Tuesday, 25 September 2012

Sabotage

Yesterday, talking with the chief of Business Continuity consultancy in one of the main companies of the industry in Spain, we have doubts about if the case of sabotage in the power infrastructure in Rayo Vallecano's stadium should be consider as a scenario in Business Continuity plans.

La falta de luz obligó a aplazar el choque que debían disputar Rayo Vallecano y Real Madrid.On the one hand, it could be clear that a scenario of lack of power, no matter the origin, must be included in BC plans. Measures to assure power are very common: generators, two power providers, etc.

On the other hand, the sabotage in football match between Rayo Vallecano - Real Madrid has two special considerations:
  • The stadium must be available at a specific time and during a relatively short period (2 hours)  There is not possibility to play the match in other stadium - it would be impossible to move 15.000 - and it's not possible to play at other time, since the main business to be continued is the is the television retransmission.
  • Internal electrical infraestructure were damaged, so there is no way to use an alternative infrastructure. It has to be repaired.
Since Business Continuity has to focus on moments after an events occurs, and the plans covers the actions to be taken on this moments, its seems to be difficult that the staff of Rayo Vallecano could done something different if they would have a Business Continuity plan. Traditional measures would be not effective in this scenario because it was damaged the internal infrastructure. So this scenario is only useful to analyze risks and define the mitigation measures.

In general terms, when business depends on somebody doing something in a certain location, business continuity plans doesn't help too much: It's not possible to change actors, location or time, so we can only make a good risk analysis and try to mitigate it as far as we can.

Friday, 7 September 2012

BYOD and Business Continuity

BYOD can be considered as a trend in the IT and is called to be developed during the following years, since this has a lot to do with mobility and telework. There has been users themselves, manly top management, who has introduced smartphones and tables into the offices when they realized that they were using their shabby professional mobiles more regularly than their brand new iphone and they began to invert this trend, forcing their CIOs to allow access to their email, agenda and other applications. This means that, instead of being the product of a marketing strategy or the conclusion of trends report by a high level consultancy company (surely they are going to include in it from now), is the result of an increasingly widespread practice.

From a technical point of view, BYOD is going to be a revolution in the workstation world that will require procedures update, new tools for manage the devices and new security policies. Security and legal issues will be probably most affected by this trend, with a lot of voices form security experts rising against it because of the violation of traditional security dogmas of access control al data loss prevention. That’s why there are a lot of comments in forums and a rising market about device protection tools to avoid happened situation like the one affected to the Spanish Homeland Security Department Minister, who loses his ipad. Most of this tool were available before and has been named with the fashion acronym (BYOD compliance…)
From Business Continuity perspective, BYOD doesn’t bring a great change, since will be very similar to remote access policies in which users usually take care of the expenses of Internet connection or even the computer they use to access to company’s intranet. In the same way they do to remote access, BC manager, usually with Human Resource department, should assure the following:
  • Employee give consent to use their own resources to a professional use.
  • Employee owns the required resources to carry out activities they have to do in a crisis or contingency situation. The better way to do this is involving the user when inventory of their own resources periodically.
  • Employee resources comply with company security and feature politics and procedures.
Apart from that, as every BC resource, BC manager should assure the information in the inventory will be updated continuously. In order to do that, the best option is to automate the process with tools like Workforce Assessment by SunGards AS, in which inventory and update process are done with a web form and is stored in a relational database. This allows using this information later, when defining BC strategies and procedures. And of course these resources have to be included in the exercising program.

Thursday, 2 August 2012

Thoughts about blackouts in India

It seems that last blackouts in India have activated a lot of Business Continuity plans and have made the different between companies with and without a BC program. Lack of power supply is a clear continuity scenario to which most companies are prepared, mainly through power generators able to support the sites demand of electricity, or at least, of the most important.

Other issue to take into account is how to assure that workforces are going to reach their workplaces, since public transport are not available. Moreover, if telework is the alternative, How can they work from their homes if there is a lack of telecommunications?

ICTs are one of the resources that will be affected most because of their dependency on power supply. Blackout in India scenario shows resiliency examples of companies which principal business is IT services, as we can read on this article about Winpro, Genpact and WNS, but is not a trivial matter.

