SlideShare a Scribd company logo
1 of 22
Download to read offline
Raj Goel, CISSP
raj@brainlink.com / 917-685-7731
www.RajGoel.com
www.ITSecurityConsultant.com
@RajGoel_NY
Grab them from
www.RajGoel.com/surveillance-notes/
2 ©2013 Raj Goel / Raj Goel, CISSP / raj@brainlink.com / 917-685-7731
…and he executes better than you.
In the last decade, New York City has
experienced:
• Multi-state power blackouts
• 9/11 World Trade Center Collapse
• Con-Ed steam pipe explosions
• Tornadoes & Cyclones
• Earthquakes
• Sandy
© Bob Gorrell, www.GorrellArt.com
…but we still need gas.
• For the 1st time in decades, NYC
implemented gas rationing.
• Even is people had power in
their homes, and their
neighborhoods were
functioning, lack of gasoline
kept people at home.
…but water is still king.
• Rising tides & storm
surges caused 5
nuclear reactors to go
offline.
(Fukushima Daiichi
problems were multiplied by
ocean water flooding the
backup generators).
• Reactors going offline
or being forced
offline caused further
strain on the
electrical grid
If you live in a flood zone,
putting transformers or
generators in the basement
isn’t the smartest idea.
Nurses and staff saved
countless lives by carrying
patients out of the hospital
manually. NYU’s BCP & DR
plan was inadequate.
Just like pizza, even bad ones
are better than nothing.
Even after LIPA & ConEd
stopped updating their maps,
knowing which areas were out,
and which ones were functional
allowed us to deal with
employees better.
…as long as you have redundant
fuel as well.
Peer 1’s data center had
generators on 2nd floor.
Peer 1 had their own generator
on 17th floor as backup.
Basement flooded – building
generators offline. Peer1 kept
running…until diesel almost ran
out.
Normal Hertz rate: $300/wk
Sandy rates: $2000/wk
Normal hotel rate: $300/night
Sandy rates: $800/night
Helicopter hired by photographer Iwan
Baan required cash up front to charter the
chopper.
We had spare servers, drives, switches &
firewalls set aside for clients BEFORE the
storm.
Do you?
A large, multinational firm
with thousands of employees
globally hosted their exchange
servers from NYC HQ. NYC lost
power for a week.
No one had emails…globally.
(CIO/COO had rejected
previous recommendations for
redundant data centers and
offsite backups).
1) Shutting down the traffic tunnels
and subway lines was the best
decision NYC’s government made.
2) Keeping cars and unnecessary
vehicles off the street was a smart
decision. This also made subsequent
recovery faster.
3) Chris Christie (NJ Governor) calling
mayors stupid for not evacuating
when ordered to – SMART!
Saved thousands of lives and billions
in losses.
Are your employee contact lists up
to date?
Do you have out-of-state next-of-kin
info?
Cellphones? IM/Skype IDs? Home
phones? Spouse & children names,
ages, contact info?
Prescription & OTC medications on
hand?
NYC MTA has plastered these signs across all the train
stations, tunnels, bridges that they are repairing OR
strengthening
How does your firm communicate post-disaster / post-breach
cleanup and remediation?
Before the storm
1.We tested all client backups in the DR center
2.Ensured we have contact info for clients, client staff, family
members
3.We published the DISASTER PREPAREDNESS TIPS page
• http://www.brainlink.com/2012/10/tropical-storm-sandy-disaster-
preparedness-tips/
During the storm
1.I published a daily blog updating clients (and others) with
resources for recovery.
• http://www.brainlink.com/2012/10/sandy-recovery-resources/
• Free or low-cost office space, places to sleep or get hot food, hot showers,
etc.
2.Called, texted, skype’d clients, employees, family members for
48 hours.
After the storm
1.We visited every client
2.Replaced many UPSes and power strips
3.Reviewed DR & BCP Plans
4.Clients purchased redundant / backup circuits for single-homed
clients
5.More clients adopted virtualization
1. Large, unprecedented events will happen more frequently
2. Review building codes and best practices
3. Power (and fuel) is KEY.
4. Budget for spare resources.
5. Geographical redundancy is imperative
6. How your city or state plans for disasters MATTERS!
7. People are more important than technology
Patron: “Barkeep, make me a Sandy!”
Barkeeper: “What’s that?”
Patron: “You know…a watered down Manhattan :-) “
They should have named the storm A-Rod.
Why?
Because then, it wouldn’t have hit anything.
Raj Goel, CISSP
C: 917-685-7731
raj@brainlink.com
www.RajGoel.com
www.linkedin.com/in/rajgoel
www.ITSecurityConsultant.com
@RajGoel_NY
Author of “The Most Important SecretsTo Getting Great Results From IT”
http://www.amazon.com/gp/product/0984424814
22 ©2013 Raj Goel / Raj Goel, CISSP / raj@brainlink.com / 917-685-7731

