Posts

Showing posts with the label DCP

If a business continuity exercise is too hot to handle

Image
Full-on business continuity exercises can be big, intimidating, lengthy, costly (although hopefully still valuable!) and (to some extent) risky affairs for complex organisations or industry groups that really go to town on them ... but that's not the only way. Alternatives include: Solitary plan review/maintenance update - where the person responsible for a particular part of the whole plan (such as a section or department head) sits quietly in a dark corner imagining how things would play out in practice, carefully checking their part, liaising with colleagues as appropriate ( e.g . on interfaces, coordination and reporting), taking advantage of their knowledge of that part of the business and any results from previous checks, working within the constraint of agreed strategies, policies and objectives .

Crowdstrike - post-incident review: a dozen learning points

Image
I blogged about the Crowdstrike incident on July 21st  while it was still playing out. Now, having  d rained the swamp and let the d ust settle, I'm  d ue to d raw out, d econstruct and d ecide what to d o about the Crowdstrike d isaster, so here goes: Design, build and test systems for resilience, where 'systems' means not just IT systems but the totality of interdependent technologies, organisations, people, information flows and other resources necessary to deliver and support critical business activities. Hinson tip : "be prepared" is not just for  boy scouts ! Those dependencies are p otential p inch p lus  p ain p oints. Test software before release. Sounds easy, right? It isn't. There is an infinite amount of testing that could be performed, only a fraction of which realistically should be, while the amount and quality of testing actually performed is resource-constrained and time-boxed for business and uncertainty (risk!) reasons (delaying secu...

An evolutionary revolution?

Image
"Mitigation and adaptation are required together to reduce the risks and impacts of climate change, including extreme weather events. Mitigation refers to actions taken to limit the amount of greenhouse gas emissions, reducing the amount of future climate change. Adaptation refers to actions taken to limit the impacts of a changing climate. Mitigation and adaptation together provide co-benefits for other environmental and social goals." That paragraph by Lizzie Fuller, Climate Science Communicator for the UK's Met Office, plucked from another excellent digest of lessons learned from various UK resilience exercises and initiatives , obviously con cerns climate change ... but it occurs to me that 'mitigate and adapt' might be a novel approach to information risks and impacts as well.

A nightmare on DR street

Image
A provocative piece on LinkeDin by Brian Matsinger caught my beady eye and sparked my fertile imagination today. I'm presently busy amplifying the disaster recovery advice in NIS 2 for a client. When I say 'amplifying', I mean generating an entire awareness and training piece on the back of a single mention of 'disaster recovery' in all of NIS 2. Just the one. Blink and you'll miss it. Oh boy. Anyway, Brian points out that recovering from disasters caused by 'cyber attacks' requires a different DR approach than is usual for physical disasters such as storms, fires and floods. Traditional basic DR plans are pretty straightforward: essentially, the plans tell us to grab recent backups and pristine systems, restore the backups onto said systems, do a cursory check then release services to users. Job's a good 'un, off to the pub lads.

Mil-spec management lessons

Image
  "A calamity can often strike without warning. Whether it be generated by humans or a natural disaster, leaders need to be ready to direct their teams in the aftermath. In order to be ready for crisis, leadership skills, like any others, must be practised over and over beforehand. So the way you lead in the quiet times helps to build the skills you need when you have to dig deep." That paragraph plucked from this month's impressive  NZ Airforce newsletter  about the military response to the devastating flooding caused by cyclone Gabrielle here in Hawkes Bay caught my beady eye this morning.  The idea of practicing incident management as well as incident handling or operations  on relatively small incidents makes perfect sense.

BCM for WFH

Image
Since home and mobile workers rely on IT to access critical business systems and corporate data, and to communicate with others, organisations need a robust IT network infrastructure that extends to workers' homes or wherever they hang out. If, in reality, the infrastructure turns out to be fragile and unreliable, business activities are likely to be equally fragile and unreliable, leading to frustration and grief all round. In other words, the extended IT infrastructure is quite likely business-critical. W orking F rom H ome or on the road can increase various information risks relative to conventional office-based work, due to factors such as: Use of cloud computing services*; Workers using their own or shared devices and internet connections for work purposes, raising questions about their suitability and security, ownership of and access to any intellectual property or personal information on them;

The TEN controls ISO/IEC 27002 missed

Image
Despite the excellent work done to restructure and update the standard, I still feel some commonplace 'good practice' information security controls are either M issing I n A ction or inadequately covered by ISO/IEC 27002:2022 , these nine TEN for example: Business continuity controls, covering resilience, recovery and contingency aspects in general, not just in the IT security or IT domains. ISO 22301 is an excellent reference here, enabling organisations to identify, rationally evaluate and sensibly treat both high probability x low impact and low probability x high impact information risks (the orange zone on probability impact graphics), not just the obvious double-highs (the reds and flashing crimsons!). Therefore, '27002 could usefully introduce/summarise the approach and refer readers to '22301 and other sources for the details. Availability and integrity controls supporting/enabling the exploitation of high-quality, up-to-date, trustworthy business information a...

Managing certainty

Image
'Reducing uncertainty' is the prime focus of  information risk management today. We do our level best to identify, characterise, quantify, evaluate and where possible reduce the probabilities and/or   adverse consequences of various possible events.   Uncertainty is an inherent part of the problems we typically face. We don't know exactly what might happen, nor how or when, and we aren't entirely sure about the consequences. We worry about factors both within and without our control, and about dependencies and complex interactions that frustrate our efforts to predict and control our fortunes. We adopt fallback and recovery arrangements, and apply contingency thinking with the intention of being better prepared and resourced for unanticipated situations ahead.     A random comment on LinkeDin set me thinking about the converse: 'reducing uncertainty' is the flip side of 'increasing certainty', in other words information risk management is equally about...

Book review: The Resilient Enterprise

Image
Just a brief note today: it's a lovely sunny Saturday morning down here and I have Things To Do . I'm currently enjoying another book by one of my favourite tech authors: Yossi Sheffi's The Resilient Enterprise *. As always, Yossi spins a good yarn, illustrating a strong and convincing argument with interesting, relevant examples leading to sound advice. Specifically, I'm intrigued by the notion that major incidents/disasters leading to severe business disruption may not come "out of the blue". Sometimes (quite often?), there are little warning signs, hints ahead of time about the impending crisis, chances for alert business people to look up from the daily grind and perhaps brace for impact. It ought to be possible to spot fragile supply chains, processes, systems and people, provided we are looking out for them ...    Here in NZ at the moment, we are being treated to a public safety campaign using the analogy of meerkats, encouraging Kiwis to be constantly o...

What is "operational resilience"?

Image
Seeing the term 'operational resilience' being bandied about right now, I thought I'd take a closer look, starting with the definitions. So what is 'operational resilience'?   It is: " a set of techniques that allow people, processes and informational systems to adapt to changing patterns. It is the ability to alter operations in the face of changing business conditions. Operationally resilient enterprises have the organizational competencies to ramp up or slow down operations in a way that provides a competitive edge and enables quick and local process modification." says Gartner . " both a process and a characteristic of an organization to adapt rapidly to changing environments and needs. It is an organizational trait that allows it to carry out its mission or business despite the presence of operational stress and disruption. In other words, it is the organization's ability to handle and control external factors that may hinder it from function...

An appetite for risk

Image
Today we've been chatting about this on the ISO27k Forum :  "Let's assume that the company is willing to accept risks with a potential financial impact less than $50k. Obviously after performing risk assessment, we need to decide which treatment option we should follow. In case when the potential impact of the risk is below $50k - (risk appetite), we should accept the risk, right?    My question is: what happens if for some reason, multiple Low Risks (below risk appetite value/already accepted) occur at the same time? Should the Risk Appetite represent an aggregation of all low risks or just reflect the appetite for a single risk?" I suggested considering 'coincident risks' as another entire category or class of risks, some of which may well be above the risk appetite/acceptance threshold even if the individual risks fall below it.  It gets worse. There are many other coincidences, errors, failures, issues and exceptional circumstances that could occur - in e...

The day the Earth stopped spinning

Image
Here's something we don't see very often, well for no more than a fraction of a second, normally, discreetly tucked away at the bottom left corner of the browser window. Today was different. Today the message was there long enough for me to grab that little screen shot. Meanwhile, I had to wait s e v e r a l l   o   n   g m i n u t e s for the Google search results to appear.   Minutes I tell you, minutes! Several of them! Shock! Horror!  My little world stood still for a moment, my online life on hold. In an instant, I realised that not only have we grown accustomed to near instantaneous access to Google's gigantic Web catalogue, but that I am actually quite dependent on it. I do sometimes use other search engines but I always scurry back to Google because it works well, almost always. The only reason I am bloggering on about it here is that a Google service failing is so unusual, exceptional in fact. Almost unheard of.   The techn...

March 26 - NZ lockdown day 1 of N

Image
From midnight last night, New Zealand is now at civil emergency "stage 4", which means all except essential services personnel are supposed to stay isolated at home for about a month. The official NZ government list of essential services appears to have been finalised and published hastily. Naturally, 'the authorities' consider themselves essential as overnight we've become a police state: police and courts are working through the lockdown, albeit providing limited services, health and immigration/customs services too. What will happen as their workers are or suspect themselves to be infected with coronavirus is unclear at this point. Presumably they have contingency plans, plus controls to limit the spread of infection within police stations, court houses, hospitals, customs halls, mail sorting offices etc.  ... but staffing and service problems are entirely possible as the lockdown continues. Since they aren't entirely self-contained , there's also a se...

