Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/25/2020
10:00 AM
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

COVID-19: Getting Ready for the Next Business Continuity Challenge

What comes after you've empowered your remote workforce in the wake of the coronavirus pandemic? Dealing with a large portion of that workforce getting sick at the same time.

Business continuity planning (or resiliency) consists of preparing for how to operate if we lose our technology, facilities, or people. During the COVID-19 pandemic, so far, we are mostly dealing with losing our facility and having to have employees work remotely. What could come next? How do we prepare to deal with a large portion of our workforce getting sick at the same time and requiring isolation?

Generally, the solution for the loss of personnel is cross-training and documentation, but many companies function on tribal knowledge and relationships. This can work fine when everything is normal, but when we start to lose key resources (those human routers that know how to connect to critical institutional knowledge), we need documented processes to reference.

Once you identify the folks who are the only ones who know how to keep a key technology or process running, you need to determine if you can get someone cross-trained and then use that training to document the function. If cross-training will not work, then the individual will have to automate or document everything needed to ensure continuity of operations. I have found this to be one of the hardest challenges but, considering the current pandemic, would say now is the time to pull your critical human and technology resources off of current operations, before you have to develop a crisis management plan instead.

Support phone trees for key functions are vital. It is important to know who the experts are for different key functions. This could include third parties and vendors. While I reference the classic fallback system of phones, today we can also use technology to minimize the impact to an isolated team. To do so, you will need to ensure application access, video teleconferencing capabilities, and collaboration tools with capabilities such as chat or document sharing. However, remember that collaboration tools are only useful if folks know whom to reach out to for support and information.

Map Out Staffing Depth for SLAs
Next, you need to determine your regulatory and contractual service-level agreements (SLAs) and map out the staffing depth you have in order to support them. For areas where you have risk, you need to determine what the criteria is for action. Ask yourself: If we lose 10%, can we still meet our SLAs? What if we lose 50%? What are the impacts, and do we have a plan for acceptable recovery? I will note there are formulas for business impact analysis (BIA) and return to operations (RTO) that can be leveraged here. Depending on the ability of the team to support cross-functional capabilities, you may want to develop a prioritized list of functions you will maintain.

Another option to consider is determining which of your vendors offer service support and making sure you have agreements in place to use them if needed. Having staffing augmentation available is a key lever to be able to pull if needed to keep systems running. 

Along the same lines, if you have not checked in with your suppliers and asked for their business continuity plans, the time to do so is now! You need to understand how mature their capabilities are and be ready to develop options if they fail.

If you don't currently have anyone certified in business continuity, it's a good time to get some of the team trained. Generally, the training is around both business continuity and disaster recovery. A pandemic doesn't really require disaster recovery, which focuses on returning the core technology or facility to operational capacity. If you follow ISO-27000 for security, there is an ISO-22301-certified business continuity manager (CBCM) course that would complement it. If you want more general certifications, there are a number of them run by different training organizations.

The bottom line is that while we are dealing with the challenge of remote workers, now is the time to conduct some exercises on how to fight through the loss of staff. 

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Three Ways Your BEC Defense Is Failing & How to Do Better."

Steve Winterfeld is the Advisory CISO at Akamai. Steve is focused on being the voice of the customer for Akamai's security vision and helping CISOs solve their most pressing issues. He brings experience with Zero Trust Security Architectures, and integrating multiple tools ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
cnsieler
50%
50%
cnsieler,
User Rank: Apprentice
3/25/2020 | 6:21:19 PM
Teleworking - Not ready for the whole organization at once!
Steve now is the time!      We have been talking about knowlege management for years.   Why are my 2 biggest tools during this time the telephone and email.  We have found out how much remote capacity was needed and we do not have enough for the whole organization to telework at once.  This is a time when one discovers who in your organization has adopted collaborative tools.   I plan to share this with others.

Thank you for the article.

 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
The Problem with Artificial Intelligence in Security
Dr. Leila Powell, Lead Security Data Scientist, Panaseer,  5/26/2020
GDPR Enforcement Loosens Amid Pandemic
Seth Rosenblatt, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5572
PUBLISHED: 2020-05-29
Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the product via unspecified vectors.
CVE-2020-5573
PUBLISHED: 2020-05-29
Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in the product via unspecified vectors.
CVE-2020-13693
PUBLISHED: 2020-05-29
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
CVE-2020-13173
PUBLISHED: 2020-05-28
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing...
CVE-2019-6342
PUBLISHED: 2020-05-28
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.