Business Talk questions Business Continuity Expert Andrew Stewart, Managing Director of data protection specialists Datto, on how businesses need to do more to safeguard themselves from major disruption.
Q: From your experience, do most SMEs take disaster recovery/ business continuity seriously enough?
A: Data is growing in size and importance along with IT applications being absolutely critical to all Companies’ productivity. Many Companies are still using traditional backup methods such as tape and disk, or even cloud-only solutions, unaware that these are insufficient and ineffective when faced with downtime and the potential crippling costly effects.
Growth rates of Business Continuity platforms are far exceeding the traditional backup and Disaster Recovery technologies as Companies recognise the benefits. But still, many Organisations are yet to take advantage.
Q: Is it very different in the US?
A: Datto was founded and has its head office in the US. From our experience the US market is ahead of the UK in adoption of Business Continuity. Big weather related disasters are more common in the US and this drives a culture of Companies planning for when disaster strikes, be that from hurricane, flood, power outage, equipment failure, employee error or cyber-attacks. Although UK is less prone to natural disasters, any business not taking Business Continuity seriously is potentially asking for trouble.
Q: Do SMEs understand the difference between Disaster Recovery and Business Continuity?
A: Many businesses have backup, whether tape, software, or out in the Cloud. Although, this lets a business retrieve its data – which is vital – it will still not get a disaster-hit company back on its feet quickly. It’s important that Companies consider both their Recovery Time Objective (RTO) and the cost of the time they are down, as well as the Recovery Point Objective (RPO), the frequency they want to back up their data or, in the event of a disaster, what they would be happy to lose! Datto has an RTO tool on our website (www.datto.co.uk) to assist in calculating the cost of downtime.
Q: Do you think SMEs appreciate the risks they take if they don’t have adequate business continuity in place?
A: Three research papers we use from PriceWaterHouseCooper, Gartner and Forrester state that 70% of small businesses that experience a major data loss go out of business within one year, 25% of PCs will fail this year, and 24% of companies say they have experienced a full data disaster.
Most business owners understand some of the risks but can think they are protected by legacy systems or can’t put a value on the cost of downtime. We’d encourage any business to first look at the RTO calculator and assess the cost to their business if they can’t function and, secondly, to test their current process to see how quickly can they get up and running again.
Q: What top three aspects of business continuity do companies often overlook?
A: Firstly, putting in a Business Continuity solution for your IT systems in place is only part of the process. You must tie other elements of Business Continuity Planning in to ensure successful continuity in the event of a disaster.
Secondly, they push ownership of the Business Continuity Plan to their IT provider and expect seamless execution in the event of a disaster. But often their IT provider doesn’t understand their business end-to-end so they need to take ownership and drive the process internally.
Thirdly, they don’t see value in having or testing a Business Continuity Plan and can be blind to the potential of disaster with significant consequences to the business. To ensure successful continuity they need to ensure all stakeholders are bought into the development and testing of their Business Continuity Plan.
Q: Are there any types of businesses that don’t need to plan for Business Continuity?
A: No. Business Continuity is about keeping your business running and being the most productive it possibly can be. Every business needs that. We have all experienced the frustration running businesses when systems and outside influences stop us from doing our jobs, affect service levels and cost the Company money in lost time and revenue.
Depending on the type and size of your organisation, the solution you put in place will be different and your IT provider is best placed to advise on the appropriate solution.
Q: Who is best to take responsibility for a company-wide ‘Business Continuity’ plan?
A: This often depends on the size and structure of the Company in question. However, it’s vital that a Director or other senior executive within the Company takes overall responsibility and has a full understanding of the plan and its stakeholders. They must also champion the plan internally as often it is seen as an unimportant process.
Q: What tools and support is available to help an SME put Business Continuity in place?
A: Datto works exclusively with our network of partners. We believe our Partners offer skills and services to ensure Business Continuity for their Customers. We’d recommend you to speak with your IT provider and they can arrange a demonstration of the products available and talk about a solution for your particular business.
You can also use datto.co.uk. We have information on our products and whitepapers for further reading. As mentioned earlier I’d suggest using the RTO calculator to review your downtime costs.
Q: What needs to be considered if you have mobile and home workers?
A: It’s important to ensure that all data, which is of business value, is stored on protected systems. There are a number of strategies in this area from ensuring roaming Users store their documents on central file Servers or have file-sync technology to replicate their local documents to a central cloud. Too often mobile Users data has no off-site copy and is lost when the laptop is lost, stolen or damaged.
Q: How best should business continuity be tested and then assessed going forward?
A: There are multiple elements to a Business Continuity Plan of which continuity for your IT systems is a significant part. It is vital that all stakeholders in the business participate in Business Continuity planning along with any external organisations when elements of the infrastructure management have been outsourced, such as IT. The business should then work with all stakeholders to schedule regular testing to ensure all elements work in harmony during execution. Lessons learned can then be used to adjust the plan accordingly.