CIO

Hope for the Best, Plan for the Worst

A fast and effective recovery from a fire, earthquake, or malicious attack, depends on two key components: a comprehensive recovery plan and a carefully selected business-recovery team.

All 320 employees of the US Securities and Exchange Commission (SEC) may have escaped unscathed the series of terror attacks that demolished New York's World Trade Centre on September 11, but vital documents did not. The commission's office was incinerated during the collapse of Tower 7, destroying crucial evidence and reportedly jeopardising its investigations into initial public offerings and other cases. Certainly the SEC can ask companies under investigation, or charge, to produce copies of documents they've already given the SEC, former New York operations leader Carmen Lawrence told Bloomberg News. "But they'll have to scrap many cases and start from scratch on others," she added.

Now we know why business continuity planners invest so much energy in preparing detailed disaster recovery plans that extend way beyond IT recovery. Getting back up and running after the world throws its worst at you is not only about ensuring an IT provider is always on hand to rescue computer networks, data and host IT services should your computer systems be destroyed. It's also about finding ways for the business to continue should the earth be pulled from under everyone's feet, buildings and paper-based documents destroyed and vital employees killed.

Thousands of lives were lost in the attacks on the WTC. More than 406 buildings were damaged, with eight demolished, including the twin towers. But the total disruption spread far wider. The attacks took out subways, roads and bridges and forced authorities to restrict access on security grounds. Communications and transport were severely disrupted.

In the wake of the attacks some organisations were left reeling, their offices destroyed or access to their buildings blocked off, forcing them into a frantic scramble to retrieve lost data or find somewhere to host their operations. Others seemed to make a virtually seamless transition to managed disaster recovery facilities. Business continuity planners who knew their stuff can glory in the way their banking, finance and regulatory businesses maintained essential processes throughout the disaster. But even the best disaster recovery plans were severely tested by the destruction. As businesses everywhere dust off their disaster recovery plans in the wake of September 11, in the new environment of menace where anyone seems a possible target, there are vital new lessons to absorb about what makes for an effective business continuity plan.

Considering that until the attacks happened even the US military believed the events of September 11 were impossible even in the worst-case scenarios. Experts now say business should focus on a new set of priorities, which even the best current plans may not address. All companies now face new concerns that must and should be incorporated into disaster recovery plans.

"The primary concern for major disaster recovery has refocused from natural disasters to include terrorist attacks within CBDs affecting buildings and infrastructure randomly over a large radius," says Tony Newman, a senior consultant with Australian company Montrose Computer Services. "The critical concerns now are the safety of people - human resources, the accessibility to buildings - the need for alternative premises off-site and outside of the local area, and the IT infrastructure needed to maintain normal business services - the need for off-site recovery facilities and mobile communications." Disaster recovery plans that don't consider all of the above may one day prove worse than useless, Newman predicts"I think what this disaster has proved is that technology is not as big a risk as is the way we use technology to do business. It is the emphasis on the people, and our dependency on them, and how we choose to operate," says IBM general manager and vice president New-York based business continuity and recovery services group Todd Gordon. "The fact that the networks are very redundant, hardware is almost infallible, and we have multiple pieces of equipment to do the same tasks [means] we have geographic load balancing. We have become quite sophisticated as users and as IT providers in terms of how technology is used."

Or as Charles Micallef, a director with Peter Voysey & Associates, puts it: "It's no use just getting your IT up and running in 24 hours if you've got nowhere for your sales force or your marketing force to take orders. If you're providing some sort of help-desk facility and that's a critical part of your business, you need to be able to switch to another site, another venue."

Join CIO, the CIO Executive Council & IDC on 6 October at Australia’s premier Melbourne event for senior IT executives – the CIO Summit 2010. Find out more or register now.

More about: Bloomberg, Compaq, Compaq Computer, Dell Computer, EMC, E*Trade, Hewlett-Packard, IBM, Information Resources, Meta Group, NATO, Newman, Ovum, ProVision, Quantum, RTA, SEC, Securities and Exchange Commission, Telstra, Texas Instruments, Transportation

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
 
Featured Whitepapers
IDC Research | Measuring the Business Value of Green Datacentres

Evidence from IDC's Business Value research indicates that efforts to reduce energy use do help companies save money and improve IT service levels. Read research findings and gain a view of advanced value solutions...read on.

Wondering how to improve your business with UC on an IP Network?

Join Computerworld's Live Webinar where we will address the move many companies are making towards IP based voice services (SIP trunking, VoIP) and look at how they are using a single connection for data and voice rather than separate lines. Learn about the latest in IP networks and how it can help your organisation.

Wednesday 25th November 2009, Time 10.30 am EST (Sydney, Australia) Screening at your desk

Register now

  • +

    WikiLeaks founder Assange questioned by Swedish police 01 September, 2010 05:36:00

    Police and prosecutor are keeping mum on how the investigation is progressing
    WikiLeaks founder Julian Assange has now been questioned by Swedish police regarding a molestation charge directed at him, his lawyer said Tuesday.
  • +

    uTorrent patches application against DLL vulnerability 30 August, 2010 04:31:00

    uTorrent is one of many applications that is affected by the vulnerability
    The developers of the uTorrent file-sharing application have released an updated version that fixes a problem that could allow an attacker to load malicious code onto a user's computer.
  • +

    Wikileaks' Assange to be questioned, says Swedish prosecutor 26 August, 2010 04:54:00

    The Wikileaks founder has been accused of molestation, though one charge has already been dropped
    Swedish Chief Prosecutor Eva Finné has ordered that WikiLeaks founder Julian Assange be questioned about molestation allegations.
  • +

    Adobe fixes 20 vulnerabilities in Shockwave Player 26 August, 2010 03:55:00

    Most of the vulnerabilities could allow an attacker to run rogue code on a computer
    Adobe Systems patched 20 security vulnerabilities in its Shockwave Player on Tuesday. Most of the flaws could allow an attacker to run their own code on an affected computer.
  • +

    Sticks and stones: Picking on users AND security pros 26 August, 2010 02:08:00

    Name-calling is harmful to the cause of security
    I took my share of name-calling as a kid. I did my share of name-calling, too. We're taught that nothing good comes of such behavior. I've been thinking a lot about that since writing an article two weeks ago called "Security blunders 'dumber than dog snot'" during the 2010 USENIX Security Symposium.

Recent comments
Zones
SAS Resource Centre

This Resource Centre hosts a wealth of thought leadership articles, whitepapers, and success videos, to help you make the most out of your corporate information in order to swiftly make sound business decisions to survive and thrive in the current economic climate.

Oracle Resource Centre

News, Features and the latest whitepapers on SOA, Application Grid, Enterprise Management and Database

CIO Industry Insight Podcast #9: Tim Ayling, Chief Executive Officer, Platform46
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper
Securing People and Information: How to Protect Against Today’s Web-based Threats

This white paper explores the benefits of an Application Delivery Network, highlighting the ability to protect your users and applications and still deliver outstanding application performance with confidence, consistency and cost-effectiveness across your distributed network.

Read Whitepaper

Brought to you by