SlideShare a Scribd company logo
Learn how our business continuity planning services can protect your company at www.cbiz.com/ras
RISK ADVISORY
Our business is growing yours
Over the past few decades, the world’s economic and political infrastructures have been tested by
physical and virtual terrorist attacks. If a business is targeted, transnational criminal organizations can
destroy years of success and profitability in matter of minutes.
How to Build an Actionable
Incident Response & Recovery Strategy
These criminal networks are expanding and diversifying
their activities, which increases the difficulty for
businesses that are preparing response strategies that
include potential terrorist threats. In the wake of the
recent terrorist attacks in Paris and San Bernardino,
companies are reassessing their own disaster response
and recovery plans to make sure they account for
potential terrorist threats to day-to-day operations.
Preparing for internal and external risks can help protect
your business, but it is impossible to predict exactly how
or when disaster will strike. Focusing too narrowly on
specific incidents when designing your incident response
strategy could hinder your company’s ability to train your
staff and react when faced with a threatening situation.
When creating your strategy, it is crucial to establish
a framework that allows you to respond quickly in any
situation. Regardless of the cause of the business
disruption, the following four components will help
you create a simple, yet holistic incident response and
recovery strategy that is easy to implement.
Loss of Facilities
Immediately following the deadly shootings and
explosions in Paris, French authorities closed major
landmarks and cultural facilities, such as the Bataclan
Theatre, the Eiffel Tower and the Louvre Museum.
When an incident renders a facility unavailable for
normal business operations, it can lead to devastating
financial and functional consequences for the company.
Regardless what causes the loss of facility, your strategy
Learn how our business continuity planning services can protect your company at www.cbiz.com/ras
RISK ADVISORY
Our business is growing yours
©Copyright2015.CBIZ,Inc.NYSEListed:CBZ.Allrightsreserved.
needs to include how your business will continue its
operations without disruption. This might include allowing
your employees to continue their work from home or
identifying a temporary alternative location for your
staff, such as a client facility or community collaborative
workspace.
Loss of People
Even if your facility remains intact after an incident
occurs, your staff could be divided. Personal tragedy,
illness or injury can render key employees unavailable or
incapable of making critical decisions necessary to get
your business back on track. Part of your overall strategy
should include the cross-training of your staff so that
each member is prepared to step in to perform critical
functions should another employee be unavailable.
Documenting your processes and procedures can ease
the burden of training and provides employees with
reference materials if necessary. It may also be valuable
to identify an outside third party that could assist your
team with critical functions in situations that would
cause large members of your staff to be unavailable.
Loss of Technology
Not every incident will be physical. In 2014, JP Morgan
experienced a data breach that compromised an
estimated 83 million customer records. As today’s
business environment increases its dependency on
information technology, companies need to have a
plan in place that helps them recognize when a cyber-
attack is occurring, react quickly to stop the breach and
recover in a way that addresses both the short- and long-
term problems from unauthorized access. Identifying
potential system workarounds can keep your operations
functioning should you lose the use of a system during
an attack. Knowing exactly how long your company can
continue to deliver client service without a particular
system can help you create a recovery timeline once an
outage or breach is contained.
Loss of Vendors
Even if you take loss of facility, people and technology
into consideration, your incident response strategy is
only as strong as the third party vendors you rely on
to deliver goods or services. These vendors should
be prepared to step in and assist should an incident
happen to your company. Additionally, companies
should expect that a vendor’s disaster recovery plan
offers protection for their company, as clients expect
that you are protected if the disaster strikes on the
vendor’s end. For example, in 2013 hackers were able
to access 40 million Target customer debit and credit
card accounts by intruding into their systems through
credentials stolen from a refrigeration, heating and air
conditioning subcontractor. Your company should have a
few alternative vendors identified that you could rely on
should your primary vendor be compromised.
Your primary objective when designing an incident
response and business continuity strategy is to create
something that is actionable. Writing a plan that includes
recovery steps for every possible scenario will most
likely result in a complex document that isn’t practical
when employees need to act quickly. The key to a strong
response and recovery plan is not to over-complicate the
context. Your strategy should account for places, people
and procedures, and it should be able to work in multiple
situations. Over time, you can and should adjust or build
upon your strategy as your company grows and evolves.
If you have any specific questions, comments
or concerns about incident response and
business continuity planning, please contact:
Mark Madar
CBIZ Risk & Advisory Services
RASinfo@cbiz.com | 866.956.1983

More Related Content

Recently uploaded

What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...AnaBeatriz125525
 
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...Rahul Bedi
 
Cracking the Change Management Code Main New.pptx
Cracking the Change Management Code Main New.pptxCracking the Change Management Code Main New.pptx
Cracking the Change Management Code Main New.pptxWorkforce Group
 
IPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceIPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceDragon Dream Bar
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowMiriam Robeson
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptxrdishurana
 
Vendors of country report usefull datass
Vendors of country report usefull datassVendors of country report usefull datass
Vendors of country report usefull datassDilipParmar63
 
Event Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridEvent Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridHolger Mueller
 
Using Generative AI for Content Marketing
Using Generative AI for Content MarketingUsing Generative AI for Content Marketing
Using Generative AI for Content MarketingChuck Aikens
 
Falcon Invoice Discounting Setup for Small Businesses
Falcon Invoice Discounting Setup for Small BusinessesFalcon Invoice Discounting Setup for Small Businesses
Falcon Invoice Discounting Setup for Small BusinessesFalcon investment
 
TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024Adnet Communications
 
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product DiscoveryDesmond Leo
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettJacobBadgett
 
