Latest news
Therefore, the start of any Business Continuity plan is a risk assessment. This does not need to be expensive to carry out. As a starting point, the head of each of the main departments of an organisation needs to be asked simple questions such as ‘What would it cost the company if you were unable to access your offices or computers?’ and ‘What would you need to do first to re-establish your department’s functionality subsequent to a disaster?’.
A risk matrix can be produced showing a list of potential disasters that could befall a company together with the probability of that disaster happening, graded as red, amber or green. The impact of the disaster upon the organisation would also be graded as red, amber or green.
Clearly, the probability of a specific disaster occuring and its impact will depend largely on the particular circumstances of the organisation, such as location and type of business. For example, premises located near a river potentially may be susceptible to flooding, whereas those located on a hill probably are not. Similarly, a manufacturing plant suffering a flood may well experience a greater impact to its business than a service business with a largely field-based workforce experiencing the same ‘disaster’.
These are simplistic examples and obviously there will be other considerations, but they do serve to demonstrate how significantly this assessment of risk can vary from organisation to organisation or even within the different business activities and sites of a single company.
A final column in the matrix shows the estimated potential loss of finance per day in the case of the specific disaster occurring. Look closely at any item which shows red/red - i.e. a high probability and your organisation. This matrix is a powerful way of convincing the board that a full Business Continuity plan is essential.
Once there is an agreement to continue with the production of the plan, then each department in the company must be examined in some depth, noting the ‘things’ that are used in the day-to-day running of the business. This would include any paper records such as contracts, client instructions, correspondence, etc., together with details of the computer systems that are essential to the business. Other points to note would include the number of people required to run the business and who these should be as it may be necessary to run for some time on a skeleton staff. For each of the essential items there must be a plan to restore it in the case of a disaster.
Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






