Logo

Sunday, April 22, 2012

Business continuity: more than just disaster recovery


John Smith of Selway Moore Solutions explains that business continuity is more than providing a safety net to disasters




Business continuity and high availability are not just about providing a safety net against risk and disaster. Even though as a subject it has grown rapidly in importance, in many businesses it is pigeon-holed as something they might do 'in an ideal world' or as a discipline which is someway down the agenda because the perceived risk is not as powerful as other pressures they face.


What the vast majority are actually failing to see is the opportunity it presents to move a business forward. IT personnel tied up with day-to-day remedial activity because small faults can cause big problems could actually be spending their time helping the business to develop new products and services.

One of the 'problems' that companies have with spending money on business continuity preparation, technology or services is that it can seem like writing cheques for something they will never need.


With the exception of certain businesses that are bound by regulation and therefore must make provision to recover effectively from disaster, many companies weigh up their perception of overall risk against the cost, and opt for keeping their fingers crossed and spending the money on something else.

Ultimately, it's a question of priorities - as with any subject in business that potentially can involve significant financial outlay, spending on Business Continuity solutions has always had to stand up to close examination.


Given the situation where budgets are often competed for within organisations, it is easy to see why some businesses would opt for spending on IT projects with a more tangible and immediate revenue generation slant than something which may or may not swing into action depending upon circumstances.

But businesses need to ask themselves, and indeed to study, how much time, effort and money they spend dealing with what they might see as 'day-to-day' continuity issues - those that don't affect an entire infrastructure or last a long time, but occur relatively often.


Most companies seem to accept that it is a fact of life that systems experience glitches and short-term downtime and there will always be the need to allocate finance and resources to deal with this inevitability. Yet this is more a question of attitude, convention and habit rather than forward thinking.


Any business that can foresee circumstances where their infrastructure is resilient and flexible enough to free support and technical staff from remedial and ad hoc work should also be able to see the possibilities this opens up for positive technical development and innovation.

There are very few business tools whose millions of users would accept breakdowns with the same fatalism that we all seem to do with IT, but by bringing Business Continuity in is a mechanism for efficiency, by allowing those people with the technical skills to create rather than merely repair, a company can spend more time attending to its goals and targets.


Imagine an infrastructure, designed with resilience at its core which allows skilled technical people to work on product development, on customer service technology or sales tools - what Board wouldn't want their staff spending more time on these kinds of projects and less on repairs?

Business Continuity needs to be part of the foundation of any IT infrastructure - it's not just backup with bells and whistles anymore, and it certainly should not merely sit as an adjunct to corporate IT only to be used in case of emergency.


It can be specified as part of the overall approach to IT and be justified and measured as a legitimate and, in most cases, affordable use of budget.


Good Business Continuity practice does not automatically come with an expensive price tag attached, and insisting that technology lets us down less often than we have been conditioned to expect does not have to put a nought on the end of any budget.

Creating a situation where any given employee who relies on IT availability to do their job has most of the ad hoc downtime eliminated is an issue which can be addressed via Business Continuity techniques and technology. If they don't need as much technical support, then that unused resource can be re-allocated.
Companies should start viewing Business Continuity technology and practices as an opportunity rather than a diversion or an irrelevance. Yes it can and has proved invaluable in times of crisis, and will continue to do so, but for the majority of businesses out there it should now be finding a revised role as a part of their infrastructure specification and as a tool to help them move forward.

Monday, April 9, 2012

Basic Steps to your first Business Continuity Management


Managing a business can be challenging and exciting especially in Africa. Everyday comes different bringing in challenges from customers, the government, competition and the environment. Knowing this, there are some events you cannot plan for, or can you?

As businesses are now even more reliant on information technology, specialist plants and suppliers which, when they fail, cause disruption to the business. Even if not destroyed access to the business may be restricted by gas leak preventing normal business operations.

Some questions to ask your organization are:
·      What would we do if you lost access to your primary premises, plant and machinery through flood or fire?
·      How would we cope if your IT or telecommunication systems fail?
·      Where would we get alternative supplies if your key supplier closed up shop?
·      How would we cope with loss of key staff and high levels of absenteeism?

Disruption can happen anytime, how well you deal with the effects to your business may determine your future.

