infoTECH Feature

August 07, 2012

Effective Disaster Recovery: Understand the Threats. Prioritize Your Plan

By TMCnet Special Guest
Curtis Paradzick, Vice President of Sales, Vector Resources, Inc.

Your business is located in an area that doesn’t get a lot of rain or snow and isn’t prone to hurricanes or tornadoes. You haven’t had a blackout in years and you’ve implemented an aggressive “defense-in-depth” security infrastructure to protect critical network assets. Why would you need to spend more time and resources on a disaster recovery program?

Congratulations on the foresight, planning and hard work you’ve put into your current infrastructure. But, the optimal protection of your network assets is a constantly moving target. It takes just one freak windstorm, accident by a utility or highly-intuitive hacker to bring your data infrastructure to its knees.

To help you take your data protection plans one step further, I’d like to offer several tips gleaned from dozens of projects Vector has completed.

1.            Understand the Threats, Prioritize Your Plan

Organize potential disasters in an order that makes sense for your organization. One example would be to categorize potential disasters by size and scope. Natural disasters, for example, can have a devastating impact on entire geographic regions and therefore your company’s disaster recovery plan would likely include much more than simply restoring business-critical systems. More localized threats to your business, such as temporary power outages, or hacker intrusions, should be prioritized and planned for in a very different way. Technical failures, such as the phone system failing, would be yet another category. The important thing is to work with your executive team to identify these threat categories, prioritize your plan for each, and allocate budget and resources accordingly.

2.            Organize Your Disaster Recovery Efforts

Disaster recovery efforts should include three types of activities: prevention, identification and repair/continuity. Preventive efforts include activities such as ensuring multiple types of solutions at each layer of your defense in depth; e.g., multiple antivirus solutions to ensure you’ve covered against the widest range of threats. It can also include physical prevention, such as installing a back-up generator, deploying a burglar alarm system and arranging for an off-site back up of key systems and services. Identification methods consist of activities such as employee training sessions, and updated identity and authentication management. Repair/continuity activities will concentrate on restoring your network speed, data bases and services to pre-disaster conditions. This might include having hot sites (alternate facilities) where your employees can work, to insurance policies that allow you quick access cash to purchase new equipment.

3.            Address Data Loss

Networks can lose data without a disaster occurring. File system corruption, storage/server failure and accidental/purposeful deletion of files by employees all lead to data loss. Proper data backup either onsite and/or offsite can allow for easy restoration of lost data. When retaining an outside vendor to handle offsite back up, make sure to ask a few essential questions including: What systems does this third-party have in place to prevent their own disaster-related data loss? What is the validity of the data you wish to back up? Who will have access to the data? How and how often is the backup occurring? And, what happens if the vendor loses your data?

4.            Develop Communications Strategies for All Key Audiences

For each disaster scenario identified in Step #1, determine how and with what frequency you will communicate with all key audiences. In addition to employees, this includes customers, partners, vendors, neighboring companies and local authorities. If you operate in a regulated industry, include regulators in your communications plan.

5.            Understand the Disaster Recovery Plans within Your Value Chain

Just as a disaster at your organization affects your partners and vendors, disasters at a partner or vendor affect you. Your customer doesn’t care if your partner’s network was hacked, all they care about is on-time delivery of the products you’ve promised them and if your partner exposed proprietary data about the customer to cyberthreats. Learn about and where possible, coordinate your disaster recovery efforts with theirs.

6.            Understand Your Customers’ Disaster Recovery Plans

Similarly, data about your products, intellectual property and financial information may reside within your customer’s network. If a customer requests sensitive information about your company, it’s fair to ask how the customer plans to protect that information.

7.            Think about the Long Term

Many organizations have disaster recovery plans in place that will tide them over a few days or a couple of weeks. But what happens if there’s a major disaster and you’re not able to use your facility, network or other infrastructure for two, three, four months. These long-term problems should be part of the scenario analysis conducted in Step #1.

8.            Test Your Plans

No first pass at a disaster recovery plan will be perfect and include all possible scenarios. Testing your plans is the only way to find the holes and plug them prior to a disaster. The more thorough and detailed the testing, the better. It’s especially important to involve your partners and vendors whenever possible, and the most impactful their business continuity is on your ability to serve your customers, the more aggressively you should encourage their involvement.

9.            Invest in Best Practices

IT teams within some organizations don’t have in-depth knowledge of disaster recovery and business continuity best practices. Within many companies today, information is among the most important assets. Management has a fiduciary responsibility to ensure this information is safeguarded. Inviting consultants that specialize in disaster recovery to review current practices and recommend improvements is well worth the investment.



Want to learn more about the latest in communications and technology? Then be sure to attend ITEXPO West 2012, taking place Oct. 2-5, in Austin, TX. ITEXPO (News - Alert) offers an educational program to help corporate decision makers select the right IP-based voice, video, fax and unified communications solutions to improve their operations. It's also where service providers learn how to profitably roll out the services their subscribers are clamoring for – and where resellers can learn about new growth opportunities. For more information on registering for ITEXPO click here.

Stay in touch with everything happening at ITEXPO. Follow us on Twitter.




Edited by Brooke Neuman
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers