A gestão de crises em ambientes federais e da SLED vai muito além da resposta tradicional em matéria de cibersegurança, exigindo coordenação entre os domínios físico, operacional e digital.
Para estas organizações, a resiliência cibernética garante a capacidade de manter os serviços, muitos dos quais têm um impacto profundo na vida das pessoas. Os sistemas de identidade, como o Active Directory, o Entra ID e o Okta, estão no cerne da resiliência, uma vez que os ataques à identidade podem perturbar serviços públicos essenciais, a resposta a emergências e as operações interinstitucionais.
Nesta Tech Talk, Josh Wagman, diretor da Cyber Resilience Advisors da Semperis, aborda a forma como o planeamento da gestão de crises centrado na resiliência da identidade é fundamental para garantir a continuidade durante crises complexas que envolvem várias entidades.
Aprenderá:
- Por que razão a resiliência da identidade é fundamental nos setores federal e SLED
- Por que e como isolar e controlar as comunicações durante um ciberataque
- Como garantir que os seus planos de gestão de crises estão preparados para situações reais
Welcome everyone. The event is now live. John, please take it away. Thanks, Allison. Hi, everyone. Welcome to today’s live Tech Talk, Beyond Cybersecurity Crisis Resilience for the Public Sector. This event was organized by the hardworking folks at Redmond Magazine and it’s sponsored by Semperis, a leader in AI powered identity security and cyber resilience for high for hybrid environments. I’m John K. Waters, editor in Chief with Live 360 Group of 1105 Media, and I’m joined today by cybersecurity specialist, Josh Wagman. Hey, Josh. Hi, John. Thank you very much for having me today. Great to have you, man. Let me tell you a little about our speaker today. Josh is an IT leader with more than fifteen years in enterprise resilience, specializing in business continuity, disaster recovery and identity security. With operational and consultive experience across server storage, virtualization and data protection, Josh now serves as Director of Cyber Resilience Advisors at Semperis, helping executives strengthen organizational resilience. I’m really looking forward to this conversation, but before we get going, I need to do just a bit of housekeeping. This Tech Talk is being recorded for later access. Keep an eye out for an email with a link to that recording. It will be coming your way in the next few days. Our sponsor has provided some extra resources you won’t want to miss. They’re available now on your console. And at the end of this conversation, we’ll have a five to ten minute Q and A. Please type your questions into the Q and A box as they occur to you. We’ll do our best to get to all of them. Okay, let’s jump in. Public sector resilience is not just about recovering from an attack. It means keeping critical services running, supporting emergency operations and maintaining continuity when people depend on them most. Today’s crises rarely stay contained in one system to one system. When identity infrastructure like say Active Directory, Entra ID or Okta is compromised, the effects can ripple across agencies and mission critical services. Our conversation today is focused on how public sector organizations can build resilience into that infrastructure and prepare for incidents that hit people, processes, technology and mission delivery at once. Okay, let’s start with the big picture, my friend. When you say crisis resilience in the public sector, what does that really mean beyond recovering from a cyber attack? Yeah. Crisis resilience recovery is definitely part of that conversation. But when we’re talking about resilience, we’re talking about a whole lot more that goes into that. It’s the preparation, the planning, and it really involves containment, eradication, continuity. So how do we keep the lights on if we have a bad situation where systems are going down? How do we keep, as many departments as functional as possible while we try to get back to normal? And then recoverability is definitely a part of that. And when we’re talking about resilience as well, we’re talking about tying back to what matters to an organization. So it goes into, have you performed your business impact assessment to understand what your critical lines of business are, how they fold into your mission? Have you defined what downtime procedures are required and what those look like? Having those critical system recovery plans, but not just recovering and restoring, but prioritizing that based off of dependency and criticality to the organization. And then as we rebuild, we have to look to build back better. We’ve got to make sure we take into account what we’ve experienced as part of that incident and making sure we’re taking steps to mitigate that from happening again in the future. Okay. So why is resilience such a different challenge, I guess I could say, for government agencies and educational institutions than it is for many private sector organizations? I think definitely one of the most impactful areas is budget constraints. When you’re dealing with public funds, the budget isn’t always there to flush out infrastructure to help mitigate. Also, you’re dealing with large complex organizations like public sector, sector, there’s potentially many agencies involved. And so getting everybody on the same page can be extremely difficult. There’s competing priorities. And when you take into account the budgetary constraints that these organizations often face, the complexity only compounds that. Makes it difficult to make sure that you can tackle everything at once. And then when you’re dealing with large and complex organizations, it’s often difficult to understand responsibility across different departments within state or local government. Who’s responsible for what? Are there systems that are being shared, be it technical or nontechnical? And who ultimately speaks for that specific system or those number of systems? Okay. So as I mentioned in the intro, the crisis we’re talking about today don’t stay neatly inside one category. What makes incidents so hard to manage when they cross cyber operational, physical and communications barriers? I think one of the biggest challenges is definitely coordinating across teams. This is where we see the biggest breakdown in crisis response in general. If you’re dealing with a low level incident that stays localized to a specific team, it’s usually not a giant obstacle to overcome. Communications is extremely efficient. Again, there’s no competing priorities. But as soon as something escalates and we have to involve more teams or more departments, that’s when coordination starts to break down. Are we able to understand who’s responsible for what within all of these different teams? And at the same time, are our priorities aligned? Do we have the same goal in mind? We have to make sure we all get on the same page, and that’s where a lot of the complexity comes into play. Okay. So when a public sector organization is hit by a cyber attack, what kinds of real world services can be affected? Yeah. When public sector gets hit, obviously, we’re talking about some pretty critical infrastructure. Sure. We’re looking at public safety, number one. Emergency services. Everything is so digitized now. If you call nine eleven for emergency assistance, you’re dealing with a completely digitized environment. And so if systems are attacked and go down, we’re definitely looking at public safety being probably first and foremost. We’ve got public health. Those that are dependent on public health, obviously, there’s a criticality there. We’re talking literally about life saving measures. Sure. We’ve got economic and labor support. So if we’re dealing with something that takes down systems for a long period of time, are people able to get employment insurance and different things like that that support their life on a day to day basis, things like social services? And really, the gamut is massive in what we’re dealing with here, but it’s usually critical services that everybody depends on on a day to day basis. Okay. So identity isn’t always the first thing people think about in crisis planning. Why should it be? That’s a great question. And and really what I think has been traditionally a focus on perimeter security has shifted in the last number of years to where identity has become a perimeter, but it’s also foundational to everything we do. So your identity enables you digitally to access all of your different applications and services that are provided by any organization. And so when we’re looking at why identity should be a focus point in crisis, it’s the first thing we need back. We can’t do anything in most of our environments if identity is not available to us. That means accessing software as a service application. It doesn’t maybe it’s not maybe obvious that identity internally is tied to that, but it definitely is. Any internal infrastructure that you need to be able to access. We’ve been in situations in an incident response capacity before where physical access was taken away from buildings because it was tied to core identity systems. So identity plays potentially a huge role in number one, physical access, but obviously access to anything digital, any information, any processing we need to do. And basically anything that’s using your primary identity is at risk. And then the other key element to look at is in modern cyber attacks, identity is usually, if not a foundational piece of what the attacker is using, it could be the primary target as well. Because threat actors understand that if they take away identity, they take away your ability to operate. Makes sense. Okay. What can happen when core identity systems like Active Directory, Entra ID or Okta are compromised during an incident? So if your identity systems are compromised, an attacker can number one, create persistence. So they can figure out a way to gain access to your environment on a long term method. They can they can do that in an obvious way. They can do that in not obvious ways, like setting up different delegations to areas of your identity platform that allow them to maintain elevated permissions in a not so obvious way. They can escalate their privilege so they can get the keys to the kingdom. All they need is a foothold in your environment, and they can find a way to turn that foothold into that, that scenario where they basically have access to anything. When an attacker has access to an identity, they can access all of your private and proprietary information. So everything that’s tied to those identities is accessible by the threat actor then. That’s where you get things like data exfiltration. They get access to consumer information. So anyone that’s got personal information stored and being public sector, there’s obviously some pretty critical information stored on people in most systems. And then they can also access any third party applications that are tied via single