The introduction of Business Continuity Management (BCM) to your organization will help you prepare and mitigate against major disruptions your organization may face. BCM has been employed by large businesses around the world to enable them cope with major disruptions. The techniques employed can be scaled to any size business in any sector.

There are five steps to an effective BCM process:

Stage 1 – Understanding your Business

The first stage is to understand how and what you need to make your business work and who has an interest in how well you perform.

·      Do you know who your stakeholders are- these are those who have interest in the business?
o   These will include your customers, employees, sub contractors, suppliers, banks, investors, insurers and auditors
·      Why do you need to identify them?
o   At the time of a major disruption these stakeholders will want to know how soon you will be back in business and what the effect of your disruption will be on their operations and investments.
·      Do you know which of your activities are most critical and if you could not continue them for any reason what would have the greatest impact on your business?
o   The impact may not initially be financial; it may be your reputation that is damaged, which in turn could cause new business to be reduced.
·      Consider how soon the disruption will impact your business; some activities can have immediate effect. Knowing this will help you prioritize activities that need to be restored
·      Do you know what you need to undertake these activities?
o   Identify the people and skills involved, what computer, software and data you require
o   Are there key drawings and specification that you need access to?
o   What communication do you need, both fixed and mobile
·      Who are your key suppliers
o   A failure by supplier may have serious consequences for you, preventing you delivering to your customers. The customers will hold you responsible, not your supplier.

Stage 2 – Business Continuity Management strategies

The next stage is to determine how you will restore the critical activities. In the initial stage you will have identified what you need to get up running first and what resources you need. There are several choices that you can make at this point.

The activity may be seen as so important that you may decide to provide a duplicate to avoid the failure occurring, eg find a second supplier for that critical product; back-up critical data off site. Alternatively you may decide that you will provide a partial level of service, perhaps to your most important customers, within a specified timescale, restoring full service as and when you are able.
Finally you may decide to do nothing in the short term, waiting until full business recovery has been completed.
Any strategy must recognise the internal and external dependencies of the organisation and must have general acceptance by management functions involved.

Stage 3 - Developing and implementing a business continuity management response
Having decided what it is you need to restore and how soon you will do this, create the business continuity plans that will enable you to quickly recover what is critical to your business.
The business continuity plan is at the heart of the business continuity management process and sets out what is to be done, who will do it and how to contact them in an emergency, where you will work from if the normal business location is unavailable, key suppliers for the essential services you need and where the critical data is stored. The plan will also detail who should be informed about the disruption.
The structure, content and detail of the plan will depend on the nature of the organisation and the risk and environment in which it operates. In particularly large or complex organisations, it may be necessary to have departmental plans, of which you may integrate into one high-level plan.
Stage 4 - Building and embedding a business continuity management culture

Documenting the business continuity plan is one element of developing a business continuity management strategy. Its success, however, depends upon implementation of the recommendations made across the entire organisation; a programme of training for those directly involved in the execution of the plan; and an education and awareness programme to ensure understanding and adoption of the plan in relevant parts of the organisation - this applies to both staff and suppliers.
All stakeholders should be informed that you have introduced business continuity management and what to expect if your business suffers a disruption, as this may give you a competitive advantage over others and customers will have more confidence in your reliability. It may even pre-empt their own demands for you to install business continuity management as part of future contracts.
Stage 5 - Maintaining and auditing business continuity management

Business continuity management does not end when the plans are written. They must be tested to see if they will work when you really need them. It is too late to find out the errors and omissions when you have to use the plan in earnest. Plans must be kept up to date as the business structure, suppliers and customers may change, as may contact details for key employees.
Be prepared to deal with any disruption, whether large or small, public or private, that would prevent you from satisfying your customers needs. Considering a BCM plan? Talk to Artco solutions on enquiry@artcosolutions.com or visit us on www.artcosolution.com

SELLING BUSINESS CONTINUITY TO FINANCE DIRECTORS


Nick Sutton, operations consultant, with Automata Global Business Continuity Solutions, discusses how business continuity professionals can gain more budget allocation for their departments by highlighting the direct benefits of business continuity to their finance directors.


The profile of business continuity has never been higher. The increasing reliance of businesses on technology, coupled with the increased risk of terrorist attacks – as highlighted by the recent tragic events in London – has meant that businesses are increasingly likely to suffer significant disruptions.

