Your Business Needs Business Contingency and Disaster Recovery Plans
Video Transcript
THE EARLIER THIS WEEK I MADE A POST ON MY PERSONAL INSTAGRAM AND TWITTER PAGES STATING THAT PEOPLE SHOULD HAVE THEIR BCP AND DOCENTATION REVIEWED GIVEN THE SITUATION WITH RUSSIA AND UKRAINE. THE QUESTION CAME BACK WELL WHAT IS BCP AND WHAT IS DR? AND I'M GONNA TELL YOU RIGHT NOW DR DOES NOT STAND FOR DOMINICAN REPUBLIC. WE'RE GONNA TALK ABOUT THAT AND A BIT MORE IN THIS VIDEO.
(MUSIC)
HEY MY NAME IS KENNY AND I RUN ROBINSON HANDY AND TECHNOLOGY SERVICES BASED IN MONTGOMERY ALABAMA. THE POINT OF THIS VIDEO IS TO DISCUSS BCP AND DR DOCENTATION OR PLANS. BCP STANDS FOR BUSINESS CONTINGENCY PLANNING OR BUSINESS CONTINUITY PLANNING DEPENDING ON WHO YOU ASK AND DR STANDS FOR DISASTER RECOVERY.
BOTH OF THESE DOCENTS ARE TO MITIGATE RISK TO A BUSINESS AND MAKE SURE THAT THE BUSINESS CAN GET BACK UP AND RUNNING. THESE ARE MORE SO NOT NECESSARILY REQUIRED BUT YOU SHOULD HAVE THEM LIKE YOU HAVE A BUSINESS PLAN. LET'S START WITH BCP. SO AS I MENTIONED BCP IS THE BUSINESS CONTINUITY OR BUSINESS CONTINGENCY PLAN. WHAT DOES THAT MEAN? THAT MEANS YOU HAVE A DOCENT THAT OUTLINES A NBER OF ASPECTS OF YOUR BUSINESS AND IT EXPLAINS WHAT HAPPENS OR WHAT SHOULD HAPPEN IN A GIVEN CIRCSTANCE AND HOW CAN YOU MAKE SURE THAT THE BUSINESS KEEPS RUNNING IF THE UNEXPECTED HAPPENS.
NOW I'M GOING TO GO AHEAD AND LET YOU KNOW NOW BECAUSE I'VE DONE THIS FOR A TECHNICAL FROM A TECHNICAL PERSPECTIVE OR AN I.T. PERSPECTIVE A LOT OF THE RELATED EXAMPLES I WILL PROBABLY BE USING BUT I'M GOING TO TRY TO RELATE IT TO OTHER INDUSTRIES TO BE MORE GENERALIZED INSTEAD OF SPECIFIC TO I.T. ALRIGHT NOW WITH THE BCP FOR APPLICATION THAT I SUPPORTED IN THE PAST THE WAY THAT DOCENT WAS SET UP OR STRUCTURED AND THIS IS NOT IN ANY PARTICULAR ORDER BUT BASICALLY YOU HAD A A SINGLE WORD DOCENT AND IN THAT WORD DOCENT IT OUTLINED THE NAMES OF THE SERVERS BECAUSE THIS APPLICATION WAS HOSTED ON PREMISES.
IT OUT LISTED THE NAMES OF THE SERVERS THE SERVERS THAT OR THE APPLICATIONS THAT THIS APPLICATION INTERFACE WITH AND A WHOLE BUNCH OF OTHER INFORMATION. HOW LONG THE APPLICATION COULD BE DOWN WHO IS OR ARE THE POINTS OF CONTACTS IN IN BASICALLY EVERY ASPECT SO IF THERE'S A DATABASE WHO'S THE DATABASE CONTACT IF THERE'S AN APP SERVER WHOSE APP SERVER CONTACT THE CONTACTS FOR THE INTERFACING SYSTEMS AND A WHOLE LOT MORE.
