70 likes | 196 Vues
This document outlines Suffolk BC's approach to risk appetite in Business Continuity (BC) and Disaster Recovery (DR) planning. It emphasizes the necessity of setting a clear risk appetite to define the scope of recovery efforts, citing specific examples such as the loss of operational offices and the evolution of the Mumbai operation. It highlights the importance of IT system resilience, robust data management, and continuous testing of recovery plans. Emphasizing remote working capabilities and ongoing assessments, it assures that readiness and rapid recovery are prioritized for organizational sustainability.
E N D
Suffolk BC forum Willis BC/DR Experience 6th December, 2013
Risk Appetite - BC • Need to set own risk appetite to give clear indication on scope eg : • We plan for the loss of Ipswich office • We plan for the loss of London office • We don’t plan for the loss of both at the same time • Mumbai operation have gone from single office to : • three offices in different parts of the city • contracted third party recovery site • improved home working capability • We don’t plan for the long term loss of all three office and recovery site at the same time
Risk Appetite – IT DR • Critical IT systems centralised • Operational efficiencies – maintenance, support, upgrades etc • Data resilience – infrastructure, management, etc • Recovery – backup systems, data replication etc. • Recovery plans • Applications have published recovery objectives • Three tier approach for recovery – High/Med/Low • Email increasingly seen as needing faster recovery given global nature of our business
Willis BC/DR experience • Have well developed and tested BC/DR plans for major global offices • Contracted or designated recovery sites for all offices • Major offices have annual recovery site exercises • Automated messaging system (SMS, voice, email) with annual testing • Annual IT DR recovery site exercise • Large scale remote working capability • Sized for 2000 concurrent remote users • Largest test (for London Olympics) 1009 concurrent remote users • Daily average 100-150 in UK • Over 500 concurrent users on Mon 28 Oct for storm – had sent emergency message out on Sunday night to all UK Associates.
Willis BC/DR experience • Requirement to update BIAs to reaffirm our recovery plans/capability • Previous BIAs indicated 24-48 hrs recovery – no financial trading systems like banks or call centres for High St insurance companies • BIAs confirmed recovery sizing • No. of seats at recovery site • Remote working capacity • Reaffirmed overall recovery period • BIAs confirmed desire for faster email recovery • Fitted with other IT projects for data centre and Email upgrades • Fully fault tolerant – no SPoF systems, infrastructure, building/ environment • Resilient - system capacity, fail over, hot swap etc • Data replication to provide full recovery within hours.