Despite this, a common problem encountered by many business continuity managers is the difficulty of getting budget allocated to spend on business continuity. One recurring question is “How do I convince CFOs/financial director to loosen the purse-strings and spend budget on BCM?” While these senior finance figures may be able to accept the more general benefits of business continuity, there are a number of benefits which directly relate to their roles and responsibilities. Convincing financial directors that business continuity management will directly benefit them may be the most direct and successful way of getting budget allocated. Some of these direct benefits are shown further on in this article.

The benefits of business continuity
The general benefits of a good business continuity programme are well-known and numerous, but here is a brief summary of some of the major plus-points:

  • The planning that goes into the conception of a programme – including BIA and risk analysis – can often prove to be a valuable way of taking stock of an entire organisation’s processes. The enhanced understanding of an organisation afforded by a business continuity programme can lead to the enhancement and streamlining of processes and subsequent expenditure reductions. 
  • Disciplines involved in protecting organisations such as physical security, logical security, risk management, insurance etc can be given improved focus if they are conducted in conjunction with a business continuity management programme emphasising mission critical activities.
  • In many organisations rational structures may be overlooked when growth becomes the most important driver. A business continuity management programme can assist in rectifying this problem by mapping out the organisational structure. This assists in highlighting where bureaucratic and inefficient structures have developed.
  • The effective handling of a business continuity incident – particularly a large-scale one – can have a positive effect on a company’s market value. Successfully negotiating a potentially devastating incident can increase public confidence in an organisation. In the case of an industry-wide incident, a company may be judged against its competitors on how the incident is managed. By successfully handling a business continuity incident when its competitors fail a company may achieve stand-out in the market.
Specific benefits for financial directors 

Business continuity can provide a number of benefits to financial directors, some of which are less obvious than others. Most financial directors will have one eye on the rising costs associated with running a business, particularly as they become more dependent on increasingly complex and expensive IT infrastructures. One expense that can often spiral out of control is that associated with storage area networks (SANs) and the memory used by them. Garry Poole, CEO of Automata, has seen how BCM can help in this area: “One of the areas in which I have seen clients make the largest savings is in terms of their expenditure on IT storage. BCM specialists can help identify the critical storage needs of an organisation. IT departments are often working blind and need input from people who understand an organisation’s needs. This is where guidance from consultants has often proved to be invaluable, helping to focus IT budgets significantly.”



The introduction of the Sarbanes Oxley (SOX) Act as well as the Companies Bill (often considered the UK’s equivalent to Sarbanes Oxley: seehttp://www.dti.gov.uk/companiesbill/ ), has raised the profile of business continuity in the world of finance. SOX is primarily focused on ensuring the accuracy of financial data and the ability of an organisation to report that data correctly. Accuracy of data is of course inextricably linked to IT security and resilience and this is just one area in which business continuity can play an important part of an organisation’s strategy. The focus that BIA can give to IT strategy and expenditure - through its identification of needs, shortfalls and priorities -makes for an IT infrastructure that can be relied upon to produce accurate data. One theory well-known amongst business continuity specialists is the ‘Backlog Trap’. The after-effects of interruptions to normal work flows can result in severe backlogs, built up while attention is focused on dealing with the abnormal situation or during resultant system- downtime. The increased workload brought about by clearing this backlog can often lead to errors being made or shortcuts having to be taken, both of which can affect the accuracy of data. Business continuity programmes can ensure that system-downtime is kept to a minimum and will also put in place measures to ensure backlogs are minimised and are subsequently cleared effectively.

One provision of SOX is the requirement that companies must disclose to investors the various scenarios and contingent liabilities that have the potential to affect the value of their investment. In this regard business continuity becomes profoundly relevant since it identifies these potential threats to an organisation. Furthermore, a business continuity programme can also minimise (and in some cases entirely negate), the likelihood of these threats being realised. Given the choice between investing in an organisation with a sound business continuity programme or one without such a programme, one would clearly be reassured by the knowledge that the investment was being made in a company with some inbuilt resilience.