March 20 - COVID-19 PIG update

Image
Here's today's update to my COVID-19 information risk P robability I mpact G raphic: I've slightly shifted and revised the wording of some of the risks but there's nothing really new (as far as I know anyway).  Reports of panic buying from the UK and US are concerning, given the possible escalation to social disorder and looting … but hopefully sanity will soon return, aided by the authorities promoting “social distancing” and “self-isolation”.   Meanwhile, I hope those of you responsible for physically securing corporate premises have appropriate security arrangements in place. Remotely monitored alarms and CCTV are all very well, but what if the guards that would be expected to do their rounds and respond to an incident are off sick or isolated at home? Do you have contingency arrangements for physical security? ‘Sanity’ is a fragile condition: there is clearly a lot of anxiety, stress and tension around, due to the sudden social changes, fear about the infectious dis...

March 17 - COVID-19 BCM

Image
From my narrow perspective as a practitioner, manager and consultant in the field, some 20-30 years ago, B usiness C ontinuity P lanning revolved around  IT D isaster R ecovery which generally involved (at the time) either powering up an alternative data centre or hiring a few servers on the back of a truck and plugging them in to restore services taken out when the data centre was flooded/burnt.   It was almost entirely IT focused, expensive, and could cope with very few disaster scenarios (there still had to be somewhere for the truck to park up and plug in, while the backups to be restored had to have survived miraculously, plus of course the rest of the organization - including the alternative data centre plus the people and associated essential services). From that primitive origin, BCP started to get better organised, with scenario planning and tabletop exercises, and actual 'management' instead of just 'planning' - leading to B usiness C ontinuity M anagement. ...

March 14 - COVID-19 information risk update

Further to yesterday's assessment of the information risks associated with the coronavirus pandemic and the discussion arising, here are a few more aspects. An increased number of knowledge workers are now working from home, some of them for the first time. What equipment and services are they using? What are the information risks and security arrangements? Who knows? Larger organizations tend to have in place suitable policies plus structured, systematic approaches towards home and other off-site working, with controls such as management authorization, remote security management of end user devices (corporate or BYOD), VPNs, network security monitoring, network backups, automated patching, antivirus etc.  Hopefully they have all scaled easily to cope with the changing proportions of off-siters. Medium and especially small organizations, however, may be less well prepared ... and all of them are likely to be feeling the strain of changed working practices and social interaction. T...

Just-in-time security awareness

Image
This afternoon, we completed, proofread and published a security awareness module on malware, a few short hours before our (self imposed!) end-of-month deadline.  The atmosphere in the office has grown increasingly tense this week as the deadline loomed. Early in January we took the decision to use the Travelex ransomware incident as a very topical (live!) case study for the module, and as such we were hostage to their timeline. By sheer chance, the main Travelex websites were up and running again this very morning, neatly tying off the month's events. Comparing and contrasting the Sony and Travelex ransomware incidents has been fascinating: they each handled the situations in their own way, and yet there are common themes - for instance they were both forced to fend off an inquisitive (hostile!) pack of journalists. Travelex also made effective use of social media, and completed the main part of their recovery roughly twice as fast as Sony, so things have moved on in the five...

Taking it to the wire

Image
Today since before 5am I've been slaving away over a hot keyboard in a steamy hot office on a flaming hot topic: malware awareness.  As you may have noticed here on the blog, all month long I've been systematically tracking the ongoing Travelex incident, observing from a safe distance the unsightly aftermath of another ugly malware - and business continuity - incident unfolding before our very eyes. With our end-of-month delivery deadline looming large, it's time to draw out the lessons from the case study and weave the whole episode into a compelling tale for February's awareness module - well, three closely-related tales in fact since as always we're catering for the differing perspectives, concerns and information needs of our customers' staff, management and professional audiences.  What have we learnt this month?  What has happened, and why?  What do we think might/should have been going on behind the scenes, out of the glare of the media spotlight? What we...

MD/CISO's question time

Image
Seems I'm not the only ravenous shark circling the Travelex ransomware incident. Over at the Institute of Chartered Accountants in England and Wales website , Kirstin Gillon points out there are learning opportunities for senior management in this "horror story". Specifically, Kirstin suggests posing six awkward questions of those responsible for managing incidents and risks of this nature ... Rhetorical questions of this nature are not a bad way to get management thinking and talking about the important issues arising - a valuable activity in its own right although it falls some way short of taking decisions leading to appropriate action. Admittedly, there's an art to framing and posing such questions. Kirstin's questions are along the right lines, a good starting point at least. Faced with such questions, some Boards and management teams will immediately 'get it', initiating further work to explore the issues, evaluate the risks and controls more deeply,...