By Tam Williams, KingsBridge BCP:
You’ve likely heard the terms before and may have a vague idea of their definition, but how do emergency response, disaster recovery and business continuity really work together during an incident? This blog post will walk you through these phases.
Putting Incident in Context
You are sitting in your office building and the fire alarm goes off. Following health and safety procedures, you head outside and smell smoke. You can see flames coming from the top two floors of the building. The fire department has arrived and is setting up to put the fire out. Your colleagues are moved away from the building, and anyone who is hurt is treated. You are left to wonder when, if ever, you’ll be able to come back to work.
Within three days your IT group has you set up with a laptop so that you can work remotely. You and your colleagues work together online and through conference calls. Eventually, after the damage to the office is fixed, you get a notice that everyone can return to work as normal.
Emergency response is the protection of life, safety, assets and the environment. In the scenario above, this is most of the steps in the first paragraph:
- The detection of a fire and setting off the alarm
- People leaving the building
- The fire department putting the fire out
- Injured colleagues receiving treatment
Business Continuity must include emergency response procedures for the program to be successful, but they are not one and the same thing. At the beginning of an incident the two programs often work in tandem. Once the initial concerns are dealt with, the longer-term business continuity steps are put into effect.
Disaster recovery includes all of the steps that IT takes to get the company’s core systems back online . In the fire instance above, that includes:
- Purchasing, imaging and distributing laptops to employees so they can continue to work;
- Any recovery steps taken to restore damaged servers;
- Ensuring that remote access to the network is available; and
- Making conference calling available for those working remotely.
As discussed above, disaster recovery focuses on the IT services. In contrast, business continuity includes the steps that support all other ongoing business critical operations. This might include processes like payroll, customer support, or accounts payable.
In the scenario above, business continuity encompasses things like:
- The decision made by Senior Management to have you work from home
- Communication of that decision to employees
- The decision to return to the office building
The fact that you are collaborating online while working from home is a business continuity strategy, whereas the actual setup of that infrastructure is a disaster recovery strategy.
As you can see, there is a distinct difference between emergency response, disaster recovery, and business continuity. The roles that each of these plans fill have a distinct focus, yet they all still work together. As a result, the response and recovery after an incident is smooth, efficient, and effective.
About the Author: Tam Williams is a skilled and experienced Business Continuity consultant working with KingsBridgeBCP. She has honed her skills over the past two decades in a number of industries including healthcare, research, information technology, manufacturing, and finance. During that time she has facilitated business continuity workshops and delivered presentations at a number of business continuity conferences throughout North America.