Business-critical networks and risk mitigation

Opinion
May 22, 20073 mins

Recently we talked about how networks played a critical role in both the crash and recovery of JetBlue after its Valentine’s Day debacle. That’s a specific case of the broader question, “What’s the role of the network in corporate risk-mitigation strategies?”

Let me explain. As my colleague Andreas Antonopoulos has pointed out in his recent Network World column, chief security officers are in the process of morphing into “chief risk mitigation officers,” responsible for overseeing all aspects of risk in an organization. One risk is downtime — which includes network outages.

The shift in focus from security toward risk mitigation affects network managers in several ways. First, net managers need to begin getting even more deeply involved in corporate risk-mitigation initiatives. That means meeting on a regular basis with the CSO, the data-center chiefs, and folks from outside of IT who’re involved in risk-mitigation activities (compliance, legal, finance).

Plan to meet regularly with these individuals and review with them some key questions:

· What are your current risk-mitigation priorities?

· How do you see those affecting our network strategy?

· How do you see our network strategy affecting those priorities?

· What is our overall organizational tolerance for risk? Are we willing to assume increased risk if it brings concomitant competitive advantage? Or is our position “avoid at all costs”?

That last question is particularly important, because it affects decisions on which technologies to invest and how much to invest in security overall. Some companies tell me they’re holding off on VoIP and collaborative tools because of (real or perceived) security vulnerabilities. I think that’s a bad idea. In my view, they’d be better off beefing up security overall, rather than avoiding new technologies.

But that’s a topic for another column. Regardless of whether you agree with me, you need to understand your company’s position on risk in general.

Second, network managers should plan to assess and consider products and services that help mitigate risk — particularly the risk of downtime. These include DDOS-prevention services, such as those offered by AT&T, Verizon and others, as well as tools. Major vendors (Cisco, Juniper, Nortel) all offer products that can protect against DDOS, and a handful of upstarts are offering point-products for that solution (an intriguing player here is RioRey).

Other alternatives to consider include emerging backup solutions, including online backup services. Some combine backup with indexing and cross-referencing in support of records retention and e-discovery efforts, which means that these services can help an organization with compliance. That can be a very big deal, so consider it.

The bottom line? As networks become more business-critical, their role in risk-mitigation increases. Your architecture and roadmaps need to take that into account.