sign on. So anything that’s related to that primary identity, all of a sudden, threat actor has access to. And they can use that information for exfiltration purposes, or they can simply use it for destruction, that type of access. Yikes. Yeah, exactly. And from there, the attacker can basically bring down anything. Oh, man. So okay. So how should public sector leaders connect identity resilience to broader community planning and emergency response? So tying identity resilience, identity resilience should really be one of the focuses of continuity planning. So when we’re looking at identity, we have to have the thought process that identity is going to be step one in our recovery. So it’s obviously got to have a key focus there. When you tie that into emergency response, what happens if all of your plans, your procedures, all of the hard work you’ve done in preparing for response are stored somewhere or dependent in some way on that primary identity that you might not have access to anymore. Right. Yeah. Basically, what that means is all of your planning and preparation, those hundreds, those thousands of hours you’ve spent building a program are basically unavailable because that identity has been compromised, the infrastructure has been taken down, and now we’re kind of flailing. So when you’re looking at emergency response, it’s extremely important to consider identity because we have to create a gap there. We have to shield the blast radius of primary identity from the impact of the attack and make sure that our response processes are not tied to that in any way, shape, or form. Okay. So what are some of the signs that an organization an organization’s identity environment may not be ready for serious disruption? Yeah. There’s few things you can check-in your environments that would kind of give you an idea of if you’re prepared for this or not. First thing is, can you perform a simple audit on change to your identity stores in your environment? And an example of this would be, can you monitor changes to different group memberships? So if somebody adds an account to a group, can you uncover what group was modified? Who performed that change? When that change was performed? How about more complex change? What if somebody goes into an identity store and modifies a policy or modifies a delegation on an organizational unit in Active Directory, for example. Can you observe those changes? Do you have a way to understand that that happened in your environment? Many of us are missing that level of visibility. What happens if somebody changes the configuration of the underlying architecture, changes replication, or something along those lines? Can you understand that? So by being able to observe change, you’re able to understand better what’s going on in your environment. From there, we get into alerting. Do you have the capacity in your environment currently to be alerted when change happens? Not just be able to observe it, but to be proactively alerted when something maybe questionable goes on. And then the third thing I would look at is, have you ever performed a full recovery of your identity environment that wasn’t just a paper exercise? Many organizations I’ve talked to in the past have basically said, well, we did a tabletop where recovered our identity environment. But nobody actually clicked any buttons and went through the process of actually verifying that their environment was recoverable and fully working after the fact. And what I would say is if the answer to any of those questions is no, then an organization is definitely not ready to face, an event that that targeted identity. Okay. I hope this isn’t a dumb question, but how much of identity recovery needs to be figured out before, the crisis starts? No, it’s not a dumb question. Absolutely. Identity recovery should be well defined and fully practiced before any issues happen in the organization. Due to the fact that, as we discussed before, that so many things are dependent on identity from physical access to buildings, right down to every internal application virtually would be dependent on identity somehow. Obviously, it’s a key focus on our recovery scenarios. And so not having a tested process and a firm understanding in what goes into that identity recovery creates significant unknown when we’re going into these events, especially if you’re trying to meet any type of SLA. If you’ve got definitions around what you need back and when you need it back, if you haven’t mapped identity recovery into that process, you basically missed step one. And that can put us at serious risk of missing those. And if there’s significant fallout as a result, and the fallout being that we’re dealing with public sector could be lives on the line, emergency services being available. We have to account for identity as part of that. And so having that figured out before any type of major incident happens is critical. Okay. In a multi agency incident, what happens when people can’t reliably authenticate access systems or coordinate across organizations? We’ve kind of been talking about this already. Yeah. Basically, if you can’t authenticate or access systems, the first thing that breaks down is communication. Because of the fact we’re so dependent on our internal infrastructure for communication purposes, It’s really and in a crisis, in a major incident, that’s probably the most important function to get back first. So you have to consider how do you get in contact with people if you can’t