Are you prepared?The rise in terrorist attacks, power blackouts and catastrophic weather events, in addition to
new threats such as bird flu, has put the issue of business continuity firmly on the radar of
financial institutions. Jessica Twentyman investigates the readiness of the financial sector
Who would have thought that the discovery of a dead swan would cause so much consternation, not just in the remote Scottish village of Cellardyke where the bird was found, but right at the heart of UK government? Some years ago, the ensuing panic would have seemed farcical. But in April 2006, the prospect of a UK-wide bird flu pandemic suddenly seemed very real, and set off a chain of events with far-reaching implications. In the initial aftermath, a protection zone with a minimum radius of 1.8 miles was immediately set up around the village, while several hundred miles away in London, the Cabinet Office activated its emergency committee, Cobra.
In fact, the fear of bird flu ripping through Britain continues to haunt London?s financial services community. This year, the City is spending six weeks rehearsing for just such an emergency, which scientists believe could result in 10 per cent of the working population being off work for as long as three months.
Every Friday for six weeks starting on October 13, more than 60 organisations in the City will be asked by the tripartite authorities
? the Bank of England, the Financial Services Authority and the Treasury ? to react to a new scenario centering on a simulated bird flu pandemic. It is part of an exercise which the tripartite authorities hold annually. Last year, the Market-Wide Exercise, as it is called, focused on the scenario of a terrorist strike, testing civil contingency responses, financial markets and systems, media and US regulator enquiries. This year?s exercise will end on November 24. By the new year, the authorities hope to know how the City would cope with reduced staffing levels and the knock-on effect this might have on essential services such as transport, power and telecoms.
People issues
It?s a good time for the City to be focusing on such matters, says Ron Miller of Sungard Availability Services. ?The financial services sector has a fine pedigree in business continuity best practice, going right back to the early 1990s and the IRA attacks on the Baltic Exchange and Canary Wharf,? he says. ?But early efforts tended to focus on the continuity of information and systems. It took the events of the 7 July 2005 to get everyone thinking hard about the human element and how staffing levels and communications are equally vital to continuity.?
Indeed one of the key findings of the Market-Wide Exercise in winter 2005, according to Rick Cudworth, a partner at KPMG, one of the companies who staged it, was that financial services companies have an unfortunate habit of making too many false assumptions, particularly around civil authority actions and people-related impacts. ?It was evident, both through the planning and preparations for the 2005 exercise and during the event itself, that many organisations underestimate the extent of civil authorities? actions ? for example, the size of cordons and the length of time these may be in place,? he says.
Financial firms also tend to over-estimate how quickly they will receive information from the authorities. ?This latter point reinforces the need to continue to improve people-related responses within business continuity plans ? for example, staff welfare and communications, corporate versus individual responsibilities, and reliance on key individuals,? adds Cudworth.
When it comes to people-related responses, there are three primary business continuity cases that financial services organisations need to address in their planning, says Tim Furmidge, head of strategy and business development at BT Trading Systems. ?First, employees may be denied access to the building in which they work, as a result of a police cordon or transport problems. Second, they may lose access to on-site equipment, so that operations and communications lines are effectively lost. Third is the issue of quarantine ? a relatively recent issue but one that become a bigger consideration in the wake of SARs and current concerns about the HN51 strain of bird flu. The infrastructure itself may not be compromised, but people?s ability to work together at their regular site may be profoundly affected,? he says.
Information availability
But that is not to say that information availability issues should be allowed to slip down the agenda ? in fact, they are the bedrock of the new standard for business continuity recently issued by the British Standards Institution. The Publicly Available Specification (PAS) 77:2006 standard explains the principles and some recommended techniques for IT Service Continuity Management (ITSCM) and has been developed in partnership with Adam Continuity, Dell Corporation, Unisys and Sungard. It is intended for use by anyone responsible for implementing, delivering and managing IT Service Continuity within an organisation, according to the BSI, and aims to safeguard the performance of IT services, both before, during and after an incident.
?The impact of security breaches, power failures, environmental catastrophes, and ? worst of all ? increased terrorist activity extends far beyond the organisations immediately affected. A single incident at one organisation could quickly extend to its customers, partners and suppliers. As a result, every link in the value chain needs to implement business continuity strategies, and begin thinking more widely about information availability requirements,? says Sungard?s Miller.
This was certainly another lesson to come out of last year?s Market-Wide Exercise, which highlighted the need for more work to be done to identify ?supply chain? interdependencies. ?No organisation is an island,? explains KPMG?s Cudworth. ?The 2005 exercise highlighted that only limited communications occurred between financial organisations, with the majority focusing on internal communications and some contact with the tripartite authorities,? he says.
That lesson was brought home to Charles Hornung, director of IT at New Star Asset Management, back in 2004, when a security breach in its data centre resulted in the company?s email systems going down. ?What surprised us was that, during the downtime, we discovered that fund managers and employees relied heavily on many aspects of Microsoft Exchange ? diary and contacts were actually more important than email itself,? he explains. ?It was untenable to operate for 48 hours without full access to Exchange. In future, we decided, key applications such as email had to be available on demand to our 300 users.?
