drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

Thinking About Cyber … What’s Different When Compared to ‘Normal’ Business Continuity and Disaster Recovery?

Business Continuity ManagementCyber Resilience & IT Disaster RecoveryData Protection: Backup & RecoveryResilience Strategy & Program Maturity

I don’t think it’s necessary to convince anyone the threat of a cyberattack is real. As most experts warn, it’s not if, but when an organization will be successfully attacked. As such, considerable work has taken place to help shore up gaps in security, but the threat continues to evolve.

As business continuity professionals, it’s our job to advise and/or build solutions to help our organizations successfully respond, recover, and return to normal as quickly as possible following a disruption. Responding to a disruption caused by a cyberattack is no different, we need to help our organizations prepare.

So, how do we do it? When it comes to cyber response, what’s similar to how we prepare for disruptions caused by other threats? What’s different? I not only reflected on my experiences, but I talked to many different information security and business continuity professionals to get their perspective on the answer to these two questions. Summarizing the similarities and the differences regarding preparedness for cyber versus other threats is the purpose of the article.

Background or Disclaimer

I need to clarify the last sentence in the introduction above. I never advocate for planning – or creating plans – for specific threats. Rather, I think it’s incredibly important to prepare for four or five different scenarios:

1. Loss of people (absenteeism)

2. Loss of the workplace

3. Loss of equipment

4. Loss of information technology and information

5. Loss of third parties/suppliers

With that said, I value different forms of research, such as the BCI’s Horizon Scan, because it serves as a reminder of the different causes, or threats, that could lead to a disruption caused by one of the five scenarios above. Considering different threats helps to stress test the validity and completeness of the different strategies and solutions which an organization employs to successfully respond and recover once one of these scenarios occurs.

So, where does cyber fit? In my opinion, it’s a combination of at least three of the five loss scenarios I noted above. People may be unavailable because they can’t perform their assigned tasks, their equipment (PCs, laptops, tablets, or equipment controllers) may be unavailable, or their applications and data repositories are corrupted or unavailable.

Based on this background, let’s explore the similarities and differences between cyber response and recovery and “normal” business continuity/IT disaster recovery. However, you might not agree with a few items in each of my lists, but I’ll do my best to explain!

What’s Different?

Let’s start with the list of what I believe are the differences.

The Resource(s) Affected

Here’s an important difference.

The cyberattack in question could affect the application, data, and the resources used to access the application and data.

As such, the need for manual workarounds and alternate procedures includes such procedures for the loss of the application functionality, the loss of access to information, and the loss of the device used to interact with the application and data.

Solution – Review your existing manual workarounds and alternate procedures and look for gaps. Do they exist, and are they dependent on resources such as laptops and PCs which may be unavailable? In other words, are your manual workarounds truly manual?

Clarity on the Cause of the Disruption

Anyone who’s experienced a cyberattack can attest that it’s not always clear that you have a cyber incident that’s causing the disruption. And even worse, it’s not always clear what type of a cyberattack has taken place, when the attack originated, or even the root cause.

Solution – Having a strong cross-functional team trained to perform a wide range of situational assessments is key, including but not limited to cyber-related issues.

Pre-Recovery Dependencies

The response to a cyberattack often requires a few actions prior to beginning the recovery effort.

For example, the organization will often need to identify and remediate the security exposure before recovery can begin. This need is often the excuse most commonly used when a recovery time objective (RTO) or recovery point objective (RPO) is missed (more on that in a few minutes).

Another difference related to pre-recovery dependency is the need to pre-identify (before the attack) expert resources to assist with identifying the security exposure and where/when the attack occurred.

Solution – Identify the right resources – internal and possibly external to the organization – which can help with diagnosis, containment, remediation, and forensics.

The Technical Recovery Strategy

This article isn’t intended to be a technical overview of the solutions available to protect applications and data when faced with a wide range of cyber threats.

But the important thing to recognize is that the solutions are often different than those used in response to a traditional data center loss, or the loss of an application hosted in the cloud.

Solution – Be intentional about identifying appropriate cyber protection and cyber recovery procedures that meet management-approved RTOs and RPOs. Assess gaps in preparedness and coordinate with the architects in your organization to identify the gaps, recommend solutions, and prioritize their implementation.

Crisis Communications Strategy

Crisis communications during cyber response can be very different.

For example, some of the resources you depend on to communicate with your employees and customers may be unavailable. That’s not so different from “normal” business continuity.

But here are two very significant differences:

First, the timing of your crisis communications messaging may need to change. It might not be appropriate to quickly communicate. The need to slow information dissemination may be critical to the response and recovery effort (and subsequent prosecution of the attackers).

Related to this point, the level of transparency may be far different. Unless the attack could spread to others (meaning connected customers and business partners), or unless there are data privacy implications, the need to quickly explain the root cause of the disruption may be unnecessary early on in the response. Consider the need to provide details regarding the cause and instead focus on issue, proactively promising to provide more detail on the root cause following the successful recovery effort.

Solution – Be intentional in how you communicate following a cyberattack and recognize the communications differences. Exercise this crisis communications scenario.

The Decisions Which Need to Be Made

We read about this all the time in the news. Should the organization pay the ransom to get the key to unlock their data following a ransomware attack?

