Tuesday, 24 May 2016

IX Business Continuity International Conference

by Jorge García Carnicero


As every year, BSI has been the promotor of the Business Continiuty International Conference, in its IX edition. The place that has been chosen this year was the Gran Melia Fénix Hotel, in Madrid, where the conference took place at first hour of the morning. In a room almost full, with 50 or 60 people, BSI shows that their ability for calling business continuity professional is healthy.

The first speech was driven by Jose Luis Miguel, Country Manager at BSI, that was exposing the BSI capabilities in both generating standards and auditing and in training. Then, he presented the results of the Horizon Scan Report 2016, led by the BCI and promoted by BSI, highlighting aspects such as the top ten threats of continuity, which can be seen in the image or the percentage of companies seeking to increase its budget business continuity for the coming months / years .


The second speech was done by Julio San Jose, from EY, in tandem with Cristina Pereira, continuity responsable at Abanca. Julio emphasize about the key aspects related with continuity:

  • Need of deploying tests and drills.
  • The importance of crisis communication.

He comment aspects as the different estrategias of communications that existe (in a good or a bad way): Silence, Negation, Responsability transference, Confession and controlled discretion, been Confession the best communication strategy.
(I would call it Transparency)

Cristina Pereira exposed the case of Abanca, commenting the different problems with which she has been to deal with when deploying the Business Continuity Plan in the organization. In the same direction than Julio’s speech, she also emphasized the importance of drills.

Before the break, took place the third speech carried out by Agustin Lopez, as representative of DRI in Spain. Agustin exposed the different contingency scenarios in the datacenter with an original presentation, using classical films as a thread (back to the future, Groundhog Day, etc)

When the Confee Break and Networking moment finish, we come back to the room, in which GMV was responsible for the fourth speech in the morning. It was based on the business continuity management system (ISO 22301) and the possibility of integration with other management systems standards, like security (27000), IT Management (20000), quality (9000), etc, with an orientation to certification.

The fifth speech was performed by Uxía Fernandez, from Grupo Ozona. Uxia expose the concept of IRBC (ICT Readiness for Business Continuity) that is used in the standard 27031. Uxia expose the content of the standard with the 5 mainstays as a elements to protect: Facilities, technology, people, data, providers and process. Since usually only technology and data was taken into account, Uxia would like to make special consideration about the other elements. It was a long speech.

Finally, the sixth speech was done by Ricardo Mesias, Risk Management Director at EDP. Ricardo made a speech showing the main problems that he had to deal with in developing the business continuity plan in EDP. He talk about the team, about achieve the complicity of all departments of the company, about the importance of test, about the metrics and about the external support, which is always important.

Conclusion

As a conclusion, I think that the role of BSI maintaining this event year after year is laudable and all the business continuity professional should be thankful about that. This event is a meeting point and is also a way to measure the state of the art of business continuity in spain.

However,  I think that messages has to be improve, since many of them are not showing the actual situation of customers. Recently I was reading an article of Amy DeMartine, senior analyst research in Forrester research for Devops, for Computer World that I think is applicable in Business Continuity. She said: “I think the reason why a lot of companies start with DevOps activities and forget the security staff is that there is a cultural gap. Security people speak a language almost different - incidents, vulnerabilities, risks - , so everybody put them at the end of the development life cycle”. This could be applicant also to business Continuity, that should be included in all the processes of the company but, however, it’s not, at least in Spain. If we focus on the management system and we forget that continuity should be practical it will drive us to see Business Continuity as a waste instead of an investment.  

Recently has took place the Business Continuity Awareness Week, led by the BCI, with a main objective: to show the ROI of the continuity and I think we should learn about int.
Although obviously, BIS as a promotor of the event has to focus speech on management systems, is urgent and essential to update the messages to a market reality different, mainly in the IT area.  It makes no sense to talk about take a tape out of the datacenter when all companies are talking about backup in the cloud, making a third copy in a public cloud, for example.

Saturday, 14 November 2015

Evaluating the Protocol for the prevention of pollution in Madrid.

by Jorge García Carnicero

Traffic restriction in Madrid because of high levels of pollution offers different analysis from a business continuity perspective, since the difficulties of employees to reach their workplaces (already driven in different posts in the past, like traffic jumps or snow storms, etc) to the supply problems that could impact to small  shops. 
However, I would like to focus on the measures and the response carried out by citizens to the restrictions imposed by the council.
 
From a general perspective, the problem could be summarized as the following: during the last week a powerful anticyclone has installed in the Iberian Peninsula which has bring a very stable situation from a climatological perspective, but that has led an grow of the concentration of nitrogen dioxide, NO2, which is a pollutant produced mainly in the fossil fuel combustion process, and cause serious health problems.

