Business Continuity & IT Disaster Recovery Planning

By Linda Hanwacker, President & CEO, The LSH Group

content-image

Linda Hanwacker, President & CEO, The LSH Group

The LSH Group addresses the many facets of Continuity Planning for businesses by providing the best value & practices across diverse industries such as IT, healthcare, insurance, finance, government, public utilities, manufacturing, education, environmental health & safety, transportation, and retail.

Companies and organizations depend, more than ever on the availability of their Infor­mation Technology (IT) and critical business processes, data and applications that are IT-based. Business Continuity and IT Disaster Recovery(BC/DR) is the ability to for an organization to be resilient using strategies and plans for recovering and re­storing the organization’s technological infra-structure and capabilities after a serious disruption or disaster. The onset of cloud computing and the proliferation of wireless mobile devices have increased the risks Managing is to protect the company, their assets, and their ability to do business under any circumstance. Without ‘Plan’ organizations are exposed to substantial loss of operations, negative publicity, finan­cial losses, legal recourse, and loss of resources and people. Organizations that continually refine their ‘Plan’ are more likely to survive in the event of a disaster. Organizations that do not have a plan are on a course toward Disaster! Organi­zations that continually refine their ‘Plan’ are more likely to survive in the event of a disaster.

"Organizations that do not have a plan are on a course toward Disaster! Organizations that continually refine their ‘Plan’ are more likely to survive in the event of a disaster"

Today’s unpredictable world puts pressure on IT depart­ments to maintain business continuity in the face of many challenges that are natural and man-made such as natural disasters, network outages, cybercrime and security breach­es. Organizations need to understand the impacts of their business in the event of an emergency. They must be able to answer these critical questions: Who executes recovery ac­tions? What is needed to recover, resume, continue or restore IT systems and business functions? When must business functions and op­erations be resumed? Where will peo­ple go to resume corporate, business, and operational functions? How, in de­tail, will recovery, resumption, continu­ity, and restoration be accomplished? How will you prevent or mitigate How how will you prevent or mitigate the risks identified?

Key reasons for planning and implementation are to minimize in­frastructure disruptions, establish roles and responsibilities for when an event or disaster is declared, safe­guard important data and informa­tion, and know how to contact employ­ees, customers, suppliers, and other key personnel.

The main objectives for BC/DR Planning are 1) Keep the organization resilient by reducing the impact of service disruptions, events, or disas­ters 2) Establish recovery strategies to reduce the impact of operations being disrupted and 3) Educate the team about the recovery procedures and how to handle an event, disrup­tion, or disaster so everyone will know what to do.

There are three basic components that all plans and programs must have to be successful –
1. Assessment Component: This determines the functional require­ments by identifying all impacts and critical components, threats, and probability of occurring through a formal risk assessment and business impact analysis.
2. Planning Component: This defines the recovery strategy and information about recovery point objectives and recovery time objec­tives, develops the plan for all criti­cal systems and processes for a suc­cessful recovery effort and tests the plan for assurance of some level of recovery.
3. Monitor/Track Component: This as­sures that the plan will be updated and via­ble; it is an iterative process that monitors the current readiness of critical systems and processes.

There are many lessons that are learned from various indus­tries and different types of disasters. They tend to all have some impor­tant lessons that are learned when it comes to planning. Top ten lessons learned are:-

1)  For IT, utilize cloud service provid­ers who have their facilities located in multiple geographical areas other than where you are.
2)  Assume your company or or­ganization will be the last one that will be back in operation. When there are wide spread outages, ‘best ef­forts’ for recovering is the term frequently used.
3) Consider the safety and personal needs of your employees. Personal needs of employees take precedence when an event occurs, even when an employee is asked prior to an event. Plus, hos­pitals may not be available for those who are injured.
4) Have enough generating power and facilities to meet long-term needs. Iden­tifying your facility’s critical loads is im­portant. Understand the costs and risks associated with utility power interrup­tions, production losses and down time.
5) Plan for outages that may last a few hours to extended time of one to weeks or 30 days. While other back-up electri­cal supply alternatives may exist, they can often take longer to engage and have shorter supply capabilities, have higher costs, lower reliability or no reasonable refuelling options during an event.
6) Have an alternative source of food and water as well as a plan to get it. If an outage goes over several days, sup­plies will be used up and will need to be replenished.
7) Frequently test readiness. BC/ DR plans must be tested. If they are not tested, then it is like having no plan at all. It is important that these plans be exercised periodically to ensure they will operate as de­signed in the event of an emergency or a disaster.
8) Supply-Chain Management and Contract for reliable providers of resources that includes consider­ing alternate suppliers for products and services.
9) Communication before, dur­ing and after is important. It is how everyone will know what to expect, what to do, how to do it and when.
10) Documentation of all this information is the key and it be­ing readily available is critical for those who need to know.In general, and repeatedly, the lessons learned from major disruptions or disasters, is that communication is key.

The LSH Group has proven planning processes and best prac­tices that are designed to mini­mize exposure to loss and disrup­tion. We have extensive industry experience and are ready to as­sist organizations in all aspects of BC/DR planning.

Current Issue