NOW YOU'RE PROBABLY ASKING WHAT'S THE INTERFACING SYSTEM? LET'S SAY YOU HAVE A SYSTEM THAT MANAGES YOUR ACCOUNTING OR AN ACCOUNTING SOFTWARE. I'M NOT GOING TO CALL ANY PARTICULAR PRODUCTS BUT YOU HAVE THE IDEA AND YOUR ACCOUNTING SOFTWARE CONNECTS TO YOUR INVOICING SOFTWARE AND BASED ON THE INVOICING THE INVOICE AND DATA COMES INTO YOUR ACCOUNTING SOFTWARE AND IS LOGGING EVERYTHING AND THEN YOUR ACCOUNTANT HAS IT THEIR OWN SOFTWARE. SO YOUR ACCOUNTING SOFTWARE SENDS OUT DATA TO YOUR ACCOUNTANT.
IN THIS SCENARIO YOUR INVOICING SOFTWARE AND YOUR ACCOUNTANT ARE TWO DIFFERENT INTERFACES TO YOUR ACCOUNTING SOFTWARE. THAT BEING SAID IF YOUR ACCOUNTING SOFTWARE WERE TO GO DOWN HOW LONG COULD YOUR BUSINESS CONTINUE TO FUNCTION? WITH THOSE OTHER TWO SYSTEMS WAITING ON DATA OR PENDING DATA TO BE SENT FOR A LOT OF PEOPLE DEPENDING ON HOW YOU SET UP YOUR BILLING IT COULD BE A WEEK. FOR SOME PEOPLE IT COULD BE THE END OF THE MONTH. FOR SOME SYSTEMS LIKE AT A BANK YOU PROBABLY WANT THAT TRANSACTION TO GO THROUGH AT THE END OF THE DAY. EVERY BUSINESS DAY. THAT BEING SAID THAT PIECE OF INFORMATION GOES IN SO WHO IS THE PRODUCER OF DATA THAT COMES TO THIS PARTICULAR SYSTEM WHO'S THE CONSER OF DATA THAT COMES TO THIS SYSTEM.
IF THEY ARE EXPECTING DATA BY A CERTAIN TIME LIKE YOUR ACCOUNTANT IS PROBABLY EXPECTING DATA BY THE SECOND DAY OF THE MONTH. SECOND CALENDAR DAY OF THE MONTH. YOU NEED TO PUT THAT IN YOUR BUSINESS CONTINUITY PLAN IF YOUR INVOICING SYSTEM GENERATES A REPORT EVERY DAY AND SENDS IT TO YOUR ACCOUNTING SYSTEM. YOU NEED TO PUT THAT IN YOUR BUSINESS CONTINUITY PLAN IF YOUR ACCOUNTING SYSTEM GENERATES SUPPORT FOR REPORT FOR YOUR EXECUTIVE STAFF. YOU NEED TO PUT THAT IN YOUR BUSINESS CONTINUITY PLAN. WHY? BECAUSE THOSE THINGS ARE CRITICAL TO MAKING SURE THAT THE BUSINESS CONTINUES RUNNING.
ALSO IN THIS BCP PLAN IF THERE ARE SIGNIFICANT ISSUES WITH THE ACCOUNTING SOFTWARE, COULD THIS BE DONE BY ANOTHER MEANS? THAT BEING SAID COULD YOU JUST PULL OUT PEN AND PAPER MANUALLY DO THE CALCULATIONS MANUALLY GENERATE THE REPORTS MANUALLY SEND THAT DATA TO YOUR ACCOUNTANT? IF THEY CAN BE PUT THAT IN THERE. IF IT CAN'T BE PUT THAT IN YOUR PLAN TOO. YOU NEED TO HAVE EVERYTHING IN THAT PLAN. THAT WAY THAT DOCENT IS A SINGLE RESOURCE FOR A GIVEN CIRCSTANCE. NOW I WOULD SUGGEST THAT AND BASED ON MY I.T. EXPERIENCE WE HAD TO DO THESE DOCENT REVISIONS OR UPDATES OR REVIEWS HOWEVER YOU WANT TO PHRASE IT ONCE PER YEAR.