The Madrid Council has decided to try to reduce the pollution level activating the Protocol for the Prevention of Pollution in Madrid, which is a set of measures that has to be adopted during this scenarios the high level of pollution by nitrogen dioxide. 
Beyond the political analysis, which is probably debatable and subjective, I think it is worth analyzing the mentioned Protocol and the answer is having citizenship.
The Protocol is divided into 4 blocks:
  1. Introduction, in which is described the air pollution problem and their risks. 
  2. Zoning the city: in order to propone the correc measueres, there are defined 4 zones: M-30 interior, South-east, North-east, Northeast and Northwest.
  3. Actuation levels definition. There are three differents actuation levels, depending on the Nitrogen Dioxide concentration: Prenotice, Notice and Alert. Recollected data from the measures stations are used to do so. 
  4. Possible Scenarios: There are described different scenarios depending on the level of contamination and the time since citizens has been under this contamination level, going from Scenario 0 (informative), level 1, 2 and 3 (Notice or Prenotice) and reaching the highest level as an Alert Scenario. 
  5. Measures: Define the different measures that are going to be carried out in each scenario.  
  6. Activation and deactivation of levels. Activation and  deactivation criteria
  7. Description of operational activities: Identifies the Group which is responsible of the application of the Protocol as a group of coordination and implementation of the protocol. 
  8. Effective date.  Date in which the Protocol will ve effective (march the 1st 2016)
As it could be seen, the Protocol has a tipical squema of a Business Continuity Plan, except for a point which I personally consider highly important: Test. Perhaps if these tests were defined before the activation of the protocol and this test should be carried out there wouldn’t haapened such a lack of understanding and mistakes that has happened during today. 

Even so, activation of the protocol itself can be considered a test of coordination and citizen response to an exceptional scenario, because in this case the scenario is important, but not critical. It can be used as way to test the agility when transferring information to citizens, stablishing the response measures and evaluating the response of the compliance of proposed actions. 

In a permanent connected world, like today, in which citizens are continuously getting information about what happen, there are opportunities to define scenarios and response measures by big cities councils more ambitious than the ones defined by now. This is what should to be seen by governments in order to increase the resilience of cities and the services that are delivered to the citizens and the companies in which the citizens are working. 

Thursday, 8 October 2015

Transport Problems


By Jorge García Carnicero

This week there has been two events that should be attended by business continutiy managers in their continuity scenarios. There are the huge traffic jam that occurred in Madrid last Monday and the problem because of a sabotage in the rail singaling system in the  highspeed traing (AVE) between Madrid and Barcelona. Both events has had the same consecuence: lack of certain profiles in their work places, that could be in their usual work place or after traveling to other city.
Analyzing possible solutions for this problem, and assuming that  it’s not possible to foresee the problem before it happen, the best option is to establish the mechanism required to:
  1. Warn the employees that there has been a problem related with transport, which requires that the company must realize that there is a problem
  2. Establish the mechanism required in ordert the employees could work remotely, through teleworking/homeworking.

 Undoubtedly, to allow the employees to be warned there has to be established a supervision system by the company, which requires a 7x24 alert system. This system could be rolled out internally or could be outsourced, always taking into account the cost-benefit relation. It could be also interesting to be incorporated in the early alert system, in the security SOCs, for example.


From teleworking, are still valid the solutions described in my post Legionella, a real threat

Sunday, 30 March 2014

Dangers of poor crisis communication: a plane in the water?

There has been talking a lot in business continuity forums about crisis communication and about how social networks could help to broadcast information to our stakeholders in an easy way, but needless to say that it is always necessary to have some restraint in sending these communications and that the people who should be responsible for these activities should be sufficiently trained to give the right information to meet strictly our needs.



The case that has made up to develop this post in the blog is the fake alarm that took place last Thursday 27th of march, when the canary emergency service 112 (@112canarias), send the following tweet:

«Control Canarias confirma caída al mar de avión a 2 millas costa #GranCanaria a la altura de Jinamar. Se desconoce el número de pasajeros»
Canarias control comfirms that a plane has fallen into the sea, 2 miles from the #GranCanaria cost, in Jinamar. It's not identified the number of passengers.

Until this moment all activities were in within normal, with the activation information exchange protocol between the airport authorities and the emergency service. But with this communication, validating the visual evidence that were being received from different points, the event went to another dimension. Media around the world assume that the news were true since canary emergency services is suppose to be a reliable source. In fact, the Canary 112 service has one the emergencies twitter profiles with more followers, more than 53,000,

The story was not greater because the 112 service itself gave the lie to the news 9 minutes after:
 Respecto posible accidente avión, SAR, Control Aéreo y helicóptero #GES confirman que se trata de remolcador tirando de una embarcación
About the possible plane accident, SAR, aerial control and helicopter #GES confirms that is a tugboat.


However, the tweet had been resent ad retweeted a lot of times, suffering a major impact and opening the debate of whether social networks are an appropriate communication channel for crisis notifications . In many cases, reaching the demonization of social networks.


Some links to the news


Sunday, 16 March 2014

Jazztel and the Crisis Communication

By Daniel Blanco Real

Last Wednesday 12th of march Spanish telco company Jazztel suffered a outage on its mobile phone network, both data and voice, since 13:30 to 21:00 approximately. From a Business Continuity point of view, there could be a lot of different analysis, but with the information that has been brought we can not define if it could be a problem in the continuity plan of Jazztel or if the service was activated in the recovery time objective or how the outage affected to the enterprises and what kind of alternative services they activated. What we can do is to analyse the crisis communication plan.

The internal communication plan will be out of the scope of this article, although it will be very interesting to know what kind of strategy would be carried out by Jazztel to this kind of unavailability scenario. Each time that we talk about alert notification, we think on call to mobile phones of persons included in the plan. As interruption was in business hours, it’s easy to assume that the communication was made by internal communication systems, like landline or any media based on IP. But would be highly interesting to study other alternatives in the carrier’s case:

  • To have Dual SIM mobile phones, with a SIM of another carrier to carry out the crises communication (However this involves removing the vast majority of managers in Spain from crisis committees. I have still not seen any Iphone dual SIM)
  • Communicate to personal phones, if there are not Jazztel phones and assuming that the managers has two mobile phones (something as unusual as the iphone dual SIM).
  • Other kind of communications: landline, email (not too much reliable since there are not certainly received by the receptor), searh engines?

About the communications plan that carry out in the media and the users, could be analyse by information published in the news and social media, and also by customers itself.
Adslzone did a follow up of all notifications realized by Jazztel, and also of messages sent by Jazztel users to what they created a foro
The first messages sent during this kind of incidents is essential and must be clear, precise and use the best channels in order that all receivers will be reached in the fastest way.
Jazztel need three hours from the beginning of the outage to send the first official message at 16:15 and used its twitter account and its official blog to send the following message:
“We have an incident in our mobile phone service that affect to a big amount of our customers, not to all. The company is working on restablishing the service as soon as possible. We’ll keep you informed.”
Analysing what happen until the official Jazztell communication, we can realise:

Time until the first message
Three hours. Taken into account that since 13:30 there was a lot of topics in social media, it seems that it would be too much time to send such a short message and with very short information.

The selected media was twitter and the Jazztel official blog 
Is this the best way to communicate to their customers?
It could be yes or not, but is a good way to ensure that the message will reach all the national communications media that are following the social media in the big companies or IBEX35 companies and in this way, advice to the customers.
It’s also a way not to waste time organizing media rooms to deliver an official communication, apart from avoid, obviously, undesirably questions or questions not easily answerable in a moment in which there are a lot of details clearly identifies about what are carrying on.

Call Center
Apart from the official message, the customers calling the call center was informed through an answering machine indicating that there was an incident in the mobile phone service of voice and data, ant that Jazztell was working in recovering the service and tell the customer to call later to know if the incident was solved.

The Message
Both in the call center and in the social media there was no information about what had been the issue that could cause the problem, the estimated resolution time or the scope of the issue and number of customers affected.
There are a lot of factors that are not kwon and perhaps it would be better not to communicate certain issues as, form example, service restoration time, but the extent of the damage, if they knew, should be included. The message was launched trhee hours after the outage and it could be identified customers talking about their problems and located in different places, so it could be quickly identified that the problem was not a local incident but a national problem. This generate untrust about the capacity of Jazztel to solve the problem, the severity of the error that caused the problem and so the time that users are going to be without service (at the end the most important thing)

It took close to five hours to Jazztel since the first official message in deliver another message, at 20:07, in which they say that will compensate the users affected by the incident.
“We’re still working in reestablishing our mobile service as soon as possible and to solve the incident. Jazztell will compensate automatically to all customers affected by this incident without any kind of request by them.
Once the service will be reestablished, the company will contact immediately with all  the customers affected to keep them informed about the resolution."

The message
Although the message begins with a clear statement of intent to fix the problem as soon as possible, still no report on the fault that caused the problem, the approximate time resolution, or what the extent of the damage and the number of clients affected. This time the message focuses on talk of rewards to those affected, without really knowing applications without injury or damage caused in this way and try to mitigate as far as possible the damage ratio and confidence that is causing the incident.

At 22:00 the mobile phone service begins to recover, but is not until the next day when users recevies a SMS at about 11:00 or 12:00 askin

A las 22:00 horas se comienza a recuperar el servicio de telefonía móvil, pero no es hasta el día siguiente cuando los usuarios reciben un mensaje SMS sobre las 11:00 – 12:00 apologizing for the damage and report back to the next bill.

A communication plan should be well prepared in order to facilitate that such communications are carried out effectively and in time with accurate and concise information and allow especially and foremost that the situation is under control. It’s important not to generate more questions than existing ones, mistrust and causing a impact in the image that can immediately affect to the business, short and long term.
Now it’s time for  everyone to judge if whether jazztel communications was performed properly?

Sunday, 2 March 2014

Whatsapp service availability.

By Jorge García Carnicero

Whatsapp is the mobile application that has been adopted faster by most messaging users, becoming essential in a short period of time. Beyond the typical messaging functions, sending messages to groups of users has been established as the most common way to communicate between people, specifically when using the telematics platforms to coordinate activities of the real life.

Last February, 22nd, Whatsapp suffered one of the most important outages of its history, or at least it was the outage that affected a greatest number of users. A big amount of users didn't realize the service unavailability until about 7:30 pm., loosing their communications with their virtual environment without having an alternative way. But why?, because there are a lot of alternatives: SMS, Line, Telegram, Skipe and applications that are part of bigger systems, like Facebook Messenger or Google Hangouts. Because not all user though on the same alternative and two parts are required to establish a communication. The easiest solutions for most users was to make a telephone call.

Further than the panic and anxiety attacks suffered by some users, the analysis of the outage of Whatsapp from a business continuity perspective must be done taking into account that Whatsapp is becoming a real communications provider.

There are a lot of self-employed and SME that are using Whatsapp as a communications channel with their customers, making advertising with the green logo of the messaging company. It brings the company a modern branding  and a feeling of beeing close to the clients because the logo has positive emotional connotations: it’s associated with the contact with our most close environment in the mobile, our family and our friends. Without any doubt, it could be a very good decision from a neuromarketing strategies perspective. I wouldn't want to raise the debate of whether this use could be considered as legal, since in the Terms of Service Whatsapp expose clearly that it must be used only for non-commercial purposes. But, Can be Whatsapp be considered as a real corporate communication tool?

Little by little, step by step, people using Whatsapp for communications related with their professional activity are becoming more dependent of its service, but nobody ensures them that the service will be available in the terms they could need. Moreover, in their Terms of Service  Whatsapp avoid any kind of responsibility or damaged that can cause by their unavailability. In combination with the lax requirements defined by the regulatory organism (CNMC in Spain), makes the service should be considered unreliable in terms of business continuity.


In order that this could change, the service should be submitted, at least, to the same regulatory requirements that a telco operator. But it seems that is not going to happen in short terms, at least it's not included in the new Spanish telecommunications law  (ley general de telecomunicaciones) that is being processed during this months. So the recommendation that we have to make from a business continuity perspective is that Whatsapp should not be used as a corporate communication tool (and of course neither should be Line, Telegram, Skipe or whatever under the same circumstances). At least is has not to be used as a main communication channel and if used, their would be always an alternative way to establish the communication with the customer.

Last point of the analysis is the lack of agility of Whatsapp when communicating their problems. Although the services outage was at 7:30 pm the incident was recognized and communicated by the company at 21:16 by twitter in its account @wa_status. Could it be because Whatsapp founder and CEO was in Barcelona, in the MWC, this weekend?

Monday, 24 February 2014

Auditing Providers, Intrusion or need?

By Moises Lopez Soto

During the last years, there has been a diversification in the way the services are being delivered, increasing the number of providers that conform the supply chain and, therefore, the complexity in the control of all components to provide success in the final result. Trends as Outsourcing some time ago and recently Cloud are clear examples.


We find ourself everyday facing the challenge of ensuring business continuity of our organization with a high number of external agents and, in some cases, this external agent could be absolutely essential to the future of our company. That's why we must take action and act proactively to strengthen the links in the whole chain, minimizing risks and cushioning the impact that could suppose to our business the break of a weak link. This is a complex task when we have to control process and resources internally so it's easy to assume that it would be much more complicated with external agents which have full freedom to be independent in their process and way to deliver their services.

SLA is not enough

Establishing Service Level Agreements are completely valid and necessary on areas of service such as capability and availability but when we are talking about continuity it become insufficient. Among other things, this is because we are not referring to both the supplier's ability to give service but to their ability to keep delivering it after suffer a contingency.

The most common solution is diversification is relying on a model of "duplicity" in a provider-service base, with a relation of N to 1 and with a minimum of two, just as if it were a load balancing in a data network. In some cases this is the usual way to deliver the service,  in other scenarios suppose an increase in the resources required for service management with a greater workload for staff but, nevertheless, is NOT a valid solution for all services. For example, it is usually to stablish this kind of countermeasures when we are talking about business critical services like providers of essential services (electricity , water, etc. . ), when the solution is too complex or too expensive, when there is a monopoly or when there is a single infrastructure common to different suppliers, etc. Any way, it seems absolutely clear that a relationship model in which provider and the company has to be strength enough to carry out all contingency scenarios just as if they were the same company.

Audit process, an interesting weapon

It could be close the day in which the ISO 22301 (or similar) would be required to provide some kind of services, just like there is required the ISO 28000, the ISO 9000 or, even, the ISO 20000, but until that day arrives, audit processes becomes an interesting weapon. On the one hand it would bring a very significantly strengthen in the customer-provider relationship and on the other it will help to raise awareness, work and improving business continuity in both companies.
It is true that providers can refuse, just as we can see in the event that was supported by SIA last year, but it must be the customers which would has to assign some weight to the Business Continuity countermeasures that could be included by their provider in the proposals of service delivery.

Providers should consider the audit processes just like turning point in their business continuity activities, or if they have not done anything before a staring point, to provide resilience to their own business, having the opportunity to strengthen and enhance the relationship with their customers and, at the same time, get a business-marketing revenue on their actions in this field. On the other side, customers should approach them in a constructively way, focusing on growth and providing support and advice to the audited provider. Definitively, a Win-Win relation.

Now a days, audit processes are called to be the main element in order to ensure the strength of business continuity management system and so, the resilience of the company, so it seem to be more a need than an intrusion....

Monday, 10 February 2014

BCMS testing, prepared or not…?

By Moises Lopez Soto

Let's talk about testing in a Business Continuity Management System, based on the premise that this is an absolutely crucial element, and not necessary else MANDATORY to consider that we really have a Business Continuity Management System, not vain, They have dedicated a complete phase of the Deming’s cycle (PDCA). Therefore, let's not deep into the need for them, we assume that point passed, and we focus on How we do them or the "preparation" for them?


