by Michael Miora, CISSP-ISSMP, FBCI

Business continuity planning still not widely implemented

Opinion
Jan 24, 20114 mins

Long-time friend and colleague Michael Miora, CISSP-ISSMP, FBCI contributes another pair of thought-provoking essays to the column. What follows is entirely Michael’s work with minor edits.

* * *

The decades following the advent of personal computing fostered the inevitable march of information from centrally stored and professionally managed safe houses consisting of mainframe and minicomputer clusters to the ad hoc world of impulsively managed devices such as microcomputers, tablet computers and smartphones. For the home user, loss of data can range from the inconvenience of the loss of financial records to the emotional turmoil caused by the loss of irreplaceable photos and other personal records. For a business, especially a small to midsized business (SMB), the same loss can spell disaster and business failure.

Nevertheless, neither individuals nor SMBs have taken backup and recovery seriously. I have been often called upon too late to help an individual recover their lost photos and irreplaceable other electronic memorabilia. Even after such disasters, many people do not take proper steps. The small business is similarly inclined.

Why do so many people ignore business continuity planning (BCP)? Is it so hard to think about contingencies or to make backups? In my opinion, it must be hard. If it were easy, more people and business would do what it takes to get prepared and stay prepared. But they aren’t doing that. The U.S. Department of Homeland Security is concerned enough to be running a campaign encouraging individuals and businesses to get prepared.

The statistics about preparedness and survival are unreliable. They are difficult to collect, incompletely reported, and often analyzed by organizations with a vested interest in a particular slant.

Having spent decades discussing backups and planning with organizations ranging in size from a few people to Fortune 500 size companies, I have found a single thread that permeates the issue: People and small companies have neither the time nor inclination to take up the backup cause because they do not really believe failures will happen to them. Why should they believe otherwise? Hardware, software and service vendors spend enormous funds to convince their customers they are safe. How are we, the Cassandras of doom and gloom to gain a foothold?

In psychological research, car drivers have consistently been found to overestimate their relative driving skill; this “superiority bias” is known as the “Lake Wobegon Effect” after the mythical town described by Garrison Keillor in his writings and on the public radio program “Prairie Home Companion.” In Lake Wobegon, “all the women are strong, all the men are good-looking, and all the children are above average.”

Like drivers who accelerate through yellow lights, we all know that we will be safe in our computing environments; never mind the driver at the intersection who is waiting impatiently for the light to change and may well start moving even before the light turns green because he thinks he’s immune to accidents. Never mind the capacitor in our disk drive that is about to melt because of a defective cooling fan – our systems won’t fail.

Other people have car accidents and other people lose data. That is why there are still data recovery companies specializing in helping people recover their irreplaceable data from failed drives.

In the next of these two articles, Michael shows how cloud computing offers a useful, albeit under-appreciated, contribution to BCP.

Michael Miora has designed and assessed secure, survivable, highly robust systems for industry and government over the past 30 years, and has become an internationally recognized expert in InfoSec, Business Continuity and Incident Response. Miora, one of the original professionals granted the CISSP in the 1990s and the ISSMP in 2004 was accepted as a Fellow of the Business Continuity Institute (FBCI) in 2005. Miora founded and currently serves as president of ContingenZ, a specialty consulting firm and the developers of ContinuityCommander, a BC/DR planning software package. He can be reached via e-mail. He frequently serves as an instructor in the Master of Science in Information Assurance (MSIA) and Master of Science in Business Continuity Management (MSBC) programs at Norwich University.