NOW THEY GOT TO A POINT WHERE THEY WERE ACTUALLY DOING THEM EVERY TIME AN APPLICATION HAD AN UPDATE THAT THE BCP AND DR DOCENTATION WERE TO BE AT LEAST REVIEWED IF NOT UPDATED. BUT YOU DON'T NECESSARILY HAVE TO DO THAT BUT I WILL SAY AT A MINIM ONCE PER YEAR REVIEW DR DOCENTATION BCP DOCENTATION FOR EVERYTHING THAT YOU HAVE NOT JUST ONE PART FORTH. AND THE REASON BEING IS BECAUSE COMPANIES CHANGE MOVE STUFF AROUND ALL THE TIME. THEY SWITCH SERVICE PROVIDERS. THEY ADD APPLICATIONS. THEY ADD SOCIAL MEDIA ACCOUNTS. ALL OF THIS INFORMATION CHANGES AND IF YOU'RE NOT KEEPING IT UP TO DATE AT LEAST ONCE A YEAR YOU'RE GOING TO FALL BEHIND AND THEN SOMETHING'S GOING TO HAPPEN A PERSON'S GOING TO QUIT A COMPUTER THAT HAS ALL THIS INFORMATION THE LOGIN IS STORED IT'S GOING TO FAIL.
SOMETHING'S GOING TO HAPPEN AND THEN YOU'RE GOING TO GO LOOK FOR THAT DOCENT AND THE DOCENT IS OUT OF DATE YOU'RE GOING TO BE SOL. ALRIGHT. SECOND THE DR DOC DISASTER RECOVERY WHAT DOES THE DISASTER RECOVERY PLAN STATE? IN THIS SHORT A DISASTER RECOVERY PLAN WOULD BE UTILIZED. LET'S SAY YOU HAVE A DATA CENTER AND YOUR WEBSITE YOUR INTERNAL APPLICATIONS WHETHER IT'S ACCOUNTING INVOICING WHATEVER IT IS IS ALL IN THE SAME DATA CENTER.
THAT DATA CENTER GETS HIT BY A TORNADO IS LEVELED YOUR BUSINESS HAD EVERYTHING IN THAT DATA CENTER. HOW DO YOU RECOVER FROM THAT DISASTER? THE DR PLAN IS WHERE THAT COMES INTO PLACE. DO YOU HAVE BACKUPS OF YOUR DATA? WHERE ARE THOSE BACKUPS? HOW FREQUENTLY ARE THOSE BACKUPS BEING TAKEN? WHO HAS ACCESS TO RESTORE THOSE BACKUPS? DO YOU HAVE ANOTHER DATA CENTER THAT YOUR BUSINESS CAN TRANSITION TO OR SWITCH TO AND BE BROUGHT BACK ONLINE AND CONTINUE WORKING?
ALL OF THESE THINGS GO INTO A DR PLAN AND LIKE I SAY THIS I'M SPEAKING FROM AN I.T. PERSPECTIVE BUT THIS COULD BE ANY OTHER THING. THIS COULD BE IF YOU ARE A DELIVERY BUSINESS AND YOUR VEHICLE HAS BLOWN A I DON'T KNOW HAS SLUNG A ROD ALRIGHT. YOUR VEHICLE HAS TO BE IN THE SHOP. DO YOU HAVE ANOTHER BACKUP PLAN OR DISASTER RECOVERY PLAN IN THAT CASE OR EXCUSE ME A BUSINESS CONTINGENCY PLAN IN THAT CASE TO GET IT OUT YOU KNOW GET YOUR DELIVERY STILL GOING IF A TORNADO HITS YOUR TOWN AND DESTROYS YOUR DELIVERY VEHICLE? DO YOU HAVE A DISASTER RECOVERY PLAN CAN YOU GO SOMEWHERE ELSE AND RENT ANOTHER DELIVERY VEHICLE OR A VEHICLE THAT WILL SUIT YOUR PURPOSE? WILL YOUR INSURANCE BE FAST ENOUGH TO GET YOU BACK AND RUNNING YOUR BUSINESS? THESE ARE THINGS THAT YOU HAVE TO INCLUDE IN YOUR DR AND PCB PLANS.