The scandals that have rocked the financial world either side of the Atlantic have further highlighted the importance of IT security in maintaining the integrity of accounting data and financial reports. It is always difficult to legislate for crimes committed from the inside, and detecting fraudulent behaviour, often by employees with vast knowledge of the particular systems, is even more troublesome. However, business continuity can provide some protection against this very real threat. By helping an organisation understand its normal work flows, processes and system dependencies the various practices common to business continuity can help an organisation detect unusual activity, assign correct authority and permissions to individual user accounts and put in place checks and balances to monitor usage. While this may not provide a foolproof defence it may be that earlier warning is given. The ultimate responsibility lies with the people who decide how to account for profits, losses etc, but a business continuity focused IT infrastructure can certainly help facilitate this accounting.

Tuesday, March 20, 2012

Business Continuity Management (BCM) Vs. Insurance


Business Continuity Management (BCM) Vs. Insurance

Insurance gives businesses the comfort of knowing that, in the event of loss or damage due to an insured peril, it will be able to replace or repair material items.  Additionally business interruption insurance gives cover, typically, for the shortfall in gross profits for a specified period following the incident.

However, no matter how effectively a business protects itself through insurance, there are always some risks that cannot be anticipated or insured against. For instance insurance can never provide cost- effective security against the long term or permanent loss of customers, market, quality, reputation and employee loyalty.

The only effective protection against serious disruption to your Business BCM.  BCM can be most simply described as “understanding and controlling risk and being best able to recover your business, regardless of the causes of interruption”. Insurance companies recognize the mutual benefit to be gained from BCM;
  • ·   BCM is seen by insurers as a means to improve the quality of the business they are underwriting and confirm that BCM helps organisations mitigate impact, recover faster and minimize losses.
  • ·      BCM can be used to protect against losses incurred through traditionally non-insurable such as Supplier insolvency or pandemic influenza
  • ·      BCM can be used to better understand the requirement for Business Interruption Cover


BCM plays a vital role, during negotiations most insurers will want to see clear evidence of the fact that the company seeking a business interruption over is managing its potential loss exposures effectively and taking the necessary mitigation steps.  This is where the BC Plan can play a valuable role in demonstrating that the organization has implemented measures to limit any possible risks. The underwriter will also expect to see evidence of processes in place to ensure that the business can return to full operation as quickly as possible after the event. 

Wednesday, March 7, 2012

DEVELOPING SEAMLESS BUSINESS CONTINUITY AND DISASTER RECOVERY PLANS by Dr. Jim Kennedy.


Introduction

The development of recovery times for both the business organization’s business continuity plan and the IT department’s disaster recovery plan need to be developed through the collaboration of both parties for either plan to provide the proper protection. However in my thirty-five years in the business continuity and resiliency field I have found in many situations they are not.
The reasons for this can be timing or a lack of knowledge of the overall business continuity and/or disaster recovery planning process coupled with a lack of understanding of each other’s real recovery timing needs.
The purpose of this article is to provide a framework in which the recovery time objectives (RTOs) for the business continuity and the disaster recovery plan can be developed together.


Reason for inconsistencies and failures

Generally the drivers for business continuity and disaster recovery planning are considered to be one and the same, but this is not always the case. Many times the very design process for IT infrastructure requires that the IT organization develop disaster recovery planning thoughts and plans early in the application and/or systems development process. So, early in the project’s timescale of the development of a new application or system, IT must have some understanding of what kind of recovery timing and recovery point timing will be needed to support the technology to be deployed. IT will try to obtain the RTO and RPO (recovery point objective) numbers, but the business is most often focused on insuring that the deployment of the new business process or function is rolled out on time and within budget. The business organization is not thinking about business continuity planning at this time. So, IT will take it on itself to develop a best guess of the required recovery times either based on conversations with the business organization or on its own, if the latter cannot or will not commit to a number.
In other cases that I have seen, there is a clear lack of knowledge about business continuity and disaster recovery planning. Each organization knows that they need either a business continuity or a disaster recovery plan but they are not trained in the overall steps in developing such plans. As such the business organization does not understand the risks, tradeoffs, and costs involved in developing a proper business continuity plan. The business organization also often does not understand that it needs to properly analyze the operation to better understand the recovery requirements during the process/systems/application development phase of the systems/process development life cycle or, as ITIL defines it, the application life cycle (ALC). The business organization needs to quantify the impacts of loss of that process or system; and may not be sure of the right questions to ask - not only in terms of loss of productivity, but in terms of costs to process manually in case of a system loss or failure. Can the organization develop and use manual processes at all if the system or IT infrastructure fails? Does the organization have the human resources to perform the necessary manual processes or will they need to bring in contingent workers and for how long and for what cost? Every business organization needs to clearly understand and to articulate their operation’s maximum tolerable period of disruption (MTPD).
MTPD is the maximum time an activity or resource can be unavailable before irreparable harm is caused to the organization. This applies to both customer-facing and internal activities. Note that the recovery time objective specifies the time by which an organization intends to recover an activity or resource: the maximum tolerable period of disruption is the upper bound on this time.