When the time comes to check that previously planned and done, actually, does its job and that the chosen strategy will cover and give the necessary support to the company in the field of Business Continuity, nervousness often comes to those responsible for have conducted each one of the established schedules, in addition the operational part enters a brewing cycle, normally, excessive.


We want to do a test, we consult to the members of the various existing committees about their availability because there is often some component of the Senior Management whose time is money, (so far, we can be considered a normal planning) further are consulted/agreed with responsible of the different systems/applications of IT that, possibly, will be affected by the test, we head to the users and their responsible to inform them that they will participate in a test, etc. etc. Outcome: hopefully, we will have preserved secretly the day and time of the test.

Just doing a Plan - Do - Check - Act of the test itself, the question is: is it really necessary?
Perhaps the question to be answered when we analyse the performing of a test be to When we want to be fired (being largely exaggerated) during a real contingency or after performing a failed test? Personally, if I would belong to some establishment of senior management and you are assured me Continuity alleging testing, and later, for the reasons that be, it’s must activate the plan and does not work due to the logic NOT preparation of the contingency, heads would roll…

With this, we don’t mean that it is not necessary, especially in the beginning, make some preparation before launching a test, but if that too much preparation invalidate the results we get with the test.
However, if we pass to the other end and we focus on testing without notice we also can find few problems and risks, for example, breaking the maxim: "Let the Business Continuity NO jeopardize the business" and we cause ourselves a contingency of major proportions. Furthermore, it is not good that groups with functions within the business continuity plans are accustomed to receive alerts for plan activation without prior notice as they may fall into the apathy and think "one more test" when treating of a real contingency.
Therefore, the most sensible proposal is the alternation, seen as making of prepared tests and improvised tests (knowledge of it reduced to a minimum number of people) so that knowledge and culture Business Continuity is encouraged in the company while feedback is obtained much more objective.

In any case, one way or another, it is always important to keep in mind when we're going to make a test that we must seek it is the failure, the vulnerability of our plans, the unexpected, obtaining lessons learned to maintain the continuous improvement, except inclement weather, the contingencies do not call the doorbell, knock down the door, and, above all, the test carry the imperative need for further testing inasmuch as the repetition is a proven method of learning and a perfect way to embed automation that will be absolutely necessary when stress atenace reasoning ability. How can we get this?

"A Business Continuity Test should not jeopardize the company, but must take the sure knowledge of your Resilience"

Wednesday, 11 December 2013

Learing how to improvise....



The other day Beatriz Portela (workmate belonging to the Tiger Team) surprised me with the following theme: “I’ve subscribed myself to a theater courses about improvisation” I immediately ask her: “Is it possible to learn how to improvise? , Could we use this concept in Business Continuity?

It’s very curious that most workmates in the industry are agree with that it doesn’t matter how complete are the continuity plans, it doesn’t matter the level of awareness would be the organization and it doesn’t matter the number of tests and training that we had carried out, real scenarios usually are worst than the worse expected scenario. Then, shouldn’t we practice improvisation?
A lot of business continuity test and trainings are aligned with plans stabilized in the companies, and this is OK, but being realistic, fire is not always affecting in the same way, hurricanes doesn’t  cause the same damage and people who are supposed to act in an incident could have the mobile out of service. So, could be the strictness of plans incompatible with an adequate crisis management? Obviously not, but what is sure is that we have to be prepared in order than in every moment of a crisis it could happen an unexpected event and our response team has to be prepared to respond in the better way.
Going deep in the improvisation techniques, two fundamental concepts are practiced in Performing Arts:
  • Listening: It’s difficult to adapt to a situation if is not attended by oneself. In case of business continuity, we should be aware to possible changes that can be done in the plan, being aware of it at all times.
  • Acceptance + proposition: understand the situation, accept it and make proposals based on it, that is, and answer that manage what has happened. In improvisation there is no room for denial; if something has happened, it’s not the moment identify why of looking for causes, but to respond in order to redirect the situation.


In a globalized world where there are a lot of cultures close to improvisation and other cultures stricter, is important to learn how to react in a joint way against the unexpected events that can occur.  In order to do that we should think about convenience of introduce in the business continuity teams training plans, improvisation practices that can help to deal with this circumstances. Perhaps introducing these simulation activities for example different plans combining between them or include bizarre situations, can help in real crisis scenarios to our teams to be better prepared and react in a proper way. This can help to understand each role and their responsibility, knowing their improvisation scope.

What is clear is that there is not possible to foresee everything and we want to provide resilience to our business, so there is no other way: we have to practice improvisation.

Monday, 21 October 2013

Spanish Critial Infrastructure Protection Law and Business Continuity

By Daniel Blanco Real


The Spanish Law 8/2011 or Ley  de Protección de Infraestructuras Críticas (LPIC) its related to grant essential services that support specific infrastructures considered critical mainly because of two properties:
  1. because its required and there are not other alternative solutions that could replace it and/or
  2. because a disruption or destruction should have very important impacts in essential services
But What is considered a essential service in the law? LPIC identify essential service as those services required to maintain social basic functions (health, security, social welfare and economics, Public administration, etc), although there is difficult to identify it based on the definition above.