NOW WHEN IT COMES TO BOTH OF THESE PLANS THERE ARE A NBER OF THINGS THAT YOU NEED TO DO. LIKE I MENTIONED YOU NEED TO UPDATE BOTH OF THEM AT LEAST ONCE PER YEAR OR AT LEAST REVIEW THEM BECAUSE IF NOTHING CHANGES THERE'S NOTHING UPDATE BUT YOU NEED TO NEED TO REVIEW THEM ONCE PER YEAR. YOU NEED TO HAVE MULTIPLE COPIES OF THEM IF YOUR DR PLAN AND BCP PLANS ARE ON A SINGLE SERVER AND THAT SINGLE SERVER GETS BLOWN AWAY BY A TORNADO, YOU HAVE NO DR AND BCP PLAN THAT YOU CAN LOOK AT.
THAT BEING SAID YOU NEED TO HAVE ONE IN A CENTRAL LOCATION THAT EVERYBODY CAN ACCESS BUT THEN YOU NEED TO ALSO HAVE COPIES OF THAT LET'S SAY ON YOUR PERSONAL LAPTOP OR YOUR WORK LAPTOP OR WHATEVER THE CASE MAY BE AND MAYBE A COUPLE OF CO-WORKERS HAVE A COPY OF THAT SAME PLAN ON THEIR LAPTOPS. AND THAT WAY IF YOUR DATA CENTER GETS BLOWN AWAY UNLESS YOUR DATA CENTER AND YOU ARE IN THE SAME CITY WHICH I WOULD NOT ADVISE YOU'RE GOING TO HAVE A COPY OF THOSE PLANS AND YOU CAN REVIEW THOSE PLANS AND UTILIZE MAKE ALL YOUR CALLS GET EVERYTHING BACK UP AND RUNNING AND YOUR BUSINESS DOESN'T SIGNIFICANTLY SUFFER AS MUCH OF AN IMPACT AS IF YOU DIDN'T HAVE ANY OF THOSE PLANS IN PLACE.
NOW FROM A SMALL BUSINESS PERSPECTIVE I HAVE A BCP PLAN SET UP NOT NECESSARILY A DR PLAN IN SOME WAYS IT COULD BE CONSIDERED A DR PLAN BUT NOT NECESSARILY. SO FOR BCP PLAN WHEN IT COMES TO THE BUSINESS WEBSITE I HAVE IT SET UP IN VERSION CONTROL. NOW THE VERSION CONTROL SOFTWARE IS BASICALLY ANYTIME THERE'S A CHANGE ANY CHANGE MADE TO THE WEBSITE THAT CHANGE IS LOGGED AND SENT OVER TO A ANOTHER PARTY SEPARATE FROM WHERE THE WEBSITE IS HOSTED. THAT BEING SAID IF THE WEBSITE HOSTS WHICH I KNOW THEY DO THE WEBSITE HOST THAT I HAVE THEY MAKE BACKUP COPIES OF THE FILES ON THEIR SERVERS AND THEY DO INTERNAL WHAT THEY CALL REPLICATION OR BACKUPS IN WITHIN THEIR NETWORK SO THAT THEY HAVE COPIES OF IT BUT IN THE WORST CASE SCENARIO.