In the wake of the emergency New Star Asset Management implemented SteelEye Technology?s high availability and disaster recovery solution, LifeKeeper for Exchange, across four of its sites in Knightsbridge, London; Docklands, London; Dublin, Ireland; and Bermuda. The aim was to ensure complete disaster recovery for its Microsoft Exchange messaging and collaboration environment and this has successfully been achieved. ?Such is the impact of email downtime that we?ve done extensive testing, including my own personal acid test for business continuity ? unplug the email server!? jokes Hornung. ?We continue to conduct this test every year because, whatever the external incident, we know that our staff need email for us to keep going as a business.?
It will be interesting to see how the financial sector handles the bird flu pandemic test in the 2006 Market-Wide Exercise and if banks, insurers, trade bodies and other players in the market are as prepared to meet the human challenges of a pandemic compared to the technological and technical problems caused by blackouts or downtime. It is to be hoped that financial institutions can meet the continuity challenge.
Ten steps to effective business continuity
Forty per cent of companies that experience a significant interruption in operations go out of business within two years of the event, according to analysts at IT market research company Gartner. However, having an appropriate business continuity plan will help lessen the impact of these events and accelerate business resumption.
?Simply looking at the news headlines on any given day is a reminder of why companies need to put the necessary steps in place to ensure business continuity,? says Ken Horner, senior vice president of corporate strategy and development for backup and recovery software specialist BakBone. ?BakBone?s ten-step guide cuts through the confusion on how to implement a business continuity strategy by blending technology and business best practices to help companies individually tailor and successfully implement plans to protect their businesses.?
Step 1 ? Define strategy objectives by performing needs analyses and create a framework for strategy implementation
Step 2 ? Determine the business value of the organisation?s applications and define recovery objectives through data risk and recovery time profiles
Step 3 ? Match technologies for safeguarding data, including backup, disaster recovery, vaulting, snapshot and replication, based upon business value
Step 4 ? Define infrastructure and personnel plans, including organisational and communications processes
Step 5 ? Implement technologies and educate critical personnel as to which business processes are impacted
Step 6 ? Test the documented plan continuously and under different circumstances
Step 7 ? Measure and validate test results relative to the plan?s overall objectives
Step 8 ? Implement required enhancements that have been prioritised as a result of continuous testing and evaluation
Step 9 ? Continuously review and enhance the business continuity plan to reflect organisational changes, fluctuating business conditions and the addition of new technologies
Step 10 ? Finally, remember to repeat the entire process continuously.
http://www.fstech.co.uk/features/features2.htm
new threats such as bird flu, has put the issue of business continuity firmly on the radar of
financial institutions. Jessica Twentyman investigates the readiness of the financial sector
Who would have thought that the discovery of a dead swan would cause so much consternation, not just in the remote Scottish village of Cellardyke where the bird was found, but right at the heart of UK government? Some years ago, the ensuing panic would have seemed farcical. But in April 2006, the prospect of a UK-wide bird flu pandemic suddenly seemed very real, and set off a chain of events with far-reaching implications. In the initial aftermath, a protection zone with a minimum radius of 1.8 miles was immediately set up around the village, while several hundred miles away in London, the Cabinet Office activated its emergency committee, Cobra.
In fact, the fear of bird flu ripping through Britain continues to haunt London?s financial services community. This year, the City is spending six weeks rehearsing for just such an emergency, which scientists believe could result in 10 per cent of the working population being off work for as long as three months.
Every Friday for six weeks starting on October 13, more than 60 organisations in the City will be asked by the tripartite authorities
? the Bank of England, the Financial Services Authority and the Treasury ? to react to a new scenario centering on a simulated bird flu pandemic. It is part of an exercise which the tripartite authorities hold annually. Last year, the Market-Wide Exercise, as it is called, focused on the scenario of a terrorist strike, testing civil contingency responses, financial markets and systems, media and US regulator enquiries. This year?s exercise will end on November 24. By the new year, the authorities hope to know how the City would cope with reduced staffing levels and the knock-on effect this might have on essential services such as transport, power and telecoms.
People issues
It?s a good time for the City to be focusing on such matters, says Ron Miller of Sungard Availability Services. ?The financial services sector has a fine pedigree in business continuity best practice, going right back to the early 1990s and the IRA attacks on the Baltic Exchange and Canary Wharf,? he says. ?But early efforts tended to focus on the continuity of information and systems. It took the events of the 7 July 2005 to get everyone thinking hard about the human element and how staffing levels and communications are equally vital to continuity.?
Indeed one of the key findings of the Market-Wide Exercise in winter 2005, according to Rick Cudworth, a partner at KPMG, one of the companies who staged it, was that financial services companies have an unfortunate habit of making too many false assumptions, particularly around civil authority actions and people-related impacts. ?It was evident, both through the planning and preparations for the 2005 exercise and during the event itself, that many organisations underestimate the extent of civil authorities? actions ? for example, the size of cordons and the length of time these may be in place,? he says.