Looking for activities and definitions carried out by other countries, we can take a look to the information published by Swedish Civil Contingencies Agency, (MSB in Swedish), that in 2007 established a set of criteria to identify Social critical functions, very close to what is described in LPIC as essential services.

Sector
Functions
Energy supply
Production and distribution of electricity, district heating, fossil fuels and vehicle fuels.
 
Information and communication
 
Telephone services, Internet, radio and TV broadcasts, postal services, production and distribution of newspapers, radio and TV.
 
Financial services
Money transmission, cash access, private insurance and securities trading.
 
Social insurances
Payment of sickness and unemployment benefits and the national pension system.
 
Public health and medical services, and special social
services
 
Emergency hospitals, primary care, psychiatry, pharmaceutical supplies, infectious disease control, and special social services for children, disabled persons and the elderly.
 
Protection, security and safety
 
Rescue services, police, courts, correctional institutions and SOS Alarm, military, coast guard, and customs, border and immigration control.
 
Transport
Road, rail, sea and air transport, and transport infrastructure management.
 
Municipal services
Drinking water, sewage treatment, streetcleaning, public meeting places, refuse collection and roads.
 
Food Agriculture and the production, distribution and control of food.º
 
Trade and industry Retail, IT operations and service, construction and contract work, guard and security services and the manufacturing industry.
 
Public administration
governance
support functions
service sector
 
 
National management, regional management and local management, diplomatic and consular services, inspection and permit services, expert and analytical services, detection and laboratory services, collection and provision of population data, meteorological services, training services and burial services.

It can be seen in the original document.

In order to clarify what is considered as a essential service, the document offers some questions that have to be answered for those who think that can be critical operators, grouped by two different blocks: preventive measures and respond measures

From a preventive measures perspective:
  • What is the potential scope of a shutdown?
  • How many people would be affected?
  • What levels of society would be affected by a shutdown?
  • To what degree would people’s lives and health be affected?
  • What financial, environmental, societal and cultural values could be lost?
  • How would public trust be affected?
  • How long would it take to repair the damage?
 From a response measures perspective:
  • Is the function essential for Leading and coordinating society’s response?
  • Is the function essential for Providing the public with enough information about the situation?
  • Is the function essential for Responding operatively to the emergency?
  • Is the function essential for Minimising the consequences?
  • Is the function essential for Restoring functions?
Once essential services are clearly defined, all organizations (obviously critical operator, but also if not)  must focus on:
  • How products and services that are delivering can affect to those essential services (This is clear in critical operators)
  • How lack of this essential services could affect to products and services delivered.
As a conclusion, Business Continuity in an organization has not only focus in how to recover products and service delivery, but also to take into account how the lack of this products and services affect to the society and the essential services. Without support of those essential services it's probably that organizations will not be able to recover their business and this is something that a lot of organizations don't take into account in their plans and business continuity management systems.

Thursday, 3 October 2013

When Goverment shutdowns

By Jorge García Carnicero

The decision taken by the Congress of United States of not to finance the Government is a continuity scenario that is going to bring multiples inconveniences to citizens and that it would provoke the activation of different contingency plans in organization, and people.

But first of all, what is a Government shutdown? It’s a situation in which Government stops to deliver public services that are not basic because of lack of money to pay it. This situation is due to the separation in the decisions groups established by the USA law in which the federal budget depends on Congress (composed by Senate and House of representatives) and have to be countersigned by President. In some circumstances, like President and parliaments groups that control the Congress, are different in political terms it could be that there would be divergences between them and not to approve the budgets, and consequently, the lack of financial for the public activity.

Last 30th of September, House of Representatives, controlled by Republicans, and Democart-controlled Government didn’t agree about deadline of health assistance law, which provoke the government shutdown. This brought along with sending 800.000 public servant to their homes and the activity of all the agencies in United State which are considered not critical stopped. Moreover, and due to the government has reached the top of approved budget, if new budget is not approved, United States will declare suspension of payments next 17th of October.

Government Shutdown consequences are a lot, as it can be imaged. Following we are going to analyses this situation from different perspectives:

 For agencies in United States:

Agencies are stopping their activities and carrying out the different contingency plans associated to each one. Those plans will be published in the following link of the White House

For Government agencies providers

It’s clear that the Government activity generate business for a lot of providers. These providers will be affected, because activity is going to decrease and so the ingress. Depending on the time that takes the shutdown, the looses in the providers will be growing. It’s difficult to thin on a contingency plan covering this situation, but assurance.

For companies depending on services of Government

There are a lot of companies which have dependencing on the government activity. Apart from the administrative activities, we are talking about, for example, public transport, needed to take people to their workplaces or custom services, needed to imports.

For Public servants

As said before, the shutdown is going to send close to 800.000 public servants to their homes, without salary, until the Congress approve the new budget. This situation can carry some finantial problems to their families, and each public servant will have to manage with measures that will anticipate, if they have done before.

There are other agents afected, like those ecompanies with a very high dependency on retail trade or al thouse business denpending on agencies actions. As an example, the validation of mobile phones.