access your company’s directory? And here’s where what I mentioned earlier come kind of comes into play in that if you’re dealing with something that’s within a single team, okay, you might you might have that contact information saved in a text message on your phone or or something along those lines. But when you’re dealing with something that’s escalating, and now we have to talk to different departments in our organization or different departments as part of the public sector framework, all of a sudden that contact information is no good anymore because we don’t have enough contact information to get access to different people from different departments. And then Okay. I’m sorry. Go ahead, please. Oh, yeah. Not a problem. And then what comms platform do you actually use to communicate? Your primary systems are gone, and they’re connected to your identity, then you have no access to those systems anymore. So now you don’t even have the ability to communicate internally. If you have access to out of band tools, and we’ll get into that a little more later, are they connected by SSO? Does the threat actor already have access to that information? And that’s a big risk. Even if you’ve got an isolation mode in those tool sets, how long has the threat actor been in your environment? They likely have access to the out of band platform that had an SSO connection at some point. So the breakdown of those communications makes coordinating response or whatever you are dealing with incredibly difficult in these situations. Okay. I suspect communications can get messy fast during a cyber attack. How should organizations prepare to communicate when their usual tools may not may be unsafe or just unavailable, as you just said. Yeah. Even if an organization doesn’t completely lose access to comms during a critical incident, can the platform be trusted? Do you definitively understand who’s connected at any given point in time in listening? I’ve been in far too many conversations in the last eighteen months where organizations have been dealing with major incidents involving cyber attacks, where the threat actor was actually sitting on the bridge with them. And it makes it extremely difficult to get ahead of the threat actor if they’re three steps ahead of you because they’ve got all of your planning information and are listening to how you’re trying to battle them. So an organization must have a trusted out of band communications platform to use during critical incidents. And this platform cannot have any dependency at any point in time on the primary identity. So SSO with isolation mode, in my opinion, not good enough. Then from there, you have to run communications drills. And this is a situation where you should mandate internally, and this is something you can surprise your organization with when you’ve got the proper out of band tooling. How quickly can you kick over to those tool sets to begin communicating? This is something that needs to be exercised regularly so we understand the processes. And if you are able to do that and do it efficiently, you’re taking a lot of complexity out of that response. Right. So practice makes perfect, guess. Absolutely. So you talked about isolating and controlling communications during an incident. What does that look like in practice? So in practice, it really involves procuring a solution that provides out of band communication that meets your organizational requirements. So when you’re looking at comms platforms, what type of functionality do you need in there? Do you need voice? Do you need video? Do you need screen share? Do you need chat capability? Do you have to have multiple lines of communication that are available to you? Or is a single line enough? And then from there, you have to assess that this platform has to be completely isolated and disconnected from your primary identity platforms, because that’s part of what we’re protecting against, and shielded from the blast radius of whatever attacks that we’re potentially able to fall victim to. And then you have to be able to maintain security on that platform. You have to be able to control who has access to that platform in the event of needing it for a real world scenario. Okay. So during a crisis, teams, you know, need to move quickly, obviously. But how do you they avoid letting urgency override security? Yeah. I mean, crises are the perfect opportunity for threat actors to get deeper access to an environment. And when we’re when we’re using the term crisis, we can mean cyber related or non cyber. And, yeah, if we’re dealing with a crisis that’s not cyber related, that’s actually perfect timing for a threat actor to get an initial foothold in the environment. And so what what threat actors look for are times of of change. So if your organizations publish that there’s a massive change going on, maybe you’ve got situation where you’re replacing systems. There’s a large public bid for a system to be replaced. That’s a perfect timing for a threat actor to try to gain access. Or maybe it’s the chaos of a physical incident that we’re dealing with, something related to a natural disaster or something along those lines. Those are when threat actors slip into the environment. So security has to remain at the forefront. Now, if we’re dealing with any of those types of incidents or cyber related incident, it’s proper planning and exercising of your response to identify gaps in your structure, in your decision making authority, the roles that people assume