However my thoughts go in other way: Can this scenario be really included in the BC scopes?
In a first approach it seems clear that this scenario has to be included, but thinking on it deeply, our customers will probably be affected by the same problem, so it has no sense to be able to deliver our service if our customers are not going to receive it.
In a globalized world, in which we can have customer located near us or in the most remote place of the earth perhaps this thoughts has no sense, but we have to take into account that most business are done locally, with companies and organizations very close one to the others. Resource investments on this scenarios are not justified too much.
As an example, we can think on a clothing store: It’s difficult to have our store plenty of customers in a situation of a blackout like the one taken place in India. Every street and every shopping center are in dark

As a conclusion, and as an advise as well, when defining the scope of our Business Continuity plans we must evaluate the scenario thinking on the situation of our customers because perhaps I recover my services and there is nobody use it.

Sunday, 22 July 2012

Corporate identity theft in Social Networks


Colaboration by Beth Ojeda, Social Media Manager at Continuam

One of the most common and relevant problems in social networks are the company identity theft. This kind of attacks generate business chaos if they are not covered in Business Continuity Plan due to recovery from this attacks are laborious, although is not imposible. This attacks use to generate a lot of inconveniences, because one of the main reasons for a corporate identity theft is discredit and damage their reputation, generating distrust in customers, providers and general followers.

There is also present a latent threat of fraudulent actions which carry theft of followers information, controlling confidential information that could be exchanged between the Community Managers and users.

Preventive measures:

  • Owning an alternative corporate account, with corporative image and not publicly available, in order to be activated only if a crisis occurs.
  • In those social networks that could be possible, define a super-administrator account
  • Having an email, from other domain than the corporate, to access social networks and store the initial codes that the social network gives to recover the account, deleting it from the email account.
  • Establish different passwords for each social network, and further, define strong passwords.
  • Send to each follower in social networks an initial message with the official customer attendance email, for more information.
  • Designate a spokesman for on-line crisis situations who will use his or her own profile in this situations.
  • Write down all actuation plan, password recovery methods and actors that has to participate in the recovery
  • Conduct a drill to identify faults.
  • Develop a template for reporting to the police, since it must be done immediately after the theft.
  • Create monitoring alerts in each social network in order to receive feedback about the company reputation and to identify problems in communication.
«Remember that everything you can think of, the cyber-criminal has also thought it before»

Managing Crisis:

  • Activate the crisis profile
  • •Publish an online press release, advertise the corporate identity theft and announce the new social network account and the spokesman designation.
  • Forward the oficial email to users communicating that the social network profile has been theft and that they can establish contact with the company in case of problems.
  • Maintain a relaxed communications level and focus on the situation, without personalize the attack.
  • Send the account recovery codes to the social networks administrators.
  • Identify the spokesman as a VIP user (with a special character adjacently the name singing he messages)
  • Create internal report about the monitoring in order to know the impact of the identity theft.
Although in a first approach could be the better response, silence is not a good option because ciber-criminals will continue casting doubts in the company followers, even creating false offers to compromise organization credibility. Even revealing internal information, although this information could be false, they are talking on behalf of the company.
Beth Ojeda
Social Media Manager at Instituto de Continuidad de Negocio.

Monday, 9 July 2012

Legionella, a real threat

As every year at this time, we face in Spain with recurring news about Legionella, which impact is very high, not only from a health point of view, but also about business continuity. This year the focal point has been in a hotel in Calpe, closed since last 3th of July and in a restaurant in Mostoles, where there is 52 people affected and a dead person.

Legionella first infection of large proportions occurred in 1977, during a congress of the American Legion in Philadelphia. In the hotel in which the congress took place there was an outbreak of an infectious disease that killed 34 people and affected more than 180. Studies determined that the source of infection was a bacterium that had been spread by the air-conditioned hotel and, due to the nature of the conference attendees, was named as Legionella
In Spain, Legionella prevention is regulated by the Real Decreto 865/2003, from 4th of July of 2003, in which are identified different health and hygiene procedures for prevention and control of legionellosis. As every health activity, the RD identifies actions to carry out in both, to prevent and to act in case of an outbreak takes place.