Financial firms also tend to over-estimate how quickly they will receive information from the authorities. ?This latter point reinforces the need to continue to improve people-related responses within business continuity plans ? for example, staff welfare and communications, corporate versus individual responsibilities, and reliance on key individuals,? adds Cudworth.
When it comes to people-related responses, there are three primary business continuity cases that financial services organisations need to address in their planning, says Tim Furmidge, head of strategy and business development at BT Trading Systems. ?First, employees may be denied access to the building in which they work, as a result of a police cordon or transport problems. Second, they may lose access to on-site equipment, so that operations and communications lines are effectively lost. Third is the issue of quarantine ? a relatively recent issue but one that become a bigger consideration in the wake of SARs and current concerns about the HN51 strain of bird flu. The infrastructure itself may not be compromised, but people?s ability to work together at their regular site may be profoundly affected,? he says.
Information availability
But that is not to say that information availability issues should be allowed to slip down the agenda ? in fact, they are the bedrock of the new standard for business continuity recently issued by the British Standards Institution. The Publicly Available Specification (PAS) 77:2006 standard explains the principles and some recommended techniques for IT Service Continuity Management (ITSCM) and has been developed in partnership with Adam Continuity, Dell Corporation, Unisys and Sungard. It is intended for use by anyone responsible for implementing, delivering and managing IT Service Continuity within an organisation, according to the BSI, and aims to safeguard the performance of IT services, both before, during and after an incident.
?The impact of security breaches, power failures, environmental catastrophes, and ? worst of all ? increased terrorist activity extends far beyond the organisations immediately affected. A single incident at one organisation could quickly extend to its customers, partners and suppliers. As a result, every link in the value chain needs to implement business continuity strategies, and begin thinking more widely about information availability requirements,? says Sungard?s Miller.
This was certainly another lesson to come out of last year?s Market-Wide Exercise, which highlighted the need for more work to be done to identify ?supply chain? interdependencies. ?No organisation is an island,? explains KPMG?s Cudworth. ?The 2005 exercise highlighted that only limited communications occurred between financial organisations, with the majority focusing on internal communications and some contact with the tripartite authorities,? he says.
That lesson was brought home to Charles Hornung, director of IT at New Star Asset Management, back in 2004, when a security breach in its data centre resulted in the company?s email systems going down. ?What surprised us was that, during the downtime, we discovered that fund managers and employees relied heavily on many aspects of Microsoft Exchange ? diary and contacts were actually more important than email itself,? he explains. ?It was untenable to operate for 48 hours without full access to Exchange. In future, we decided, key applications such as email had to be available on demand to our 300 users.?
In the wake of the emergency New Star Asset Management implemented SteelEye Technology?s high availability and disaster recovery solution, LifeKeeper for Exchange, across four of its sites in Knightsbridge, London; Docklands, London; Dublin, Ireland; and Bermuda. The aim was to ensure complete disaster recovery for its Microsoft Exchange messaging and collaboration environment and this has successfully been achieved. ?Such is the impact of email downtime that we?ve done extensive testing, including my own personal acid test for business continuity ? unplug the email server!? jokes Hornung. ?We continue to conduct this test every year because, whatever the external incident, we know that our staff need email for us to keep going as a business.?
It will be interesting to see how the financial sector handles the bird flu pandemic test in the 2006 Market-Wide Exercise and if banks, insurers, trade bodies and other players in the market are as prepared to meet the human challenges of a pandemic compared to the technological and technical problems caused by blackouts or downtime. It is to be hoped that financial institutions can meet the continuity challenge.
Ten steps to effective business continuity
Forty per cent of companies that experience a significant interruption in operations go out of business within two years of the event, according to analysts at IT market research company Gartner. However, having an appropriate business continuity plan will help lessen the impact of these events and accelerate business resumption.
?Simply looking at the news headlines on any given day is a reminder of why companies need to put the necessary steps in place to ensure business continuity,? says Ken Horner, senior vice president of corporate strategy and development for backup and recovery software specialist BakBone. ?BakBone?s ten-step guide cuts through the confusion on how to implement a business continuity strategy by blending technology and business best practices to help companies individually tailor and successfully implement plans to protect their businesses.?
Step 1 ? Define strategy objectives by performing needs analyses and create a framework for strategy implementation
Step 2 ? Determine the business value of the organisation?s applications and define recovery objectives through data risk and recovery time profiles
Step 3 ? Match technologies for safeguarding data, including backup, disaster recovery, vaulting, snapshot and replication, based upon business value
Step 4 ? Define infrastructure and personnel plans, including organisational and communications processes
Step 5 ? Implement technologies and educate critical personnel as to which business processes are impacted
Step 6 ? Test the documented plan continuously and under different circumstances
Step 7 ? Measure and validate test results relative to the plan?s overall objectives
Step 8 ? Implement required enhancements that have been prioritised as a result of continuous testing and evaluation
Step 9 ? Continuously review and enhance the business continuity plan to reflect organisational changes, fluctuating business conditions and the addition of new technologies
Step 10 ? Finally, remember to repeat the entire process continuously.
http://www.fstech.co.uk/features/features2.htm