Disaster Planning With a Business Continuity Plan (BCP)

Your business may be a thriving placeEven if your company is located away from the
experiencing consistent growth. During thesecoastline and the potential for hurricanes, your
times of growing revenue and increasing profits, itlocale could be vulnerable to a catastrophic event,
may seem like nothing could go wrong. Of course,particularly if you are located in a large
assuming such an attitude is naïve, as everymetropolitan area that attracts a lot of tourists.
savvy businessman knows. Whether yourOther geographic locales can be prone to specific
business is booming or going through andisasters. If you are located near a desert, your
adjustment period, it's highly recommended youarea could be prone to choking dust storms,
strategize and create a business continuity plan. Ifrivers regularly flood and mountainous areas are
your business doesn't have a formal plan in place,prone to avalanches. Perhaps you live near an
it's time to create one.earthquake fault line. The disaster potential of
A BCP (Business Continuity Plan) provides awhere you live is important so that you can plan
framework for ensuring business operations runaccordingly for business continuity.
regardless of virtually any possible or unforeseenThe types of disasters that create a business
event occurring in your absence. Within the plan,disruption are in the thousands. Disgruntled
critical business operations are identified that,employees seeking to sabotage the company
should there be a disruption, would havepresent a risk for business disruption. In particular,
devastating consequences on your business. Aa disgruntled IT employee who has access to
priority is made to keep these businessyour most sensitive data and business-critical
components running and, should a disruption occur,operations could have a devastating effect with a
a BCP defines (in order of priority and chain offew clicks of the mouse. Other employees,
command) how to keep your business fullylocated in various departments of your company,
operational while minimizing downtime.may steal computer equipment. Besides the
Critical technology components consist of allmonetary loss of the physical piece of equipment,
assets (including people) used to facilitate coreif the hardware included sensitive files or a critical
business processes, as well as applications thatbackup files, the potential to disrupt business
support employee productivity and IToperations is magnified.
infrastructure that manages these criticalRegardless of the event, communications failures
applications throughout your company.can create revenue losses. Typically,
The degrees of impact of core businesscommunications lines are down when power lines
processes going down must also be considered inare down, but not always. How would
a well-developed BCP. Consider the far-reachingcommunications occur at your business if the
costs of an essential process going offline. Forprimary method of communications failed?
example, your firm may use an accountingHardware crashes can also prove detrimental.
application that produces daily financial reports forMost often, these happen as hard-drive failures
clients. On one level, the only employees affectedwhere data becomes inaccessible, but information
are those kept idle by not being able to use thetechnology always has a potential for failure.
application. However, should the network go downLocating the origins of what caused an actual
when company management is set to attend afailure can consume a lot of time.
board meeting, without essential financial reports,A catastrophic network failure can have a huge
the consequences become significant.impact on your business. Preparing for one is
Applications that enhance productivity have aessential to recover from such an event. Network
different impact on business operations. Customertools must be in place, and used, to offset the
contacts may be kept in a certain database. Howpotential for unforeseen network failures. Viruses
are they kept without this database? If thepenetrating your internal network can bring about
solution is pen and paper, the potential is high forhardware failures, bring down communications or
critical business contact information to be lost. In apotentially create a catastrophic failure of the
different perspective, if your business relies onnetwork.
the Internet to establish business contacts aroundOf course, disasters don't have to be dramatic to
the world and the Web site crashes, thecause serious downtime for your company.
recovery effort becomes impossible because theBrownouts often occur during the summer
information was never retained in the first place.months when demand for power is at a
Be sure to keep vendor contact informationmaximum. Temporary power outages can also
backed up and accessible so vendors can beoccur during traffic accidents involving a
contacted in the event of a disaster. Establishtransformer. Without auxilary power, your critical
contacts that can assist you in the disasterIT processes are not functioning. It is essential to
recovery effort, including off-site backups ofplan for these occasions should they occur; even
critical business files, fuel suppliers for on-siteif you don't perceive it as likely.
power generation and proper insurance coverageMany companies don't understand the actual costs
information.involved with disrupted business operations until
Not only must a BCP be in place at your business,they become very real after the fact. To
employees must also understand the recoveryunderstand how these costs add up, you must
process should the need arise. It is essential thatconsider costs both tangible and intangible. Tangible
your company document policies that addresscosts are the quantifiable ones directly associated
BCP objectives. Take the time to communicatewith the downtime such as lost production, idle
BCP objectives during orientation and remindhourly employees, lost revenues and costs
employees of BCP objectives annually duringassociated with recovering data losses.
yearly employee performance reviews. As theTo attach specifics to these costs, understand
BCP objectives change, it is critical to keep staffthat the average hourly rate for a professional
informed.employee in the United States is approximately
Your BCP will contain RTOs (Recovery Time$42 USD per hour. Take that figure and multiply it
Objectives) that define the critical time periodby the number of employees at your firm, and
during which business functions must be restored.you have one of the tangible costs of downtime.