Raising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE VenturesRaising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE VenturesAlejandro Cremades
 
Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)Alejandro Cremades
 
India’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfIndia’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfCIOLOOKIndia
 
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...ssuserf63bd7
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportDubai Multi Commodity Centre
 
USA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfUSA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfsuperbizness1227
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesDragon Dream Bar
 

Recently uploaded (20)

What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
 
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
 
Cracking the Change Management Code Main New.pptx
Cracking the Change Management Code Main New.pptxCracking the Change Management Code Main New.pptx
Cracking the Change Management Code Main New.pptx
 
IPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceIPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best Service
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to Know
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptx
 
Vendors of country report usefull datass
Vendors of country report usefull datassVendors of country report usefull datass
Vendors of country report usefull datass
 
Event Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridEvent Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybrid
 
Using Generative AI for Content Marketing
Using Generative AI for Content MarketingUsing Generative AI for Content Marketing
Using Generative AI for Content Marketing
 
Falcon Invoice Discounting Setup for Small Businesses
Falcon Invoice Discounting Setup for Small BusinessesFalcon Invoice Discounting Setup for Small Businesses
Falcon Invoice Discounting Setup for Small Businesses
 
TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024
 
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob Badgett
 
Raising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE VenturesRaising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE Ventures
 
Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)
 
India’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfIndia’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdf
 
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
 
USA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfUSA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdf
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and Employees
 

Featured

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
 

Featured (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

How to Build an Actionable Incident Response & Recovery Strategy

  • 1. Learn how our business continuity planning services can protect your company at www.cbiz.com/ras RISK ADVISORY Our business is growing yours Over the past few decades, the world’s economic and political infrastructures have been tested by physical and virtual terrorist attacks. If a business is targeted, transnational criminal organizations can destroy years of success and profitability in matter of minutes. How to Build an Actionable Incident Response & Recovery Strategy These criminal networks are expanding and diversifying their activities, which increases the difficulty for businesses that are preparing response strategies that include potential terrorist threats. In the wake of the recent terrorist attacks in Paris and San Bernardino, companies are reassessing their own disaster response and recovery plans to make sure they account for potential terrorist threats to day-to-day operations. Preparing for internal and external risks can help protect your business, but it is impossible to predict exactly how or when disaster will strike. Focusing too narrowly on specific incidents when designing your incident response strategy could hinder your company’s ability to train your staff and react when faced with a threatening situation. When creating your strategy, it is crucial to establish a framework that allows you to respond quickly in any situation. Regardless of the cause of the business disruption, the following four components will help you create a simple, yet holistic incident response and recovery strategy that is easy to implement. Loss of Facilities Immediately following the deadly shootings and explosions in Paris, French authorities closed major landmarks and cultural facilities, such as the Bataclan Theatre, the Eiffel Tower and the Louvre Museum. When an incident renders a facility unavailable for normal business operations, it can lead to devastating financial and functional consequences for the company. Regardless what causes the loss of facility, your strategy
  • 2. Learn how our business continuity planning services can protect your company at www.cbiz.com/ras RISK ADVISORY Our business is growing yours ©Copyright2015.CBIZ,Inc.NYSEListed:CBZ.Allrightsreserved. needs to include how your business will continue its operations without disruption. This might include allowing your employees to continue their work from home or identifying a temporary alternative location for your staff, such as a client facility or community collaborative workspace. Loss of People Even if your facility remains intact after an incident occurs, your staff could be divided. Personal tragedy, illness or injury can render key employees unavailable or incapable of making critical decisions necessary to get your business back on track. Part of your overall strategy should include the cross-training of your staff so that each member is prepared to step in to perform critical functions should another employee be unavailable. Documenting your processes and procedures can ease the burden of training and provides employees with reference materials if necessary. It may also be valuable to identify an outside third party that could assist your team with critical functions in situations that would cause large members of your staff to be unavailable. Loss of Technology Not every incident will be physical. In 2014, JP Morgan experienced a data breach that compromised an estimated 83 million customer records. As today’s business environment increases its dependency on information technology, companies need to have a plan in place that helps them recognize when a cyber- attack is occurring, react quickly to stop the breach and recover in a way that addresses both the short- and long- term problems from unauthorized access. Identifying potential system workarounds can keep your operations functioning should you lose the use of a system during an attack. Knowing exactly how long your company can continue to deliver client service without a particular system can help you create a recovery timeline once an outage or breach is contained. Loss of Vendors Even if you take loss of facility, people and technology into consideration, your incident response strategy is only as strong as the third party vendors you rely on to deliver goods or services. These vendors should be prepared to step in and assist should an incident happen to your company. Additionally, companies should expect that a vendor’s disaster recovery plan offers protection for their company, as clients expect that you are protected if the disaster strikes on the vendor’s end. For example, in 2013 hackers were able to access 40 million Target customer debit and credit card accounts by intruding into their systems through credentials stolen from a refrigeration, heating and air conditioning subcontractor. Your company should have a few alternative vendors identified that you could rely on should your primary vendor be compromised. Your primary objective when designing an incident response and business continuity strategy is to create something that is actionable. Writing a plan that includes recovery steps for every possible scenario will most likely result in a complex document that isn’t practical when employees need to act quickly. The key to a strong response and recovery plan is not to over-complicate the context. Your strategy should account for places, people and procedures, and it should be able to work in multiple situations. Over time, you can and should adjust or build upon your strategy as your company grows and evolves. If you have any specific questions, comments or concerns about incident response and business continuity planning, please contact: Mark Madar CBIZ Risk & Advisory Services RASinfo@cbiz.com | 866.956.1983