20-07-2024, 07:00 AM
The critical infrastructure are the servers.
As in all such systems, there are risks: it's up to those responsible to mitigate as many of the risks as possible (within your remit/budget) and then to quantify those risks remaining. These turn have to be signed off and accepted by senior management.
This process is a fundamental tenet of DR &BC (Disaster Recovery and Business Continuity) planning. DR is a different situation than BC - they are related but are very different things.
In this example, DR is how you get your infrastructure back on air; BC is how you keep the business operational in the interim.
I spent a lot of my career as a CTO for financial institutions and hedge funds with DR&BC central to my responsibilities. It's not an easy job as designing the processes needed requires a deep & fundamental knowledge of how the organisation works, plus continual refinement and testing. These are "living" processes - there is no "end" to a DR&BC project. There is also a full spectrum of how minor or severe an individual incident may be, both from a DR or BC perspective: the CFO is seriously ill (BC) or "there's a gas leak nextdoor and we have to evacuate the building" to "the office has burnt down" or "a bomb has gone off" - we were in the West End of London and both the gas leak and bomb scenarios happened, as did a 11KV underground substation fire coupled with a failure of a backup generator.
In the few times over 35 years I've had to execute (part of) such a plan, there have always been unexpected/left field events that have had to be handled in real time - you can't plan for everything, so have to be flexible and very quick thinking. You need a good team, good resources, authority and backing from the executive board as hard decisions may have to be made.
I had to plan for dirty bombs, pandemics, hacking, infrastructure failures, comms failures (roadworks breaking fibres etc.), utility failures, pandemics, strikes, fire, theft, heatwaves, floods, commercial risk (upstream supplier failures) etc. Plans have to workable and regularly rehearsed so everyone is aware of what to do when called upon. It's very very hard to do well.
As in all such systems, there are risks: it's up to those responsible to mitigate as many of the risks as possible (within your remit/budget) and then to quantify those risks remaining. These turn have to be signed off and accepted by senior management.
This process is a fundamental tenet of DR &BC (Disaster Recovery and Business Continuity) planning. DR is a different situation than BC - they are related but are very different things.
In this example, DR is how you get your infrastructure back on air; BC is how you keep the business operational in the interim.
I spent a lot of my career as a CTO for financial institutions and hedge funds with DR&BC central to my responsibilities. It's not an easy job as designing the processes needed requires a deep & fundamental knowledge of how the organisation works, plus continual refinement and testing. These are "living" processes - there is no "end" to a DR&BC project. There is also a full spectrum of how minor or severe an individual incident may be, both from a DR or BC perspective: the CFO is seriously ill (BC) or "there's a gas leak nextdoor and we have to evacuate the building" to "the office has burnt down" or "a bomb has gone off" - we were in the West End of London and both the gas leak and bomb scenarios happened, as did a 11KV underground substation fire coupled with a failure of a backup generator.
In the few times over 35 years I've had to execute (part of) such a plan, there have always been unexpected/left field events that have had to be handled in real time - you can't plan for everything, so have to be flexible and very quick thinking. You need a good team, good resources, authority and backing from the executive board as hard decisions may have to be made.
I had to plan for dirty bombs, pandemics, hacking, infrastructure failures, comms failures (roadworks breaking fibres etc.), utility failures, pandemics, strikes, fire, theft, heatwaves, floods, commercial risk (upstream supplier failures) etc. Plans have to workable and regularly rehearsed so everyone is aware of what to do when called upon. It's very very hard to do well.
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
ʞɔıu