From a the perspectgive of administration as a provider of business continuity services, companies and continuity responsables in United States has to take into account that the following services are affected:
  • FEMA: the disaster recovery information is not beeing up to date, although it has been asking for help trough disasterassistanc.gov
  • Ready.gov, the website information is not up to date.
  • The NOAA (National  Oceanic and Atmospheric Administration) is not operative, and the NHC(National Hurricane Center) is operative and working properly.

Friday, 27 September 2013

Conference AENOR-Continuam: Business Continuity Management

By Moises Lopez Soto


Last Friday, 27th of September, has taken place a conference about Business Continuity Management: ISO22301, promoted and organized by AENOR and Continuam with a high success of attendance and a great level of lectures. There has been perhaps for the first time that there were people of a great variety of industries, like Telcom such as Telefonica, energy companies like Iberdrola, or transport, represented by the Municipal Transport Company of Madrid (EMT).


Although this pot is not intended to be a wide summary of the session and there will probably be a lot of details not covered, I’d like to make widely known the event and some points that were covered by the different experts invited.

The session started with the exposition of the content and scope by Mr. José Luis Tejera, business development director of AENOR, who made a review about the different security standards and who made the first reference to an issue that was emphasized in the lectures after him: it’s really necessary to collaborate with supply chain, that is providers, because of the dependences on them.

After that, a round table was established about Regulation and Certification, in which there were reviewed different contents of ISO 22301 by Mr. Tomas Marín Iñurrieta, chief of Regultations service and Coordination of CNPIC, and Mr. Carlos Manuel Fernández Sánchez, Business Development TIC manager of AENOR, who emphasizes about the importance of deploying business continuity system instead of certificate it, although certification requires you to keep your deployment up to date.

Mr Juan José Miguez Iglesias, technology risks associate of PwC, contribute with the experience of PwC in Business Continuity consultancy, defining a four phases methodology (Document review, BCMS gap analysis, verification and tests and support to audit process) with which they intend to cover most of their customer requirements for deployment of BCMS. PwC metohodology also can include fast track actions, with which they will test in a first approach through a role play the knowledge and maturity of the company take this test as a starting point and developing the plans and procedures in a second approach. This combines Latin character (based in improvisation) with Anglo-Saxon character (based in procedures).

Closing this first round table, Cristo Perez, Busines Continuity Manager of Sanitas, made a presentation of the pocess follow by Sanitas for deployment and certification of BCMS, showing an example of a DRP evolution since it was not enough to cover the varity of scenarios typically included as Business Continuity scope. He used two examples: thread of terrosit attack in Campo de las Naciones, that caused a unavailability scenario and Aviar flu. As a resasault their have a global management system in which they include the business decision makers and, over all, that put People as cornerstone of all system.

In the second part of the session, Mr. Cesar Perez Chirions, President of Continuam, and Ms Maria Parga, general director assessor of BME-INNOVA and vicepresident of Cotinuam, made a presentation about the “Instituto de continuidad de negocio” and about their objective of connect professionals who want to share their knowledge and try to to make widely known and promote Business Continuity activities.
Closing the session, there toke place a second round table with the following professionals:
  • Mr. Manuel Carpio Cámara, Information Security and Fraud Prevention director in Telefonica, who apart from giving information about specific cases and present the global BCM structure of such a big company, made his particular vision of BCM, with two dimensions: a vertical dimension with BCMS and a horizontal dimension which put together particular requirments). He also expose the way they support the different BCM plans of each telco belonging  to Telefonica Group through SUNGARD BCM tool in DRASS model. I would like make two highlights of his lecture: The phrase “Continuity is NOT an option” and Event Correlation, which can bring information about where is anybody at any time during an incident.
  • Mr. Ángel Robles Rodríguez, Deputy lawyerd at EMT, presented how from his organization they have to think on buses as if they was an employee.
  • Mr. Pedro Pablo, Security, privacy and Global Continiuty Manager of RSI, talk about necessity of reinforce supply chain and make emphasis in problem trying to grant the service level agreed with providers, especially with big ones.
  • Mr. Javier García Carmona, responable of information security and communications in Iberdrola, was the autor of an other phrase that I consider it a great phrase: “In Spain there is not Business Continuity Culture”. Apart from that he sent a calming message about Spanish electric infrastructure, considered one of the critical infrastructures.
  • Mr Roberto Rodriguez, Business Continuity Director in Grupo Santander, made an exposition remarking the  value of test as a way establish automatism responses to a contingency and serving as a catalyst that avoid the potential shock of personal selected to answer the incident because of the type of crises that could be close to their environment, or because of their own character and their ability to answer to a contingency, being critical to the success to the Business Contintuity program the election of this people and we do not usually pay to much attention to this.
  • Mr Victor Llorente, bussiness consultor at Grupo SIA, go into detail about the need of support Business Continuity programs in tools that allow the automation of BCMS processes.
The closing lecture was carrying out by Mr Avelino Brito, general director at AENOR, who toured the organization and put into relevance the meaning of AENOR as a unifying knowledge organization.

In general terms, I feel has been an interesting event, which highlights the progress in Business Continuity industry. Business Continuity professionals begin to look for strengths and obtain resilience, ensuring not only our internal capabilities but also the dependencies by third parties. This requires focus much more towards people, towards their responsiveness, to heard and given the capacity of business decision makers as opposed to the old IT disposal. And all this is done under a global international framework, which is ISO22301 in which to look and be bound to improve.

