sensemaking in organizations. Thousand Oaks: SAGE Publications, 1995. ISBN 10: 080397177X. WEICK, K. E. Making sense of the organization. Maiden: Blackwell Publishing, 2001. ISBN 10: 0631223193. WEICK, K. E. Making sense of the organization. 2nd ed. Chichester: Wiley, 2009. ISBN 10: 0470742208. WEICK, K. E. & PUTMAN, T. Organizing for Mindfulness: Eastern Wisdom and Western Knowledge. Journal of Management Inquiry, 2006, 15(6), pp. 275-287. WEICK, K. E. & ROBERTS, K. H. Collective mind in organizations: Heedful interrelating on flight decks. Administrative Science Quarterly, 1993, 38(3), pp. 357-381. WEICK, K. E. & SUTCLIFFE, K. M . Managing the Unexpected: Assuring High Performance. San Francisco: Jossey-Bass, 2001. ISBN 10: 0787956279. WEICK, K. E. & SUTCLIFFE, K. M . Managing the Unexpected: Resilient Performance in an Age of Uncertainty. 2nd ed. San Francisco, CA: John Wiley & Sons, 2007. ISBN 10: 0787996491. 40 WEICK, K. E., SUTCLIFFE, K. M . & OBSTFELD, D. Organizing for high reliability: Processes of collective mindfulness. In: R. Sutton & B. Staw, eds. Research in Organizational Behavior. Stamford: JAI Press, 1999. pp. 81- 124. WESTRUM, R. Cultures with requisite imagination. In: Verification and validation in complex man-machine systems. New York: Springer, 1991. WESTRUM, R. A typology of Resilience Situations. In: Resilience Engineering: Concepts and Precepts. Aldershot, UK: Ashgate, 2006. WHITE, H. C. Identity and control : a structural theory of social action. Princeton, N.J.: Princeton University Press, 1992. ISBN 10: 069100398X. WILDA V SKY, A. B. Searching for Safety. New Brunswick: Transaction Books, 1991. WOOD, R. & BANDURA, A. Social cognitive theory of organizational management. Academy ofManagement Review, 1989, Volume 14, pp. 361-384. WOODS, D. D. Creating Foresight: How Resilience Engineering Can Transform NASA's Approach to Risk Decision Making. In: Testimony on the Future of NASA for Committee on Commerce, Science and Transportation. Washington, DC: U.S. Government Publishing Office, 2003. pp.76-84. WOODS, D. D. Creating foresight: lessons for enhancing resilience from Columbia. In: Organization at the Limit: Lessonsfrom the Columbia Disaster. Maiden, M A : Blackwell, 2005. pp. 289-308. WOODS, D. D. Essential characteristics of resilience. In: Resilience Engineering: Concepts andprecepts. Aldershot, UK: Ashgate, 2006. WREATHALL, J. Properties of resilient organizations: an initial view. In: E. Hollnagel, D. D. Woods & N. Leveson, eds. Resilience engineering: concepts andprecepts. London: Ashgate, 2006. pp. 258-268. 41 List of figures Figure 1 Diagram of a decision cycle known as the Boyd cycle, or the OODA loop Figure 2 Mindful infrastructure for high reliability 13 19 List of abbreviations B C M - Business Continuity Management HRO - High-Reliability Organization RE - Resilience Engineering NAT - Normal Accident Theory NPP - Nuclear Power Plant NCR - Non-Conformity report IAEA - International Atomic Energy Agency OSH - Occupational Safety and Health 42 List of appendices Appendix 1: Questions for Interview Appendices Appendix 1: Questions for Interview Monitoring 1. What systems are in place to create and revise monitoring indicators? What systems are in place to analyse or extract relevant information from these indicators? 2. What type of processes exist to enable an early recognition of deviations? 3. What systems are in place to assess whether the set of indicators of safety and security performance used are adequate and relevant? 4. How is information on precursors integrated in the management of the organisation? 5. What systems are in place to determine how, when and where processes are reviewed and updated as appropriate? Anticipation 1. What is the process for near miss reporting and how are those reports integrated into the process of safety? 2. What systems are in place to look into the future at potential safety and security related weaknesses and threats? Do these systems or people who make these forecasts have sufficient expertise, capability and resources to make accurate and relevant forecasts? 3. What systems are in place to ensure that forecast information is communicated to relevant parts of the organisation or institutions? 4. What systems are in place to develop and maintain staff skills and competencies to adequately anticipate future safety and security weaknesses and threats? 5. What systems are in place to ensure that employees are equipped with the knowledge and skills to be able to work effectively in a team? 6. What systems are in place to ensure that employees are equipped with the necessary knowledge, team-working skills and competencies, and skills for effective situation awareness? Respond 1. What systems are in place to ensure that human factors are considered before modifying or acquiring plant or equipment? 2. What systems are in place to develop or establish a list of possible or potential events (such as potential incidents and accidents) and corresponding prepared responses? 3. What systems are in place to ensure that the list of possible or potential events are relevant and that prepared responses are adequate? 4. What systems are in place to ensure the list of events and prepared responses are prepared, maintained and updated/revised where necessary or relevant? 5. What systems are in place to determine the criteria for responding to the events? What is the threshold when the response is activated and when the normal state is restored? 43 Learning 1. Are there systems in place for staff to easily and confidently report deficiencies with plant or equipment? What is the process for reporting safety related events in the organisation? 2. What systems are in place to ensure it is easy, straightforward and welcoming for employees to raise any issues with work processes or operational environment, or with potential or anticipated safety and security related weaknesses and threats? How are these employee contributions taken into account?? 3. Are there systems in place to ensure that these reports are adequately assessed and appropriately addressed? 4. What kind of recognition, if any, is given to employees that report abnormal conditions, concerns, actual or near miss events etc.? What systems are in place to encourage reporting of events and information relevant to learning? 5. What systems are in place to ensure the organisation learns from safety-related events? How does the organisation learn from incidents and accidents as well as near-misses or free-lessons? 6. What systems are in place for staff and managers to meet regularly and discuss the design of processes and find better ways to make work processes safer? 7. What systems are in place to determine which events are used for learning and which are not? What systems are in place to ensure information relevant to learning is permeated throughout the organisation and that the learning is a continuous, ongoing process? 8. What systems are in place to ensure the analysis of events derives relevant information that can be used for learning? How are the events analysed? 44