More Related Content

Similar to 2013-09-23-ASIS59-Raj_Goel_Lessons_Learned_From_Sandy_v1d

Assignment 1_Case Study: Tornado
Assignment 1_Case Study: TornadoAssignment 1_Case Study: Tornado
Assignment 1_Case Study: Tornado
talipb
 
Renewable Energy Presentation
Renewable Energy PresentationRenewable Energy Presentation
Renewable Energy Presentation
Evan Norman
 
Michael STAVY was quoted on grid stability in the April 24, 2013 New York Times
Michael STAVY was quoted on grid stability in the April 24, 2013 New York TimesMichael STAVY was quoted on grid stability in the April 24, 2013 New York Times
Michael STAVY was quoted on grid stability in the April 24, 2013 New York Times
Michael Stavy, Consulting Energy Economist
 
Back-up Webinar presentation 5-2013
Back-up Webinar presentation 5-2013Back-up Webinar presentation 5-2013
Back-up Webinar presentation 5-2013
Larry Stapleton
 
How Thermal Storage Can Save the Grid
How Thermal Storage Can Save the GridHow Thermal Storage Can Save the Grid
How Thermal Storage Can Save the Grid
Elton Sherwin
 

Similar to 2013-09-23-ASIS59-Raj_Goel_Lessons_Learned_From_Sandy_v1d (20)

Analysis of Community Microgrids: The path to resilient and sustainable commu...
Analysis of Community Microgrids: The path to resilient and sustainable commu...Analysis of Community Microgrids: The path to resilient and sustainable commu...
Analysis of Community Microgrids: The path to resilient and sustainable commu...
 
Case Study :: Small Wind Turbines in the Built Environment Decommissioning Guide
Case Study :: Small Wind Turbines in the Built Environment Decommissioning GuideCase Study :: Small Wind Turbines in the Built Environment Decommissioning Guide
Case Study :: Small Wind Turbines in the Built Environment Decommissioning Guide
 
Community Wind -- It's Needed In the SF Bay Area
Community Wind -- It's Needed In the SF Bay Area Community Wind -- It's Needed In the SF Bay Area
Community Wind -- It's Needed In the SF Bay Area
 
Community Wind—It’s needed in the SF Bay Area
Community Wind—It’s needed in the SF Bay AreaCommunity Wind—It’s needed in the SF Bay Area
Community Wind—It’s needed in the SF Bay Area
 
Assignment 1_Case Study: Tornado
Assignment 1_Case Study: TornadoAssignment 1_Case Study: Tornado
Assignment 1_Case Study: Tornado
 
Dragos & SRP, PI World 2019: Utilizing Operations Data for Enhanced Cyber Thr...
Dragos & SRP, PI World 2019: Utilizing Operations Data for Enhanced Cyber Thr...Dragos & SRP, PI World 2019: Utilizing Operations Data for Enhanced Cyber Thr...
Dragos & SRP, PI World 2019: Utilizing Operations Data for Enhanced Cyber Thr...
 
Michael was quoted on Grid Stability in the NYT
Michael was quoted on Grid Stability in the NYTMichael was quoted on Grid Stability in the NYT
Michael was quoted on Grid Stability in the NYT
 
Earliest days SIM reactor suite models
Earliest days SIM reactor suite modelsEarliest days SIM reactor suite models
Earliest days SIM reactor suite models
 
Goleta Load Pocket Community Microgrid: Renewables-driven Resilience for the ...
Goleta Load Pocket Community Microgrid: Renewables-driven Resilience for the ...Goleta Load Pocket Community Microgrid: Renewables-driven Resilience for the ...
Goleta Load Pocket Community Microgrid: Renewables-driven Resilience for the ...
 
What We Do Before, During, and After an Emergency - Steve Greenley, Center Po...
What We Do Before, During, and After an Emergency - Steve Greenley, Center Po...What We Do Before, During, and After an Emergency - Steve Greenley, Center Po...
What We Do Before, During, and After an Emergency - Steve Greenley, Center Po...
 