The business needs to utilize the MTPD to develop its processes and contingency processes, and the IT organization need to understand the MTPD to properly develop its technology and RTO which, in turn, will enable the business to achieve its RTO objectives.
At the same time, IT needs to utilize the recovery time numbers developed by the business organization as a basis for its system and infrastructure RTO values.
Standards and planning process
There are so many business continuity and disaster recovery standards to choose from, as well as other related standards of practice, that this might be the reason for all of the confusion. The fact that none of these standards really talk of integrating the business recovery and the IT technology recovery plans together in to the overall process or application development life cycle complicates the matter even further.

There is also the issue that business continuity and/or disaster recovery planning classes are usually only electives in business administration or computer technology/information systems curriculum. So we are not exactly preparing our next batch of business or technology leaders to properly understand the methods, or importance, of contingency planning.
All that being said, most of the standards that exist do have a pretty consistent set of predefined steps to be reasonably successful. So if we take all of the contingency planning steps and align them with the ITIL ALC phases the planning cycle will integrate system development with continuity planning together at the best possible time in the development process.
I will outline the steps below in developing business continuity and disaster recovery plans with their corresponding points within the ITIL application development life cycle:
STEPS IN BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNINGITIL APPLICATION LIFE CYCLE PHASES
1) Understand the Organization
a. Risk Assessment
b. Business Impact Assessment
            i. Determine MTPD for operation
           ii. Develop RTO for Critical Systems
           iii. Develop RPO for Critical Systems
Requirements – requirements gathered based on business needs of the organization
2) Evaluate and Determine Strategy
a. BC strategy to meet RTO/RPO
b. DR strategy to meet RTO/RPO
Design – requirements translated into specifications
3) Develop Plans
a. BCP – Business Organization
b. DRP –IT Organization
Build – Application and the operational model are made ready for deployment
4) Exercise PlanOperate -- IT operates the application as part of the business service
5) Audit and Maintain PlanOptimize

Using the standards and good practices
During the requirements gathering phase of the ITIL ALC the business owner should have also conducted the risk assessment and business impact analysis or BIA. The results of these two activities allow the business owner to clearly see the impact on the business of a failure or discontinuation of operations in either, or both, of the business or IT operations. They can then translate that knowledge from the risk assessment and business impact analysis into quantifiable RTO and RPO numbers to be used in the next phase of business continuity and disaster recovery planning (Evaluate and Determine Strategy) and the Design phase of the ITIL ALC.

The RTO and RPO numbers are used to develop alternative strategies that meet the recovery time and point needs. A cost for each alternative design is developed. The cost is the total of the IT cost to design, implement, build and operate; and the business cost for any workarounds or special handling during the outage period; plus costs to load any transactions processed during that outage period into the system (processing resynchronization) after they are brought back on-line and are processing again as before the incident.

The alternative strategies are then looked at using a cost and benefit (time, reduced workaround complexity, and etc.) analysis of each alternative. The best option will accomplish return to operation in a reasonable time with an acceptable cost to the business and IT. However, the alternative selected will require input from both IT and the business to properly address the risk of outage. The business will need to insure that it can perform the workarounds and still meet all of the business, regulatory and audit needs of the operation for the time period that the alternative defines the IT organization to need for restoring the IT systems needed to restart the application and its associated services.
For the plans to be effective and ‘fit for purpose’ it is very important that the business and IT are on the ‘same sheet of music’ as to recovery times and points. It is no good if the business has planned its resources and workarounds expecting a system recovery time of 24 hours only to find that the system will be down for 48 hours. On the other side of the coin it is not fiscally responsible to pay the cost to expedite the recovery time of an IT system to less than four hours if the business can tolerate an outage period of 24 hours or more at much less cost for the final IT solution.
Once it has been concluded that both plans are consistent with each other, the actual plans can be developed. While the business prepares for implementation of the new application and/or service, IT will make ready the systems and infrastructure needed to also meet the business schedule for implementation.