Sunday, 24 March 2013

Conference SIA - Continuam. Summary

With a relevant number of attendees, about 100 people, last 20th of March took place a conference sponsored by SIA Group and Continuam in which there were given an overview of the different activities that are taking place within the sector. The conference took place in the restaurant Loft39, at C/Velazquez in Madrid, calling for assistants at 12:00 and elongating until 16:00.

Introduction to the conference was provided by Enrique Palomares, CEO of SIA Group, who highlighted the commitment of this company for business continuity and the path along the last years, with both services consulting and automation tools, with SunGard AS.

First lecture was given by Daniel Blanco, BCM consultant at SIA Group. Under the title “Continuity, state of the art” Daniel gave an overview of the various standards and their evolution over time. He identified the main differences between BS25999-2 and ISO 22301 and highlighted the relevance of training and drills, specifically to provide visibility to the rest of the organization.

After Daniel, Juan Manuel Gil, CEO of F24, continued putting in value the relevance of notifications and how this notifications should change from traditional models (calls, SMS, emails, etc) to latest channels, dependent on the resources available for the employees of the organization.
In the third lecture Alfonso Costa, BCM Manager of Mutua Madrileña, stated which, from his point of view, are the cornerstones of business continuity within an organization:
  • Alignment of objectives, mission and vision. The strategy of the organization must be aligned with the continuity management program.
  • Governance model. Management should be involved. It is important to have a good sponsor.
  • Visibility: must publicize the work done since continuity areas. You have to "come out". Testing is the largest showcase of business continuity
  • Report: The record of what is becoming essential to show activity.
Then Pablo de Vera and Luis Sancho exposed the management structure of the business continuity used in BBVA, providing continuity of different committees depending on the severity of the incidents that occur: corporate continuity committee, country continuity committee and plan continuity committee. They gave a clear message which is the aim of his plans to ensure the service that BBVA provides to their customers and, therefore, their business.
 
Luis made it clear what is and is not a contingency BBVA, going more in detail about different scenarios to which BBVA had faced in recent years: pickets impeding access to a center, Hurricane Katrina and Ike, fire "neighbor" in the Windsor building, falling bank communications, critical power drop, the Icelandic volcano ash, etc..
 
To conclude the presentations, Tomas Martin, from CNPIC, outlined the activities being developed as a national critical infrastructure center, in collaboration with other European bodies: BUCOPCI standard, workgroup with AENOR, Smart grids: Spanish industrial safety platform, collaboration with coesga, among others.
 
To round off the event, it took place a panel discussion, moderated by Cesar Perez Chirinos (Continuam president) in which there was in an interesting representation: CNPIC, Bank of Spain, RSI, BSI, AENOR, Arsys and SIA. Cesar was moderating the table with different speakers that were answering the questions and gave their views on business continuity.
 
As a conclusion, the event was very well organized by SIA. Perhaps the time of lectures was extended in excess, but the speakers transmitted very pragmatic views, changing the discourse of IT by business discourse, closest to a comprehensive understanding of business continuity. The BC industry is maturing every day in Spain.

Sunday, 20 January 2013

Crisis management in Madrid Arena party


There has been a lot of information about Madrid Arena Halloween party, in which four women was killed in a stampede. Most of this information is related to political responsabilities, but there are an issue that has gone unnoticed and I think there Is very important from business continuity perspective. It’s  the role played  by mobile communications in whole crisis.

According to the testimony of the participants, it seems that there were a mobile communications breakdown, mainly due to the great amount of people in such a small space. It similar to what happen in a sport event with huge crowds, for example a football match each weekend or to what happened last year in the Mobile World Conference in Barcelona. 

However, when this situation occurs in crisis scenarios we have  two problems:

  • Those affected cannot communicate or make emergency calls
  • Emergency teams cannot communicate with each other in order coordinate if this communications depend on the mobile generic infrastructure. 

In order to avoid this kind of situations, there are two options: make the service stronger or use an alternative service.

Thinking on the attendees, there could be explored the possibility of providing an alternative coverage (wifi network). With such a large crowd, it will probably has the same problem than the generic mobile infrastructure, but it will not be dependent on a mobile operator and could be offered as an aggregated service to the whole infrastructure.

There are mobile cells to allow operators improve mobile coverage in special locations, moreover, there are companies focused on offer coverage in public locations with a large crowds, for example Spring.

However, although could be technical solutions to avoid this kind of situations, neither facilities responsible will include wifi service, nor mobile operators will strengthen coberage in an altruistic way.  Government should include this as a requirement for license this kind of events with the guarantee that mobile communications will be delivered.

On the other hand, in order to allow the communications between members of emergency teams they use the RF network, Tetra. This network were not working because the walls were of concrete, so emergency staff had to use they own personal mobiles to allow the communications with other members. This situation is complicate to avoid without valuing the architectural problems of the building.

A good practice could be to advise the attendees about the problem that they could have when using their mobiles, specially when the location are not prepared to host a very huge crowd, form example in public demonstrations. Generalitat of Catalunya do it every year when is near the day of National Day of Catalunya.