Monday, December 31, 2012

Phone Data Back up anyone


This weekend I learned a lesson about working on my phone that I’m not likely to forget. My screen broke. The folks at Verizon swear I dropped it. But I know that unless someone came into my house while I was sleeping and swiped my phone off my night stand, dropped it on a concrete floor and put it back… it wasn’t dropped. But that’s irrelevant. I had no phone!

Wednesday, September 19, 2012

Sophos on a Rollercoaster




It appears that Sophos pushed out an update that has caused it to see software updaters (including its own) as malware infections.  This could be a wild ride – as thousands of computers world-wide are popping up warnings that they are infected and sending users into a panic. Network administrators are busy answering phones and trying to calm down users, while not able to get a line IN to Sophos, as all their lines are swamped.


Tuesday, September 11, 2012

Eleven Years Later - 9/11/01


I began my journey into the IT world in 1999. From the beginning I had my sights set on Information Security. In 2000 I was working for an IT services company and found myself encouraging my employer and our customers to consider information security and business continuity initiatives.

Monday, September 10, 2012

The Case For Putting Eggs in Multiple Baskets




Today hundreds of small businesses experienced web site outages. Go Daddy, the most popular domain registrar/web hosting company, saw its DNS servers attacked after 10AM Pacific time. The alleged attacker claimed to be working alone, to have taken down the entire Go Daddy DNS array and that he wanted to test the cyber security. DNS servers on the web are what translate the name of a web site (such as www.godaddy.com) to the numerical address assigned to it. Find a more detailed explanation of DNS here

Monday, August 13, 2012

You’ve Been Hacked?




Yes, it can happen. It’s almost inevitable. So what can you do to prepare for the discovery that your systems have been successfully compromised? What plans should you have in place for communicating with law enforcement? Do you collect financial information from your customers? If you do, you must have a plan in place for notifying them of a breach.

Tuesday, June 5, 2012

What The Heck is That?

So you decided to do an internet search on Business Continuity – and the sites you came across spoke a language you’ve never heard! As in any industry, the BC/DR community has its own jargon. Here’s a breakdown of a few terms used in the early planning stages.

Business Impact Analysis (BIA) is a term that is tossed around a whole bunch in reference to business continuity planning. The BIA is generally done at the beginning of the planning process and the plan is based around its information.  During the information gathering phase of the planning process, the Business Impact Analysis determines the processes, resources and assets that are necessary to the health of the business, how they depend on each other, and the criticality of each.

Recovery Time Objective (RTO) is determined for each process – how soon do we need this process up and running, and how soon do we need it at full capacity after an incident. In some cases, the RTO can be a staged process that might include temporary workarounds until all of the resources needed for the full process are restored. Perhaps your organization has a sales process that utilizes a rather large database. The database has an ordering system built into it so sales personnel can track what a customer purchases, how often the purchases are made, the quantities, and other information that assists them in the sales process. The IT department needs to know from the sales department how quickly their database needs to be back up if the servers hosting the database go down – and the sales department needs to know from the IT department how quickly it can be done. The gap between the two times then requires a plan to provide minimum service to the customers while the database is being brought back to full capacity.

Recovery Point Objective (RPO) is determined for data – how much data can we afford to lose? Is it one hour – or one week? The determination depends on how quickly your organization can rebuild the data that is lost. If you have a process that only gathers data once a week, then it will have a longer RPO than a process that has thousands of lines of data entered every day. For example – though your payroll process is important to getting the employees paid, it might only need to be run twice a month, and doesn’t change often in between. However, your sales staff communicates with 200 customers in a day, and places orders. The reconstruction of the sales database would require calling all of those customers in order to get their orders back. So a day’s data would set the sales department back a lot more than it would the payroll department, depending on when the failure occurred. Backups for the sales data would need to be done daily or more often, where backups for payroll would only have to be done as new data was entered.

An Incident is any unplanned interruption that has the potential to affect any business process. This can include anything from a major disaster to just a failed backup. Even though the backup might not be needed at that precise moment, there is still the possibility that it could affect a process.

These definitions will help sort out some of the information found on the web, and perhaps in the event you decide to hire a consultant, help you to begin to understand their explanation of their services.

Tuesday, May 15, 2012

The Living Plan


So you’ve put together a plan. Really. It’s that binder sitting on the shelf above your credenza. If anybody asks if you have one, you can point at it and say “yes, we have a plan!”