LET'S SAY THAT SERVICE PROVIDE THAT HOSTING SERVICE PROVIDER DECIDES TODAY WE'RE GOING OUT OF BUSINESS. GOOD LUCK GETTING YOUR STUFF. WELL I HAVE BACKUP COPIES IN MY VERSION CONTROL THAT VERSION CONTROL I CAN PULL FROM THERE GO TO ANOTHER HOSTING PROVIDER SPIN UP A NEW SITE WITH THE EXISTING CODE THAT I HAVE IN A MATTER OF MINUTES. ALRIGHT NOT EVERYBODY PLANS IN THAT MANNER ESPECIALLY WHEN YOU HAVE A HOSTING PROVIDER THAT YOU ARE LIKELY YOU HAVE SOMEBODY MANAGING YOUR WEBSITE. AND A LOT OF TIMES THE PEOPLE THAT ARE MANAGING A WEBSITE DON'T NECESSARILY GIVE YOU THE DATA TO OR THE USERNAME LOGINS WHATEVER THE CASE MAY BE TO BE ABLE TO MAINTAIN YOUR OWN WEBSITE AND THEN SOMETHING HAPPENS TO THEM. YOUR WEBSITE IS LOST IN THE WIND BECAUSE THEY HAD FULL CONTROL OVER EVERYTHING AND YOU HAVE NONE OF THOSE CREDENTIALS.
THAT'S A BAD IDEA FROM A DISASTER RECOVERY PERSPECTIVE I DON'T NECESSARILY HAVE ALL OF THESE THINGS IN PLACE BUT I COULD COME UP WITH A DISASTER RECOVERY PLAN BECAUSE LIKE I SAY MY HOSTING PROVIDER IS IN I KNOW WHAT HOSTING PROVIDER IS IS ON THE EAST COAST BUT IN THE WORST CASE SCENARIO I CAN GO FIND ANOTHER POSTING PROVIDER THAT'S ON THE WEST COAST SET UP EVERYTHING OVER THERE USING MY VERSION CONTROL AND BOOM EVERYTHING WILL BE RUNNING FAIRLY QUICKLY. I CAN PROBABLY GET IT DONE IN MAYBE 15 TO 20 MINUTES. NOT EVERY BUSINESS PERSON CAN DO THAT BUT THE FASTER YOU CAN GET THAT PRESENCE BACK ONLINE THE FASTER THAT THERE WILL THE LESS IMPACT ON YOUR BUSINESS THAT IT WILL HAVE.
NOW ANOTHER QUESTION YOU MAY HAVE IS WELL HOW LONG SHOULD A BCP BE? HOW LONG SHOULD IT BE A DR PLAN BE? THAT IS UP TO YOU YOU NEED TO INCLUDE EVERY BIT OF INFORMATION. I WOULD SAY AT LEAST THE CONTEXT FOR WHATEVER IT IS SO IN THE IN THE SCENARIO OF HOSTING A WEBSITE OR HOSTING A BUSINESS SPECIFIC APPLICATION YOU NEED TO HAVE THE CONTACTS FOR THAT APPLICATION. SO IF YOU'RE PAYING SOMEBODY TO MAINTAIN IT FOR YOU YOU NEED TO HAVE THAT KIND OF CONTACT INFORMATION. WHO IS THE HOSTING PROVIDER. LIKE IF IT'S INMOTION. IF IT'S AWS. IF IT'S AZURE. YOU NEED TO HAVE THAT INFORMATION ACCOUNT NBERS ALL OF THAT STUFF. YOU STILL NEED TO KEEP IT SECURE DON'T PUT IT ON THE OPEN INTERNET. SO PUT STICK IT IN THE EMAIL ACCOUNT OR SOMETHING OF THAT NATURE BUT YOU NEED TO HAVE IT ALL DOCENTED AND THAT WAY YOUR BUSINESS IS NOT SIGNIFICANTLY IMPACTED. IF IT IS IMPACTED IT SHOULD BE MINIM DOWNTIME IN THAT REGARD.
HOPEFULLY THIS ANSWERS OR INCLUDES A LITTLE BIT OF CLARITY OF WHAT BCP IS AND WHAT DR IS. IF YOU HAVE ANY QUESTIONS PLEASE LEAVE THOSE DOWN BELOW. THANK YOU FOR WATCHING UNTIL NEXT TIME PEACE!