Another decision which needs to be made is how far back we should go in recovering data when we’re not completely sure when the attack took place.

Some of the decisions which management will need to make aren’t pretty or precise. Your management team may not have all of the information on policy, precedent, or the attack when preparing for remediation and recovery. Help them be prepared for such occurrences by exercising their decision-making, especially with incomplete information.

Are there internal policies governing such decisions, especially ransom payment? What does your insurance carrier think about some of these issues if your organization will eventually seek a claim? Work to understand the answers to these in advance.

Solution – Similar to the crisis communications point above, be intentional and roleplay via exercises. Identify the questions which can be answered now and include this information in exercises. Capture the results in your plan so all participants understand the outcomes.

Generational Considerations

I promise this isn’t a rant about Baby Boomers versus Gen X versus Millennials.

But the point I’m about to raise is a real lesson learned for many organizations. Not everyone knows how to work without technology! Newer employees weren’t around when “paper and pencil” processes were still in use.

Solution – Train employees on the use of manual workarounds (without PCs, laptops, tablets, etc.), including the use of alternate sources of data. Document lessons learned and continue to refine these manual workarounds over time.

Before moving on to what’s not different, here’s a summary point. Cyber recovery is NOT an IT-only issue. While information security is addressing the root cause and IT is working to recover the affected technology, the rest of the organization needs to perform its work, often in an environment that will feel like pre-1980. Communications will slow, information won’t be readily available, and that may have to be OK over the short-term. The key is to recognize that everyone must be involved in preparing and contributing to the recovery.

What’s Not Different?

Now let’s talk about what’s not different. The first item on my list is probably the most controversial.

RTO and RPO

Without introducing too much jargon, RTO is the pain threshold the organization identified – regardless of cause – expressed in time. RTO is essentially when management wants to begin working again. The key words here are “regardless of cause.” Prior to really thinking about recovering from cyberattacks, we didn’t have RTOs for hurricanes and another for pandemics. Why should we have a different one for a cyberattack?

Also, RTOs and RPOs are “objectives,” not “promises.” We need to build strategies, implement solutions, and train to achieve these objectives. When we don’t reach the objective, we need to work to understand why and implement corrective actions.

But what we don’t need are separate RTOs and RPOs.

Solution – Adjust our thinking!

Loss of Technology Scenario

Some of our clients have astutely commented, “Isn’t the outcome of a cyberattack the same as what we plan for today, the ‘loss of technology’ scenario?“

It’s true there are some new response and recovery tasks when faced with a cyberattack, maybe even a new solution to leverage to recover to meet the RTO or RPO if the application or its data is affected. But the answer is generally YES!

The organization’s manual workarounds and alternate procedures when faced with a loss of technology apply here. The real challenge is that the application, data, and the end point used to access the functionality may all be unavailable at the same time. If the recovery effort slows and the RTO is missed, the manual workarounds and alternate procedures may need to be used for a protracted period of time.

Solution – Same as above. Review existing manual workarounds and alternate procedures and look for gaps. Do they exist, and are they dependent on resources such as laptops and PCs which may be unavailable? In other words, are your manual workarounds truly manual?

The Process Used by Management to Lead a Response

Yes, organizations employ technical, specialized teams to lead the technical response to a cyberattack (e.g., CSIRT).

As noted already, the response to a cyberattack isn’t purely an IT or information security response. It’s still an organization-wide problem. If you’re like most organizations with a high-functioning business continuity program, you probably have a crisis management process and team. Use this team – or a sub-set of this team – to lead the response to a cyberattack. Don’t create another strategic response process and team because it adds unnecessary complexity.

Solution – Leverage your existing crisis management process, team, and plan for the strategic response to a cyberattack. Train and exercise this team to interact appropriately with your CSIRT and have them serve as an escalation point and a decision-making body for your technical teams.

What’s Next?

Do any of the “what’s different” items resonate with you (or are you currently operating differently than “what’s the same?” Do you have some work to do to address any of them? Your next step might be to set some goals to close out any of these preparedness gaps in 2020.

Here are a few example goals based on the “what’s different” list above:

1. Address Pre-Recovery Dependencies – Identify the expert resources you may need to assess, diagnose, contain, and remediate a cyber issue. Train them, keep them trained, or if external, have them on retainer. List these resources in your plan.

2. Make the Decisions You Can Make Now – Brainstorm the list of cyberattack-related decisions which your leadership team may need to make and see if any of the decisions are absolute, meaning they aren’t situation dependent. The best example: would the organization ever pay a ransom?

3. Re-Purpose the Crisis Management Team – Train and exercise your existing crisis management team regarding the response to a cyberattack. Test the interaction with the CSIRT.

4. Manual Workarounds and Alternate Procedures – Review and validate these procedures based on a documented cyberattack scenario and look for gaps. Train your most time-sensitive teams in using them effectively and identify corrective actions.

Conclusions

The response to a cyberattack can be quite different, but there are many similarities when faced with other forms of disruption.

Consider using this article as a means of gap analysis and where appropriate, set goals to improve your response posture for 2020.

Most importantly, recognize preparing for and responding to a cyberattack is a shared responsibility – information security, information technology, and the rest of the organization.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.