during these times, and then going through operational testing of that response. Help us act with urgency while still maintaining a secure posture as possible. So really the answer here is preparation and practice help us maintain that level of urgency, but also using security first approach to that. Okay, many organizations have their response plans sitting in binders or on shared drives. What separates a real crisis plan from a document that just sort of sits in a box? The first thing I would say is currency and availability. So how current is your document? So you mentioned sitting in a binder. I’ve talked to a few a handful of organizations that take that approach. When is that binder refreshed? Is it done annually? Is it ever done? So how current is the documentation we have? And then from an availability standpoint, what I would say is where is that information kept and maintained? Is it maintained internally in a SharePoint environment? What happens if we lose access to that environment or an internal file share? It could be anything. We have to make sure that we have access to the environment or to those to that information no matter what happens internally. And so we have to make sure, number one, everything is up to date, and number two, it’s available. And then the second thing I would highlight is how the plans are built. And what I mean by this is we tend to want to be very specific and detailed in the plans we create. And that’s great if you’re dealing with a situation that you can perfectly anticipate. The reality is every situation is different. And so when we create the plans that are so specific, they instantly become obsolete because the incident we’re dealing with isn’t following the roadmap we expect. And so instead of creating hundreds of plans for specific situations, we should be focusing on creating plans or fewer plans that are more simplified. But they address roles and responsibilities in these response situations, decision making authority, how we communicate, who we communicate to, and what regulatory obligations we’re responsible for, amongst other things as well. But by doing this, by focusing on the right information in those plans, we’re able to be flexible in other areas of response while still maintaining proper visibility, governance and communications on the incidents we’re dealing with. So how often would you say agencies should be testing, these plans and what should those exercises actually look like? So testing of plans should be done multiple times per year and in multiple formats. You should be running tabletops at least a couple of times a year, but it’s also more important to run more operational tests as well. Tabletops are great for identifying gaps in policy, strategic roles. But what they don’t test is the stress of a live situation. And they don’t test necessarily implementing the response. Basically, if you only perform tabletops, when we face an incident, there’s usually operational issues that creep up because we never actually practice the operationalization of the response effort itself. There’s no muscle memory there. Right. And so it’s really important to include a number of different types of exercises when you’re performing that testing. Okay, so, you know, what kinds of tabletop exercises should simulations, you know, tend to reveal, you know, the biggest gaps? Yeah. With the tabletop, again, we’re looking at policy alignment, strategic roles, but it does miss the stress timing and system failure impact of what we’re actually dealing with. One thing to say we could do something, but can we actually operationalize that when it matters? As we can see on the screen here, we’ve also got communications drills, and I did mention this a little earlier. And that’s being able to test our alternative channels and logins to the infrastructure that we’re using to help facilitate that. And what it can miss though, if you don’t implement it correctly is is cross team synchronization gaps. And and so, what we want to make sure is when we do test our comms drills that we’re involving different teams from different areas and making sure we’re looking at it at scale, not just in small groups necessarily. You’ve got operational drills, which help with logistics and resource pipelines. Basically, the logistics of the response effort. So who’s going to be involved? How do we operationalize that? How do we track what’s going on during the response effort and things like that? And then live fire exercises. And this is critical for more of a technical aspect. So active defense and recovery mechanics. The ideal situation, I know it’s difficult to do, is to really be able to get to the point where you can exercise an enterprise wide war game where you’re basically integrating all of these components into one big scenario, and you’re able to validate all of these elements at once. It’s extremely difficult to get scheduled and actually carry through. But if you’re in the position to be able to do that, you’re in a much better scenario from a response standpoint, and it it definitely will make a difference. Okay. So you’ve been at this a while. In your opinion, where do cybersecurity emergency management, IT operations and leadership teams most often fall out of sync? I think, in my opinion, it’s usually, competing priorities. And, yeah, it’s rarely technical. It’s typically operational and cross functionally. Take the who approves what bottleneck. So you’ve got a situation where you need approval