Should critical business process remain offline pastKeep in mind, this is but one cost, and it's per
this time window, you face disastroushour, so the tab is running.
consequences at your company. This timeIntangible costs are much more difficult to
window has progressively shrunk with thequantify and too often, these are the causes that
development of technology that enhanceskeep a business from ever opening its doors
business operations.again. These are the lost opportunities your
Employees should know in advance theirbusiness had because the doors were closed. Has
responsibilities in the wake of an unforeseenyour business reputation been damaged? Have
event. Also, specific employees should be selectedyou lost customer loyalty? What are the costs
to communicate contingency plans should theassociated with replacing your best employees?
need arise. The fact is your business is onlyWith all the talk of gloom and doom, hopefully the
capable of the cumulative total of the workpoint has been made: Your business needs a BCP.
effort put in by staff and the technology thatYour BCP should include steps that minimize
supports your business architecture.downtime. Here are five smart tips to help you
Before the advent of the Internet, businessesachieve that goal:
often defined RTO as a period of three days." Define and document an emergency response
Now that the Internet is a primary means ofpolicy. This includes the definition of the chain of
communication for many businesses, RTOs arecommand at your company and how
often defined in seconds and minutes. Define thiscommunications are carried out.
figure by attaching a monetary value to the cost" Define and document a contingency plan for
of the critical business processes going offline andemployee communications should the primary
what that loss would mean to your company.means become inaccessible. How would you keep
Keeping the need for BCP in mind, it is importantcritical communications flowing if your
for the reader to ask themselves these questions:communications network was destroyed? If
" If your office space was destroyed in atraditional communications are down, critical
disaster; do you have the proper steps in place toemployee data such as contact information must
recover from this situation?be accessible should the need arise.
" Do you have a contingency plan in place to" Develop a plan to handle business inquiries in the
recover from a significant loss of employees dueevent of a disaster. A server virtualization
to a disaster or pandemic?strategy can provide essential backups offsite in
" What is your contingency plan and where can itthe event your physical office has been
be found offline?destroyed. Provide updates on the company Web
" Do you have a clearly defined chain ofsite about what is happening locally.
command at your company and do you" Consider the dimensions of IT capacity at your
coordinate communications?business and develop redundancy in your critical
Business may be booming and the potential forsystems. Maintaining off-site backups is essential
disaster may be minimal, but don't let that senseto keeping these mission-critical applications
of security keep you from developing a BCP. Iffunctioning. Consider mirrored off-site data
you can't clearly answer the questions above,redundancy located off-site from your primary
then you don't have a plan in place that wouldbusiness operations.
keep your business functioning following a disaster." Regularly review the BCP, making changes and
Businesses throughout New York City were givenupdates when necessary. A BCP is dynamic and
a rude reminder of the need for a BCP followingevolves with your business. Establish quarterly
the 9/11 disaster, as were businesses throughoutbusiness reviews of the BCP to keep it in line with
the Northeast following the devastating blackouttechnology enhancements at your firm. Be sure
that left one-seventh of the United Statesto train IT staff on the recovery process and
population without power on August 14, 2003.don't depend on a core group to carry out the
We were all reminded of the potential for aplan. Backup employees must also be trained on
catastrophic disaster when Hurricane Katrina hitthe process should the primary employees
New Orleans in 2005. Total monetary losses havebecome unavailable.
soared well over $200 billion. Of this total, theToo often the lessons learned from the lack of a
greatest sum can be attributed to businessBCP occur when a disaster strikes. However,
disruptions when facilities were damaged andthese lessons have been well documented and
destroyed, and employees were displaced for anyour business can learn from these examples to
extended period of time. The Katrina disasterprepare for such an occasion. The key is to not
provides the best example for Americans toallow your business to become a statistic on
understand the need for a business contingencydisaster unprepared ness, but one that continued
plan. Could your business continue after such aits operations after a devastating catastrophe.
catastrophe?