Leaving aside the health and hygiene aspect, from a business continuity point of view the most important chapter of whole RD is the number 12, which identifies activities to do in facilities when an outbreak is detected. This chapter describes the following:
"In the presence of cases or outbreaks, very poor facilities, contaminated by Legionella, obsolete, or poor maintenance, the health authority may order the temporary closure of the facility until the defects are corrected or decommissioning. May not be placed back on track these facilities without the express permission of the competent health authority."
If we rely on the historical cases that have product in recent years, we could say that the risk important, and therefore the scenario of facilities unavailability is more than justified. Mainly, for the facilities most likely to proliferation and spread of Legionella, identified in the RD as follows:
  • Cooling towers and evaporative condensers.
  • Hot water systems with storage and return circuit.
  • Heated water systems with constant stirring and recirculation through high-speed jets or air injection (spas, Jacuzzis, pools, glasses or therapeutic tubs, whirlpools, jets treatments, etc.).
  • Industrial humidifiers centrals.
That’s mean every installation with refrigeration systems and/or air conditioner is likely to host a Legionella outbreak,mainly if a proper maintenance is not done that grant everything is clean.
Even more, the RD also includes sanctions, classified as minor, serious or very serious, which have economic penalties from 30.000€ to 600.000€, that also should also be taken into account by business continuity responsibles.

As a conclusion we can say that the Legionella must be taken into account when identifying business continuity scenarios and carrying out the following actions:
  1. Identify the level of responsibility of the company in the refrigeration system and cooling towers.
    • If the site is an owned site, the company has to make reviews and regular checks.
    • If the site is rented, company has to require the leaseholder to perform the checks
  2. Perform an impact analysis, with changes over the time, in which economic sanctions will be taken into account.
  3. Define actions to be performed in case of outbreak will be detected: alternative sites, communication procedures to employees and customers, media communications, etc.

Friday, 25 May 2012

5th Business Continuity International Conference

As every year, and this is the 5th, last Tuesday 22th in Madrid and Wednesday 23th in Barcelona has taken place the 5th Business Continuity International Conference by BSi, this year with the new standard ISO 22301 being launched.  Following I summarize the event with a little description of each lecture of the conference in Madrid, to which I had the pleasure of attending.
With an attendance of more than 150 people from different industries, the maximum capacity was practically cover.
 
  • Introduction and welcome by Marcio Viergas (BSi general director). Provides the general definitions of an ISO standard, the different committees and how BSi, as a standard developer, has historically contributed with a lot of norms developments that has became international standards. ISO 22301 is called to be an important international reference and is predicted to be a boost for the industry and, seeing the attendees to the conference, looks set to become a reality.
  • From BS25999 to ISO 22301 - Business Continuity Management by Agustín Lerma (BCM Product Manager at BSi) Agustín provides in general terms the content of the standard and the correspondence with the Demming cicle, which is mainly the following :
Plan
4. Context of the organization
5. Leadership
6. Planning
7.Support
Do
8. Operation
Check
9. Performance Evaluation
Act
10. Improvement
    Agustín also define the alignment of the standard with  Guide ISO 83, about standard structure, PAS 99 about management systems and ISO 31.000 related with risk analysis.
    • The new International Standard for Business Continuity: ISO 22301. Dave Austin (member or ISO committee for standard 22301 development) Dave exposed deeply the standard, in some points overlapping with Agustín lecture. Highlighting the following points:
      • Standard is equivalent to BS 25999-2,  so the schema will be completed when ISO 22313 were published. Its publication is scheduled for next year.
      • There are a new concept MBCO (Minimum Business Continuity Objective)
      • Legal requirement specific for each country are included.
      • Risk evaluation is aligned with ISO 31000
      • Strategy had some shortages in BS25999, in the new standard it has a better definition, proposing the identification to reduce probability and impact, RTOs definition, resources needs and actions to protection and mitigation requirements compliance.
      • Incident communication: is much more complete and gives more importance. A better integration with emergency system is proposed.
    • Business Continiuty Management  end to end. Fernando Picatostes (Deloitte) The lecture was based on Deloitte business continuity methodology, focused in risk too much. Incidents in which Deloitte was involved some years ago (Windsor building and Twin Towers) were mentioned, as usual.
    • Crisis management and Business Continuity. Andrés Gonzalez (Near Technologies) made a review of the main security and business continuity incidents occurred lately and lesson learned for each one: Twin Towers, Tepco in Japan, Spanair MD-82, etc. The "prezi"ntation can be viewed here
    • Risk Management ISO 31000 and integration with new ISO 22301. Angel Escorial (AGERS) After a description of what Asociación Española de Gerencia de Riesgos y Seguros is, Angel make a deep review of the standard 31000 and the contrast between this standard and ISO 22301. From a personal point of view, the lecture was very interesting and I highlight a phrase: Risk management works with impact, while BC management works with time and impact. If we think on continuity as risk management, I think is not the better approach, aligned with the tittle of this blog.
    • Business case of Telefónica UK in Business Continuity. David Clarke (Telefonica O2) With on of the most complex business continuity management, David expose the long way he have to walk before the certification. From the lecture I highlight the benefits of implementing the BCM, what I think is key for every BCM system:
      • Increase trust from customers, partners and third parties.
      • Ability to work with suppliers to build continuity strategies
      • Industry recognition
    • Experts colloquium- Workshop about new standard ISO 22301. Julio San Jose (Bankinter), Fernando Picatostes (Deloitte), Andrés Gonzalez (Near Tech.). Moderator: Marcio Viegas. Due to agenda problems, I cannot attend this interesting colloquium.
    Conclusions
    With a great attendee, the event shows the general interest in Business Continuity from the different Spanish companies and organization. Furthermore, the fact that ISO 22301 has been launched do foresee that the directors interest in BC will rise.
    From an organizational point of view, once again, congratulate BSi by the professionalism with which held both the call as the event itself (Congratulations Patricia, Silvia, Beln and company)
    About contents, I think that attendees general feeling was they were poor, mainly those from BC service providers.

    Saturday, 5 May 2012

    Business Continuity and Operational Risk

    After the last Argentine government's decision to nationalize YPF, followed by the Bolivian doing the same with REE subsidiary, in different business continuity forum has started  a debate about the requirement or not to include this scenario in the scope of the Business Continuity plans. Does Business Continuity manager really contemplate the possibility of an expropriation? and as a extension, May bankruptcy scenarios or extremely adverse economic situation, like the situations caused by economic crisis, be included into the scope of plans? It's not a trivial question since scope will determinate the economic requirements of the Business Continuity program and the roles which will be responsible of BC in the organization.

    An answer to this question can be found in operational risk management and the integration with Business Continuity management. Operational risk management look for analyze those factors that can affect negatibly to business, defining this, as in every risk analysis, by probability and impact.

    In some industries, like financial, risk operational management is a common practice. In fact, financial system regulation (Basilea iI), defines operational risk as:
    “The risk of loss resulting from inadequate or failed internal processes,
    people and systems or from external events.”

    This is quite similar to a risk analysis from a Business Continuity point of view.
    Deepening in Basilea II, it defines seven categories of risk operational:
    • Internal fraud;
    • External fraud;
    • Employment practices and workplace safety;
    • Clients, products and business practice;
    • Damage to physical assets;
    • Business disruption and systems failures;
    • Execution, delivery and process management.

    Although some of this categories seems to be quite close to Business Continuity categories and scenarios, not all of them may to be included in our business continuity plan. For example, damage to physical assets can be covered by our BC plan, including a IT service recovery plan and all the recovery procedures. However, internal and external fraud seems to be far away from Business Continuity.

    As Richar Wartered, from Marsh Risk Consulting, defined in the workshop Risk, Resilience & Continuity by BCI, BC management process and operational risk management must begin at the same tieme and independently, joining resoults when definint risk mitigatin strategies.

    It's necessary to take into account that objectives of BC are to recovery the service or delivery of product after a disaster or disruptive event occurs, since risk management has to be focused on the preventive actions, before the occurrence of the disaster.

    In order to define the BC scope, the best practice is to follow BS25999, and hope ISO 22301 soon, in which there are defined five componenet that has to be inluced in the plans:
  • people (7.3)
  • premises (7.4)
  • technology (7.5)
  • information (7.6)
  • supplies (7.7)

  • As  I defined in my previous post (Components supporting business), depending on the characteristics of business, each component will have a specific weigh in the delivery of services or products.