for something. Where do you go for that? The security team probably wants to isolate networks, stop data exfiltration, and things like that. Then you get operations that needs to stay online to be able to serve their their consumers. You’ve got legal wanting to preserve data evidence. And then you’ve got your engineering team that’s looking to wipe and rebuild as soon as they possibly can, Can finance get emergency funding, to provide to a forensics vendor, if their banking lines are shut down? How does HR handle payroll? So there’s so many competing priorities that that’s really where teams most often fall out of sync. What a mess. Okay. So what mistakes, do you find public sector organizations commonly make when planning for identity related attacks? I think this is actually a fairly simple answer. And it’s really that not understanding the full dependency impact of an identity related attack. So and it might not be the technical teams that don’t understand that. It’s usually the business itself, like up the organizational chain, so to speak, where the impact might not be fully understood. And so it’s not prioritized as highly as it probably should be. I think in the last few years, this is starting to change because of the focus on identity during the attack life cycle. So I’m optimistic that we’re getting to the point where everybody’s starting to put the right level of urgency on that. But traditionally, this is where I’ve seen the biggest issue is just around prioritization based off of understanding. Okay. So for agencies with limited budgets and small teams, what are the first moves that will make the biggest difference? If we’re talking about, crisis tooling or crisis planning, Having a proper tool set in place can move the maturity needle quite a bit without putting a lot of time and effort into it. By by crisis tooling, I mean, having an out of band platform that allows you to store your information, be it contact information, be it response plans, continuity, downtime procedures, that type of information, as well as the ability to communicate during a critical scenario, as well as being able to operationalize and track your response, that can move your maturity needle quite a bit. Even if your plans aren’t fully fleshed out, at least you’ve got somewhere to go where you can begin to respond. Okay. So finally, I I guess if if you could leave public sector leaders with one thing to do before the next crisis hits, what would that be? So I’ve actually got three recommendations that would make in this scenario. And these are something that can be done fairly easily. What I would say is the first objective would be to map your top three business critical process to identify dependencies. So what are the three most important things for your organization to be able to meet its mission? And then look at the dependencies that go into that. From there, you define or align these functions with your North Star. What truly matters to your organization? How do we leverage these three processes to maintain our operations? And then from there, you run a cross functional exercise with leaders and executives. Are there key decision points that require authority outside of normal? You have to be able authority you have to be document those. Because when it happens for real, and you need someone to be able to make that decision when when the bullets are really flying, you have to be able to have the authority to do that or access to the person that does. Okay, that’s all the questions I’ve got for you, but I’d love to get some questions from attendees. You up for a few questions from our our viewers? Absolutely. Okay, folks. Remember, can type your questions into the Q and A box at any time. We’ll do our very best to get to all of them. Let me look at the questions here. Okay, so we’ve got one from Al who’s wondering who says, You mentioned crisis tools being able to help mature quickly. What types of wait, you mentioned crisis tools being able to help mature quickly. What types of tools are required for managing major incidents or crises? Yeah. When you’re looking at tooling around managing major incidents or crises, the first thing you want to look at is disconnection. And what I mean by that is you want something again, I’ve mentioned this a few times throughout our conversation is completely shielded from the blast radius of your internal identity. So it cannot be dependent in any way, shape, or form. From there, we need to be able to store information like contact information, our response plans, downtime information, continuity information, support contracts, any executive crown jewels, legal information, everything that we’ll need to properly formulate a response and to support those activities. From there, we get into communications. You have to be able to communicate in a crisis scenario. And you have to be able to control who has access. So what I mean from that is if you’ve got a scenario where you have a communications platform, but anybody can dial into that platform, should they find out the number for that conference line, the password for it is pretty easy to discover, that that’s not control. You have to be able to authenticate to these platforms to be able to control who has access. And then from there, you have to be able to stand up multiple lines of communication because you might not just need one line for a crisis team or something along those lines. Each of the response teams involved or each of the teams involved in response may need to have their own individualized line of communication. Then from there, you need to be able to track response. You need to be able to provision tasks to different people within your organization or supporting third party organizations and get visibility into what’s actually going on without having a million spreadsheets flying back and forth because that gets confusing and difficult to report on. And so in my opinion, all of those functions kind of bleed into what you should be looking at from a crisis management solution. Okay. We’ve got one here from Sunny, who is wondering who should be involved in tabletop exercises? Are there different types? That’s a great question. And there are different types of tabletop exercises. You’ve got your technical tabletops, you’ve got your executive tabletops, you’ve got cross functional tabletops. And really, who’s involved at any given point in time is really dependent on what you’re looking to test and define during the tabletop exercise. I would definitely say it’s important to run a couple of executive level tabletops in any given year. The reason being is that’s typically where decision authority, policy and different things like that are formulated, as well as potentially where the biggest gaps exist when we’re dealing with a major incident or crisis. From there, we should be executing technical tabletops. Now these technical tabletops can be quite small and well defined in nature, or they can be broader than involve more teams. But I would definitely take any given technical team in an organization and run at least one tabletop annually for individual teams, well then executing additional tabletops for cross technical team functionality as well. And then the third type I’d really focus on are fully cross functional tabletops, where we’re involving executive leadership as well as different technical resources to be able to get into more of those live fire exercises that we were talking about and be able to more I guess, provide a more well rounded tabletop that involves more moving parts so that the executive team understands the technical team requirements. The technical team then understands the executive process, procedure, and decision making authority and different things like that. So, the three main ones that I’ve identified, and, yeah, I think that should pretty much answer that. Okay. All right. We’ve got checking my clock. So we’ve got time for one more question. This is a little kind of a long one. It’s from Perry. We are looking at developing business continuity and crisis plans, but are having a tough time determining where to start. Do you have any recommendations on where to begin the process? Yeah. And this is something I’ve run into quite a bit is where to start piece. And I think the picture on the screen is a little appropriate for that, is it’s kind of like trying to eat an elephant. You have to do it one bite at a time. When you’re looking at building your business continuity and crisis plans, the first thing that’s important is to really understand what the organizational mission is. So what is your key mission, with whatever you’re doing? If it’s, emergency services, you’re there to save lives. So what do you need to do to support yourself to be able to save lives? From there, you have to perform a business impact assessment. Understand what different departments in your organization are reliant or or what tasks they perform, what systems they’re reliant on to do that, and how does that fold into your mission. Once you understand that, it becomes much easier to start developing continuity plans and crisis management plans. Because you understand your core mission, you now understand the processes that go into delivering that core mission. Now you can identify what those processes have for dependencies within your technical environment. By identifying those key dependencies, we now understand where our focus should be first when you’re getting into the situations where those systems are not available anymore. Do you have downtime procedures that can help mitigate those systems being offline? Is it possible to build those downtime procedures? Some systems, you may not be able to do that. Some systems, it might be easy to be able to set up downtime procedures. From there, get into, okay, if we’ve got downtime procedures, how long can we use those downtime downtime procedures to maintain effective operations? Is it an hour? Is it a week? Is it a month? Once you’ve identified all of that, creating a response plan that or a business continuity plan that addresses those needs becomes much more simple. We understand the systems that we’re dependent on to deliver our core mission. We understand where we can get away with those systems being off line a little longer and where we can’t get away with that. And from there, we can start prioritizing what our response effort looks like from a recovery standpoint. And that’s where we really get into that business continuity conversation. And how do we keep the lights on? So where we got downtime procedures, we may not need to focus on them quite as urgently. Where we don’t have the ability to create those, we’ve got to focus on those yesterday. And that’s all the time we have for this Tech Talk. Many thanks to Josh Wagman for his sharp insights and for sharing his experience with us and to Semperis for making this conversation possible. We couldn’t have done it without them. Thanks everyone and have a great day.