The 100 Year Storm...Every Year
The 100 Year Storm...Every YearThe 100 Year Storm...Every Year
The 100 Year Storm...Every Year
 
Idealife dev.plan 2014
Idealife dev.plan 2014Idealife dev.plan 2014
Idealife dev.plan 2014
 
Renewable Energy Presentation
Renewable Energy PresentationRenewable Energy Presentation
Renewable Energy Presentation
 
DOW Public Meeting Slides 2.5.20
DOW Public Meeting Slides 2.5.20DOW Public Meeting Slides 2.5.20
DOW Public Meeting Slides 2.5.20
 
Michael STAVY was quoted on grid stability in the April 24, 2013 New York Times
Michael STAVY was quoted on grid stability in the April 24, 2013 New York TimesMichael STAVY was quoted on grid stability in the April 24, 2013 New York Times
Michael STAVY was quoted on grid stability in the April 24, 2013 New York Times
 
Back-up Webinar presentation 5-2013
Back-up Webinar presentation 5-2013Back-up Webinar presentation 5-2013
Back-up Webinar presentation 5-2013
 
The Community Microgrid Initiative: The path to resilience and sustainability
The Community Microgrid Initiative: The path to resilience and sustainabilityThe Community Microgrid Initiative: The path to resilience and sustainability
The Community Microgrid Initiative: The path to resilience and sustainability
 
DOW Public Meeting Slides 12.19.19
DOW Public Meeting Slides 12.19.19DOW Public Meeting Slides 12.19.19
DOW Public Meeting Slides 12.19.19
 
How Thermal Storage Can Save the Grid
How Thermal Storage Can Save the GridHow Thermal Storage Can Save the Grid
How Thermal Storage Can Save the Grid
 
Centralised Vs Decentralised
Centralised Vs  DecentralisedCentralised Vs  Decentralised
Centralised Vs Decentralised
 

More from Raj Goel

2016-09-05-Lessons_Learned_From_The_FTC_v1c
2016-09-05-Lessons_Learned_From_The_FTC_v1c2016-09-05-Lessons_Learned_From_The_FTC_v1c
2016-09-05-Lessons_Learned_From_The_FTC_v1c
Raj Goel
 
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
Raj Goel
 
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
Raj Goel
 
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
Raj Goel
 
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
Raj Goel
 
Google Health - NYHIMA
Google Health - NYHIMAGoogle Health - NYHIMA
Google Health - NYHIMA
Raj Goel
 
2009 10 21 Rajgoel Trends In Financial Crimes
2009 10 21 Rajgoel Trends In Financial Crimes2009 10 21 Rajgoel Trends In Financial Crimes
2009 10 21 Rajgoel Trends In Financial Crimes
Raj Goel
 

More from Raj Goel (12)

2016-09-05-Lessons_Learned_From_The_FTC_v1c
2016-09-05-Lessons_Learned_From_The_FTC_v1c2016-09-05-Lessons_Learned_From_The_FTC_v1c
2016-09-05-Lessons_Learned_From_The_FTC_v1c
 
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
2013-09-13-DATTO_What_Should_MSPs_Know_About_Compliance_v3h
 
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
2016-10-20-Growing_Your_MSP_with_SOPCulture_SMBTECHFEST_v1c
 
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
2013-06-26-Is_your_company_Googling_its_privacy_away_brightalk_format_1c
 
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
JSD-RG HIPAA-EHR-BreachNotification Oct20-2009
 
Raj Goel - Social Media & Cloud Computing Threats to Privacy, Security & Libe...
Raj Goel - Social Media & Cloud Computing Threats to Privacy, Security & Libe...Raj Goel - Social Media & Cloud Computing Threats to Privacy, Security & Libe...
Raj Goel - Social Media & Cloud Computing Threats to Privacy, Security & Libe...
 
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
2011 10 19 Raj Goel Isc2 Secure Boston Cloud Computing Oversharing Over Colle...
 
2010 10 27 Isc2 Protecting Consumer Privacy
2010 10 27 Isc2 Protecting Consumer Privacy2010 10 27 Isc2 Protecting Consumer Privacy
2010 10 27 Isc2 Protecting Consumer Privacy
 
Grow your Law Practice Using LinkedIn
Grow your Law Practice Using LinkedInGrow your Law Practice Using LinkedIn
Grow your Law Practice Using LinkedIn
 
Cloud Computing Panel - NYCLA
Cloud Computing Panel - NYCLACloud Computing Panel - NYCLA
Cloud Computing Panel - NYCLA
 
Google Health - NYHIMA
Google Health - NYHIMAGoogle Health - NYHIMA
Google Health - NYHIMA
 
2009 10 21 Rajgoel Trends In Financial Crimes
2009 10 21 Rajgoel Trends In Financial Crimes2009 10 21 Rajgoel Trends In Financial Crimes
2009 10 21 Rajgoel Trends In Financial Crimes
 

2013-09-23-ASIS59-Raj_Goel_Lessons_Learned_From_Sandy_v1d

  • 1. Raj Goel, CISSP raj@brainlink.com / 917-685-7731 www.RajGoel.com www.ITSecurityConsultant.com @RajGoel_NY
  • 2. Grab them from www.RajGoel.com/surveillance-notes/ 2 ©2013 Raj Goel / Raj Goel, CISSP / raj@brainlink.com / 917-685-7731
  • 3. …and he executes better than you. In the last decade, New York City has experienced: • Multi-state power blackouts • 9/11 World Trade Center Collapse • Con-Ed steam pipe explosions • Tornadoes & Cyclones • Earthquakes • Sandy © Bob Gorrell, www.GorrellArt.com
  • 4.
  • 5.
  • 6. …but we still need gas. • For the 1st time in decades, NYC implemented gas rationing. • Even is people had power in their homes, and their neighborhoods were functioning, lack of gasoline kept people at home.
  • 7. …but water is still king. • Rising tides & storm surges caused 5 nuclear reactors to go offline. (Fukushima Daiichi problems were multiplied by ocean water flooding the backup generators). • Reactors going offline or being forced offline caused further strain on the electrical grid
  • 8.
  • 9. If you live in a flood zone, putting transformers or generators in the basement isn’t the smartest idea. Nurses and staff saved countless lives by carrying patients out of the hospital manually. NYU’s BCP & DR plan was inadequate.
  • 10. Just like pizza, even bad ones are better than nothing. Even after LIPA & ConEd stopped updating their maps, knowing which areas were out, and which ones were functional allowed us to deal with employees better.
  • 11. …as long as you have redundant fuel as well. Peer 1’s data center had generators on 2nd floor. Peer 1 had their own generator on 17th floor as backup. Basement flooded – building generators offline. Peer1 kept running…until diesel almost ran out.
  • 12. Normal Hertz rate: $300/wk Sandy rates: $2000/wk Normal hotel rate: $300/night Sandy rates: $800/night Helicopter hired by photographer Iwan Baan required cash up front to charter the chopper. We had spare servers, drives, switches & firewalls set aside for clients BEFORE the storm. Do you?
  • 13. A large, multinational firm with thousands of employees globally hosted their exchange servers from NYC HQ. NYC lost power for a week. No one had emails…globally. (CIO/COO had rejected previous recommendations for redundant data centers and offsite backups).
  • 14. 1) Shutting down the traffic tunnels and subway lines was the best decision NYC’s government made. 2) Keeping cars and unnecessary vehicles off the street was a smart decision. This also made subsequent recovery faster. 3) Chris Christie (NJ Governor) calling mayors stupid for not evacuating when ordered to – SMART! Saved thousands of lives and billions in losses.
  • 15. Are your employee contact lists up to date? Do you have out-of-state next-of-kin info? Cellphones? IM/Skype IDs? Home phones? Spouse & children names, ages, contact info? Prescription & OTC medications on hand?
  • 16. NYC MTA has plastered these signs across all the train stations, tunnels, bridges that they are repairing OR strengthening How does your firm communicate post-disaster / post-breach cleanup and remediation?
  • 17. Before the storm 1.We tested all client backups in the DR center 2.Ensured we have contact info for clients, client staff, family members 3.We published the DISASTER PREPAREDNESS TIPS page • http://www.brainlink.com/2012/10/tropical-storm-sandy-disaster- preparedness-tips/
  • 18. During the storm 1.I published a daily blog updating clients (and others) with resources for recovery. • http://www.brainlink.com/2012/10/sandy-recovery-resources/ • Free or low-cost office space, places to sleep or get hot food, hot showers, etc. 2.Called, texted, skype’d clients, employees, family members for 48 hours.
  • 19. After the storm 1.We visited every client 2.Replaced many UPSes and power strips 3.Reviewed DR & BCP Plans 4.Clients purchased redundant / backup circuits for single-homed clients 5.More clients adopted virtualization
  • 20. 1. Large, unprecedented events will happen more frequently 2. Review building codes and best practices 3. Power (and fuel) is KEY. 4. Budget for spare resources. 5. Geographical redundancy is imperative 6. How your city or state plans for disasters MATTERS! 7. People are more important than technology
  • 21. Patron: “Barkeep, make me a Sandy!” Barkeeper: “What’s that?” Patron: “You know…a watered down Manhattan :-) “ They should have named the storm A-Rod. Why? Because then, it wouldn’t have hit anything.
  • 22. Raj Goel, CISSP C: 917-685-7731 raj@brainlink.com www.RajGoel.com www.linkedin.com/in/rajgoel www.ITSecurityConsultant.com @RajGoel_NY Author of “The Most Important SecretsTo Getting Great Results From IT” http://www.amazon.com/gp/product/0984424814 22 ©2013 Raj Goel / Raj Goel, CISSP / raj@brainlink.com / 917-685-7731