Exercising the plans
There is one caveat, however. Even if both sides have planned together and developed their plans based on a single and consistent recovery time, the two planning activities still need to verify (via exercising the plans together) that the IT recovery timing (the disaster recovery plan which includes hardware restoration, software restoration, synchronization of databases, and etc.) actually comes in on time to meet the business’ needs as provided for in the business continuity plan.
Only in testing and timing the two recovery processes to ensure that they are coincident can an organization truly be confident that the overall plans will be successful.

Social media can transform enterprise business continuity management


Social media can hold the key to transforming enterprise business continuity management, especially crisis/incident management and communications practices, according to Gartner.
Gartner analysts predict that, by 2015, 75 percent of organizations with business continuity management systems will have public social media services in their crisis communications strategies; and BCM professionals are advised to immediately begin assessing social media's opportunities and risks.

"Enterprises simply cannot afford to ignore social media as a crisis communications tool," said Andrew Walls, research vice president at Gartner. "In many cases, social media may represent the only available means of locating and contacting personnel; providing stakeholders with the information and assistance they need; informing citizens, customers and partners of product/service availability; and taking other business-critical actions following a disruptive event."
However, Mr. Walls said that effective use of a new communications channel requires forward planning and practice. Attempting to leverage social media for the first time during a crisis can cause more harm than good. Instead, he said that organizations must develop comprehensive social media strategies and tactics for crisis/incident management and integrate social media with the enterprise's established business continuity management processes.
The use of social media for user input and knowledge sharing can create a conflict for organizations when the sites are being used during a crisis by the workforce and others that are involved or watching the event unfold.

"As the workforce develops personal, digital friendships that might take precedence over the official spokesperson of the organization, a conflict over who is the authority during an event can emerge, leading to unanticipated and negative results if official procedures are not followed," said Roberta Witty, research vice president at Gartner. "Such usage shouldn't turn into a battle for control, but organizations must protect their reputations and the effectiveness of their communications during stressful times. Therefore, putting forth a social media management strategy as part of a business continuity management program is essential to ensure that the organization's crisis communications effectiveness is protected, and that response and recovery plans and procedures are followed."

Social media is very different, technically and culturally, from the tightly controlled technologies and means of communication that enterprises are accustomed to using and supporting (such as corporate email systems). The use of social media for collection and distribution of information can create serious challenges for enterprises:
  • Maintaining an authoritative and credible information source;
  • Enlisting active, effective participation of staff and the public that are active in social media;
  • Collecting, filtering, analyzing and applying information gathered from social platforms
"Organizations developing social media strategies and tactics for crisis/incident management must take these factors into account by establishing effective authorization processes, content guidelines, and monitoring and message retention capabilities," Ms. Witty said. "The bottom line is that no enterprise's business continuity management efforts can afford to ignore the opportunities and risks presented by social media. BCM and crisis management specialists should begin working now to integrate social media tools and practices into their BCM efforts."

Sunday, February 19, 2012

Africa’s internet use sees 2 000% growth

Growth of internet use in Africa has gone beyond that of the global average in the last decade, reaching 2000 percent growth, compared to 480 percent growth globally.

Internet in Africa has grown at an incredible speed (image: Patrick Hajzler)
This significant growth is partly as a result of the increased capacity provided by new ICT infrastructure on the continent, including improved fiber-optic connectivity and increased accessibility to computers and mobile phones.
Internet penetration on the continent remains lower than that of the developed world however. South Africa, Ghana and Egypt experienced the most growth, according to Frost & Sullivan ICT analyst Birgitta Cederstrom.
“With the new undersea cables and terrestrial fiber roll-out, as well as the satellite influx across Africa, we expect to see close to double-digits in terms of growth in the more mature markets over the next two to three years,” she said.
Data service prices in Africa are set to drop in the coming year as well. In the next two to three years, the use of data services is expected to grow by as much as 60 percent.
Sarah Sheffer