Home > Midmarket CIO Tips > Security for the midmarket > SMB business continuity planning basics -- Part 1
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

SMB business continuity planning basics -- Part 1


Pierre Dorion, Contributor
04.13.2006
Rating: -4.11- (out of 5)


Technology news and tips for Midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Developing a business continuity plan has long been considered a luxury that only large enterprises can afford. The reality is, business continuity planning (BCP) is a necessity for all companies, and small and midsized businesses (SMBs) are often perceived as being less disaster resilient than large, geographically dispersed multinational companies. Part 1 of this two-part series addresses why SMBs need a business continuity plan.

What is business continuity planning?

Read more on business continuity

Worst practices for disaster recovery, part 1

IT Management Guide: Disaster recovery planning

The terms BCP and disaster recovery (DR) planning are often used interchangeably to describe an organization's ability to survive a disastrous event. However, most contingency planners now consider DR planning a subset of BCP, which itself is a subset of risk management. BCP reduces the impact of an interruption to a level that is acceptable to the business.

A business continuity plan is developed based on these key elements:

Business impact analysis:

  • Understanding the business (what it does, who does it and how);
  • Calculating the impact on the business should its critical processes be interrupted;
  • Identifying the dependencies for these processes (people, infrastructure, tools, records, etc.)

Risk assessment:

  • Threats to which the organization is subject and its vulnerabilities
  • The probability of those threats materializing
  • Controls in place to mitigate or reduce the risk

Communication:

  • Knowing what to do, how and when to do it and what to say in the event of a crisis

Of course, the above information does not mean much if the procedures are never tested or they are allowed to become outdated. Hence, the program must also include BCP testing, training and updating.

Why is BCP important?

Traditionally, BCP was viewed as a process that was reserved for Fortune 500 companies. SMBs had to be content with daily tape backups sent off site. SMBs have the same continuity requirements as large enterprises, albeit on a smaller scale. They, too, have customer and market demands to satisfy, employees to pay, revenue streams to maintain and, in many cases, shareholder investments to protect.

Some of the drivers for implementing a business continuity program are summarized below. Note that while these drivers apply to organizations of all sizes, they are particularly important to SMBs, which typically have fewer financial and staffing resources to weather a crisis.

Competitive advantage: Many partnership or supplier agreements include clauses that require certain service levels in the event of a disaster or business interruption. Having a plan in place gives a company a competitive edge over those that don't.

Legal implications: Industries beyond banking are legally bound to have a contingency plan in place because of regulations such as the Sarbanes-Oxley Act.

Insurance premiums: Many insurance companies now factor in a company's level of disaster preparedness as part of the risk calculation. Some companies have seen significant reductions in their business insurance premiums based on a measurable level of preparedness.

BCP planning is primarily intended to protect a company's assets, such as people, revenue flow, records and intellectual property and infrastructure. Beyond contributing to the prevention or mitigation of tangible losses, BCP is also essential to protect an organization's reputation in the event of a disaster or major interruption.

A BCP, even if incomplete, is better than no plan at all. At a minimum, it should ensure that roles and responsibilities are clearly defined. It should also include tested procedures that focus on the safety of employees and the timely resumption of business-critical and revenue-generating activities.

Stay tuned -- Part two will explore the business impact analysis element of a DR plan from an IT perspective.

Pierre Dorion is a business continuity consultant at Mainland Information Systems Ltd. in Calgary, Alberta, specializing in business continuity planning.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security for the midmarket
Unified communications: Keeping lines secured
Risk assessment frameworks easy to employ
Compliance: Don't let your guard down
Single sign-on: Sensible security on scale
Laptop theft easily preventable while on the road
Information security requires organized teams
How to choose a DR service provider
Security on a midmarket budget
Security's crystal ball for 2008
Security outlook challenging for SMBs in 2008

Disaster recovery planning and business continuity
The Real Niel: Not all risks are created equal
Disaster recovery: Use simple plan to classify apps
Disaster recovery plan: Finding the best solution for the money
Virtualization the center of county's 'disaster avoidance' plan
Disaster recovery planning off CIOs' plate -- sort of
DR planning: When good isn't good enough
Legal Expert: Avoid legal issues in disaster's wake
Disaster recovery funding often hard sell for CIOs
CIO Decisions Conference 2008: Presentations and Coverage
Five tips that could change your data center

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts