Cyber Risk, as anyone with a television is aware, is growing at a mind-boggling pace. In a recent presentation, former Homeland Security Secretary Tom Ridge said, "The cyber world presents the greatest threat to U.S. security and
economic well-being. Our infrastructure generally is exposed, raising the possibility of a catastrophe affecting millions of people."
High-profile breaches are an almost every-day occurrence. From the highest level of government, through small businesses, to the largest companies - it seems nothing is safe. The United States Office of Personnel Management, SonyPlayStation, NASA, TJ Maxx and Google – to name just a few –have all been stung. Recently my wife's small business was hit with a "ransomware" attack.
It's just plain scarey.
Just this week, a member of the Federal Bureau of Investigations (FBI)
recommended that ransomware victims “just pay the ransom” if no other
option exists and if they need access to their encrypted data.
Last Wednesday, during Cyber Security Summit 2015 at Boston’s Back
Bay Events Center, Joseph Bonavolonta, the Assistant Special Agent in
Charge of the FBI’s CYBER and Counterintelligence Program in the Boston
office, observed that as the encryption standards protecting most
ransomware samples, including Cryptolocker and Cryptowall, are so strong, the FBI generally advises victims to pay the ransom payments.
That can be cost serious money. Usually, between $500 and $2000 - per machine.
Cyber risk can either continue to be seen as a negative – as another potential set of costs, complicated procedures and incoming legislative demands – or firms can use good cyber risk management as a differentiator from their competitors, as a selling point to clients, and as a measure of reassurance to stakeholders.
One new option, still being worked toward maturity, is Cyber Risk Insurance. Many companies are offering it, but the details of which is best are still being resolved. As always - Caveat Emptor!
The choice is yours - learn, plan and protect - or wait for that pit-in-your-stomach feeling, when you turn on your system and see that you've been hit.
It's not a good feeling.
Tuesday, October 27, 2015
Tuesday, October 6, 2015
Tabletop Exercises: What's up with that?
A tabletop exercise is a great way to get business continuity plans off the written page without the interruption of a full-scale drill. Rather than actually simulating a disaster, the crisis management group gathers for three hours to talk through a simulated disaster.
The exercise planning process determines the participants, exercise scenario, injects and the execution order for the course of the exercise. A group of exercise planners focused on the objectives selects the best means to reach those objectives and develops a complete exercise plan known as the master scenario event list (MSEL). The MSEL serves as the script for the execution of the exercise; it includes the ordering of injects, time of execution, and the expected reactions from the training audience.
It can be a full-scale production that involves local first responders and professional moderators, or it can be a simple affair conducted by in-house disaster planners. The idea is to have an escalating scenario that unfolds in several segments. After each segment, small working groups discuss how they would respond, then report back to each other before hearing from moderators about what happens next.
Tips for an Effective Tabletop
Decide how much gloom and doom you want. When planning a tabletop, ask: "Do you want this to be a physical event with assets damaged and destroyed, or do you just want those things inaccessible? Do you want death and injuries, or just to test the ability to get work up and going someplace else?"
It’s sensible to ask your delegates to suspend their disbelief if you’re running a scenario-based exercise. It’s useful to ask them to remember you’re testing the plan, not the scenario. You can also suggest that they make reasonable assumptions regarding any issues or holes they spot. But none of this takes away from the fact that you should aim to make any scenario as realistic as possible.
Test how quickly you can pull together key players. To be realistic, the crisis management team doesn't always know when a tabletop will occur. Instead, the company tests how quickly it could reach all those individuals. Specialized software pings team members' phone numbers and communications devices, alerting them that the crisis management team is assembling.
Involve everyone. Make sure each person has a role. If one person answers all the questions, have others enact how they would respond if that person were unavailable.
Acknowledge that first-timers may be nervous. Some business managers don't want to show that they may not know how to respond to a certain issue. To make them more comfortable, consider holding an hour-long orientation, well prior to an actual exercise. Later, work your way up to a three-hour exercise. Consider inviting local law enforcement and first responders to participate.
Encourage misinformation – and add “surprises” (AKA: Injects). During a crisis, you're always asked to make timely decisions based on incomplete and inaccurate information. Also, you can be sure that there will be crises within the crisis. You can simulate the confusion this causes by giving the groups handouts containing different information.
Take the lessons with you. A designated note-taker should keep track of what happens; always leave time for lessons learned.
Monday, October 5, 2015
HPAI (Bird Flu) in the USA - 2015
Highly Pathogenic Avian Influenza - 2015
Since it was first identified in the United States in December 2014 in the Pacific Northwest, highly pathogenic avian influenza (HPAI) has been detected in commercial and backyard poultry flocks, wild birds, or captive wild birds in 21 States. With the last case of the spring outbreak identified in June, 2015, a total of 211 commercial and 21 backyard poultry premises had been affected. This resulted in the depopulation of 7.5 million turkeys and 42.1 million egg-layer and pullet chickens, with devastating effects on these businesses, and a cost to Federal taxpayers of over $950 million.
Genetic analysis has shown that a comingling of migratory birds between northeast Asia and Alaska allowed for re-assortment of Asian HPAI strains with North American low pathogenic avian influenza (LPAI) viruses. The resulting Eurasian-American (EA/AM) HPAI viruses that infected wild birds and domestic poultry earlier in 2015 serve as a potential threat to poultry this fall and winter. Wild birds, particularly resident and migratory dabbling ducks, appear to be the reservoir for these viruses.
To prepare for additional outbreaks that could occur this fall or later, USDA planning activities assumed a worst-case scenario beginning in September 2015, with HPAI occurring simultaneously in multiple sectors of the poultry industry throughout the nation. Under this scenario, 500 or more commercial establishments of various sizes across a large geographical area could be affected.
The USDA plan for preventing and responding to future HPAI cases, in collaboration with industry and State partners, includes:
Promoting improved on-farm biosecurity practices in order to prevent future HPAI cases to the greatest extent possible;
Improving HPAI surveillance in wild birds as a means to provide “early warning” risk information to States and industry;
Expanding Federal, State and industry response capabilities, including availability of personnel, equipment, and depopulation, disposal and recovery options;
Improving our capabilities to rapidly detect HPAI in domestic poultry and to depopulate affected flocks within 24 hours to reduce the environmental load of HPAI viruses and their subsequent spread;
Streamlining the processes for payment of indemnity and the cost of eliminating viruses so that producers receive a fair amount quickly, to assist them in returning to production;
Enhancing our ability to communicate in a timely and effective way with producers, consumers, legislators, media, and others regarding outbreaks and other information; and
Making preparations to identify and deploy effective AI vaccines should they be a cost beneficial addition to the eradication efforts in a future HPAI outbreak.
A document was published in August 2015 entitled: USDA APHIS HPAI Response Plan: The Red Book (Draft August 2015) which reflects the knowledge and lessons learned during the spring 2015 outbreak event.
Importantly, while HPAI is zoonotic, and while it appears to have a relatively high species-specific transmission barrier, it also can be fatal for humans. Animal health officials should and do coordinate with public health officials in the event that HPAI is identified in the United States; appropriate health and safety measures should always be observed when conducting HPAI response activities.
Bottom line is, there is a high probability that the HPAI is coming back, this fall. The time to consider preventative and mitigation activities is NOW.
Wednesday, August 12, 2015
Command & Control - Who's in Charge Here?
Over the course of the years, it's been shown that most crises situations typically involve a chronology of events, each requiring somewhat distinct knowledge, skills, training, and decision-making to minimize harm and damage. Planners in California have articulated the following typical stages of a crisis:
1. - Observance of threatening conditions or events, becoming aware that a crisis may be commencing, and escalating awareness up the chain of command to an appropriate level of authority;
2. - Emergency responses, to minimize loss of lives, injuries to humans and animals, and damage to customers, property, reputation, or public trust;
3. - Assessment of damages and, if sufficiently severe, strategic decisions for significant actions to thwart long term damage;
4. - Activation of alternate or temporary facility operations to minimize disruptions to valuable operations;
5. - Repair or replacement of damaged capabilities; and
6. - Migration or return from temporary operations to the long term “permanent” or “normal” environment.
Fact is, most crises are small - they happen every day. Usually, management can undertake these steps as needed within normal capabilities. The larger ones, however (think major earthquakes, terrorist attacks, major hurricanes), require activation of a pre-defined team of senior leaders and operators - a Senior Activation Team (SAT) - trained in a crisis management methodology.
As should be pre-defined in a Business Continuity Plan or continuity of operations plan, high-value / time-sensitive operations will have pre-determined strategies for stage 4 above. The senior activation team will also find itself addressing all disrupted operations requiring stage 4, not just those covered by a continuity plan. Most executives on the SAT will also retain their normal responsibilities for oversight of operations that are not affected by the crisis. Depending on the nature of the crisis, a senior executive activation team may convene and be also be involved in stages 1, 2, 3, or 4.
This raises the important question of how a senior activation team is activated and empowered, if it is in fact different from the senior executive team that is normally in charge.
Waiting until the stuff is in the fan is the wrong way to go. Criteria must be pre-established and procedures pre-developed and well-practiced so that all involved understand how executive authority is transferred or transformed as a crisis unfolds.
The "Alexander Haig scenario of, "I’m in charge!" is not the way to go. Figure it out early.
That is all...
Wednesday, July 29, 2015
Plan, Do, Check, Act (repeat) - Getting it Done with Business Continuity Planning
The Plan, Do, Check, Act (PDCA) Cycle are the four stages of problem resolution.
The concept is also referred to as `the Shewhart Cycle'. It was originally developed by Walter Shewhart, the pioneering statistician who developed statistical process control in the Bell Laboratories in the US during the 1930's. The concept was taken up by W. Edwards Deming, the famous Quality Management authority, and is consequently known by many as `the Deming Wheel'.
Properly applied, the PDCA Cycle is used to coordinate continuous improvement efforts. The concept demonstrates that improvement programs must start with careful planning, leading to effective action, then move again to careful planning in a continuous cycle.
There are a wealth of resources available to guide in the use of the PDCA Cycle and it is an integral part of the Business Continuity Planning (BCP) process. Nearly every emerging standard is following this approach, including the newest, ISO 22301.
One of the best things about using PDCA in the realm of BCP is pretty straight forward: it's language senior management already understands! Possibly the greatest challenges in BCP are gaining executive sponsorship, then creating a culture-shift in the organization. The last part is tricky - you can't dictate culture change, it must be LED by leaders. The best way to get leaders involved is to speak a language they already understand. Most good leaders in business today have studied Deming.
Ergo: PDCA.
If you need help with all this, shoot me a note!
Saturday, June 13, 2015
Cyber Preparedness
Cyber Security in the Smart Grid. "Is that a real problem," you might ask? Well, yes...yes it is. A very real problem. Here's a bit of a blurb from today's news:
The man in charge of America's cyber operations said that on a scale of one to 10, the nation's preparedness to deal with a major cyber attack on critical infrastructure sits at a dismal three.
"Somebody who finds vulnerability in our infrastructure could cause tremendous problems," Army Gen. Keith Alexander, Director of the National Security Agency and chief of U.S. Cyber Command, told audience members at the Aspen Institute's annual security forum. Alexander said that since 2009, attempted cyber attacks on the nation's infrastructure systems have risen seventeen-fold.
"I'm worried most about power. I'm worried about water. I think those are the ones that need the most help," he said.
As emergency managers, we need to question those who run our power grids. Sure, they own the infrastructure, but lives depend on how well they are controlling it! I prefer to think of the power companies as "custodians" of the critical infrastructure, rather than "owners."
My advice to the EM Community - take those custodians to task. Ask them to produce their cyber security plans and their business continuity plans. Your constituents will be grateful.
Friday, May 15, 2015
Don't Get Complacent!
I continually write and speak about the dangers of complacency. More people have died because they refused to recognize the dangers around them than can be counted. All year, the weather prognosticators have been calling for a "less than normal" hurricane season, mostly because of an expected El Nino event. Well, I read the following editorial today:
Forecasters were right about an El Nino this year. The weather phenomenon warms the eastern Pacific Ocean and generates strong wind shear that cuts the top off thunderstorms and stops them from developing. The odds of a major hurricane making U.S. landfall are 27 percent in an El Nino year, compared to 45 percent in a neutral year, according to Colorado Sate University climatologist Phil Klotzbach.
It seems to be doing it's job, so far this year.
In the meantime, Gulf Coast residents shouldn't count on El Nino or the initial forecast for a less-than-average season to protect them.
Sound familiar? Wake up. Smell the Starbucks. Get a plan.
Be Prepared!
Friday, January 2, 2015
I Resolve...
Welcome to 2015! Yet another opportunity to do great new things and to improve on the old.
I resolve to be better through greater use of these four principles: self-awareness, ingenuity, love and leadership.
Self-awareness: “To order one's life”
“Leaders thrive by understanding who they are and what they value, by becoming aware of unhealthy blind spots or weaknesses that can derail them, and by cultivating the habit of continuous reflection and learning.”
Ingenuity: “The whole world will become our house”
“Leaders make themselves and others comfortable in a changing world. They eagerly explore new ideas, approaches and cultures rather than shrink defensively from what lurks around life's next corner. Anchored by nonnegotiable principles and values, they cultivate the ‘indifference’ that allows them to adapt confidently.”
Love: “With greater love than fear”
“Leaders face the world with a confident, healthy sense of themselves as endowed with talent, dignity, and the potential to lead. They find exactly these same attributes in others and passionately commit to honoring and unlocking the potential they find in themselves and in others. They create environments bound and energized by loyalty, affection, and mutual support.”
Leadership: “Eliciting great desires”
“Leaders imagine an inspiring future and strive to shape it rather than passively watching the future happen around them. Leaders extract gold from the opportunities at hand rather than waiting for golden opportunities to be handed to them.”
Wednesday, July 25, 2012
GET A PLAN!
GET A PLAN!
You can take steps to decrease the impact of a disaster by planning in advance and learning about potential threats. It is important to make sure that your plans are adequate for your family’s situation. Practice your plans regularly.
Having a basic kit on hand to sustain yourself and your family after an emergency is an essential part of preparation. Think first about basic survival needs: fresh water, food, clean air, and warmth. Store your supplies in a portable container as close as possible to an exit and review the contents of your kit at least once a year. Include in your kit:
• 3-day supply of water: at least 1 gallon per person per day
• 3-day supply of non-perishable food
• Manual can opener and eating utensils
• Supplies to care for your pets including 3-day supply of food and water,
ID tags, proof of vaccinations, and veterinarian contact information
• Flashlight
• Portable, battery-powered radio
• Extra batteries
• Basic first aid kit and manual
• Warm clothing and blankets
• Whistle
• Filter face masks (N95 rating)
• List of emergency contact information
• Photocopies of important documents (birth certificate, licenses, insurance information, etc.)
• Cash and coins
• Sanitation and hygiene items (hand sanitizer, moist towelettes, feminine hygiene products, toilet paper, etc.)
• Household chlorine bleach and medicine dropper: 9 parts water to 1 part bleach can be used as a disinfectant, 16 drops of bleach to 1 gallon of water can be used to treat water in an emergency (do not use scented, color safe, or bleaches with added cleaners)
• Items for infants (formula, diapers, bottles, and pacifiers) if applicable
• 4 or 5 solar lights (regular garden lights) – these will light your space all night and recharge during the day
Sunday, April 8, 2012
PS-Prep, FEMA, PPD8: Just more crazy acronyms?
It's been said that we live in a world of TLA's (Three Letter Acronyms) and X-TLA's (eXtended Three Letter Acronyms). How true is that? It doesn't seem to matter the field, we all live with them. The ones mentioned in the title to this blog post are important, though, if you plan to have your business prepared for a worst case scenario. The have to do with BCP (Business Continuity Planning) and the establishment of a BCMS (Business Continuity Management System).
Let's start with the Private Sector Preparedness Program (PS-Prep). PS-PREP (also known as Public Law 110-53: Title IX) constitutes a credible, practical, standards-based approach to certification of a business continuity and emergency management program for private sector organizations. It is managed by the Department of Homeland Security, administered by the American National Standards Institute’s American Society for Quality (ASQ), and accredited by the American National Accreditation Board (ANAB), and came as a recommendation from findings of the 9/11 Commission. Organizations can be certified to PS-PREP by an ANAB accredited certifying body.
Under PS-PREP, the organization has the ability to individually select and implement a set of reasonable and appropriate requirements and controls from any one (or a combination) of three different business continuity and emergency management standards. These include:
The National Fire Protection Association’s NFPA-1600- Standard on Disaster/Emergency Management and Business Continuity Programs dated 2007
The American National Standard ASIS SPC.1-2009 Organizational Resilience: Security, Preparedness, and Continuity Management Systems- Requirements with Guidance for Use
The British Standard Institute’s BS-25999-2:2007 Business Continuity Management- Part 2: Specification.
All of these standards recommend a Plan / Do / Check / Act (PDCA) approach to establishing a BCMS with the enterprise. Since there are very few disasters or crises that you can see coming (hurricanes and floods pretty much round out the set), having a well-practiced, often-exercised plan is imperative for most every business. Basing the plan on proven guidelines make good sense.
Presidential Preparedness Directive 8 (PPD-8) is the newest element of the National Preparedness Directive. Specifically, it identifies six components to improve national preparedness for a wide range of threats and hazards, such as acts of terrorism, cyber attacks, pandemics and catastrophic natural disasters. The system description explains how as a nation we will build on current efforts, many of which are already established in the law and have been in use for many years. These six components include:
Identifying and assessing risks;
Estimating capability requirements;
Building or sustaining capabilities;
Developing and implementing plans to deliver those capabilities;
Validating and monitoring progress made towards achieving the National Preparedness Goal; and
Reviewing and updating efforts to promote continuous improvement.
Most of this can be accomplished through adherence to the standards and programs mentioned under PS-Prep.
The Federal Emergency Management Agency (FEMA) is chartered with managing these programs. A pretty good idea, assuming that getting more entities on board could result in lowered risk and therefore lowered impact to the nation's resources.
So - how are YOU doing? Does your company have a BCP? Is it compliant with one or more of the BCP Standards? Do you exercise it regularly? Has it been audited by an external resource?
Let me know if you need help answering any of these questions.
Ed.minyard@responseforce1.com
Let's start with the Private Sector Preparedness Program (PS-Prep). PS-PREP (also known as Public Law 110-53: Title IX) constitutes a credible, practical, standards-based approach to certification of a business continuity and emergency management program for private sector organizations. It is managed by the Department of Homeland Security, administered by the American National Standards Institute’s American Society for Quality (ASQ), and accredited by the American National Accreditation Board (ANAB), and came as a recommendation from findings of the 9/11 Commission. Organizations can be certified to PS-PREP by an ANAB accredited certifying body.
Under PS-PREP, the organization has the ability to individually select and implement a set of reasonable and appropriate requirements and controls from any one (or a combination) of three different business continuity and emergency management standards. These include:
The National Fire Protection Association’s NFPA-1600- Standard on Disaster/Emergency Management and Business Continuity Programs dated 2007
The American National Standard ASIS SPC.1-2009 Organizational Resilience: Security, Preparedness, and Continuity Management Systems- Requirements with Guidance for Use
The British Standard Institute’s BS-25999-2:2007 Business Continuity Management- Part 2: Specification.
All of these standards recommend a Plan / Do / Check / Act (PDCA) approach to establishing a BCMS with the enterprise. Since there are very few disasters or crises that you can see coming (hurricanes and floods pretty much round out the set), having a well-practiced, often-exercised plan is imperative for most every business. Basing the plan on proven guidelines make good sense.
Presidential Preparedness Directive 8 (PPD-8) is the newest element of the National Preparedness Directive. Specifically, it identifies six components to improve national preparedness for a wide range of threats and hazards, such as acts of terrorism, cyber attacks, pandemics and catastrophic natural disasters. The system description explains how as a nation we will build on current efforts, many of which are already established in the law and have been in use for many years. These six components include:
Identifying and assessing risks;
Estimating capability requirements;
Building or sustaining capabilities;
Developing and implementing plans to deliver those capabilities;
Validating and monitoring progress made towards achieving the National Preparedness Goal; and
Reviewing and updating efforts to promote continuous improvement.
Most of this can be accomplished through adherence to the standards and programs mentioned under PS-Prep.
The Federal Emergency Management Agency (FEMA) is chartered with managing these programs. A pretty good idea, assuming that getting more entities on board could result in lowered risk and therefore lowered impact to the nation's resources.
So - how are YOU doing? Does your company have a BCP? Is it compliant with one or more of the BCP Standards? Do you exercise it regularly? Has it been audited by an external resource?
Let me know if you need help answering any of these questions.
Ed.minyard@responseforce1.com
Sunday, August 28, 2011
Complacency: Letting your Guard Down after Irene?
Complacency is an interesting phenomenon. It usually occurs after great success. Ever wonder why so few pro teams "3 peat"? It's because they couldn't "repeat." Why? Because they become complacent. In our business - that of disaster response and emergency management - complacent kills.
In NOLA, most of the folks who died had the attitude that they could "ride this one out", just as they and their parents had all the "other storms." Complacency, writ large.
So, here we are, on 8/28/2011 - one day shy of the 6th anniversary of Katrina. Irene is literally passing my front door right now, here in the White Mountains of New Hampshire. We've had 7 inches of rain since 10AM (ok, I could have been up earlier, but WHY?), and the wind is till puffing about. 15 lives lost have been contributed to this storm, and who knows how much property damage? 4 million people are without power (which, for those of you who haven't spent a few days without power, really sucks) and flooding is all over. But, you know what? NO ONE WAS COMPLACENT! Everyone took this seriously.
That said, since it wasn't "so bad," will the same folks along the east Coast take the next storm seriously? Will folks evacuate, when told, in the face of the next, inevitable, storm? Man, I truly hope so.
In 2008, my team and I were back in NOLA, helping to execute an evacuation plan which, 2 years earlier, we helped to write. We got out everyone that needed to get out.
Then, the storm went around us.
Mayor Nagin, at that time, like Mayor Bloomberg, this time, made a very hard and costly decision. Made in the spirit of saving lives. I was also in Mexico City when Mayor Marcelo Ebrard made the tough decision to shut that giant city down, when faced with H1N1 - again, to save lives.
But, it turns out, none of those events turned out to be as bad as the "hype" made them seem.
So, what about next time?
My guess? People will die. They will die because of complacency. That John Wayne attitude that says, "How bad can it be? I survived the last one!"
As I write this, there are several new storm systems developing in the Atlantic and one predicted for the Gulf of Mexico. We are not yet at the peak of Hurricane Season 2011. We've just had a 5.9 earthquake on the EAST COAST.
Seriously, Are You Ready?
Or are you COMPLACENT?
In NOLA, most of the folks who died had the attitude that they could "ride this one out", just as they and their parents had all the "other storms." Complacency, writ large.
So, here we are, on 8/28/2011 - one day shy of the 6th anniversary of Katrina. Irene is literally passing my front door right now, here in the White Mountains of New Hampshire. We've had 7 inches of rain since 10AM (ok, I could have been up earlier, but WHY?), and the wind is till puffing about. 15 lives lost have been contributed to this storm, and who knows how much property damage? 4 million people are without power (which, for those of you who haven't spent a few days without power, really sucks) and flooding is all over. But, you know what? NO ONE WAS COMPLACENT! Everyone took this seriously.
That said, since it wasn't "so bad," will the same folks along the east Coast take the next storm seriously? Will folks evacuate, when told, in the face of the next, inevitable, storm? Man, I truly hope so.
In 2008, my team and I were back in NOLA, helping to execute an evacuation plan which, 2 years earlier, we helped to write. We got out everyone that needed to get out.
Then, the storm went around us.
Mayor Nagin, at that time, like Mayor Bloomberg, this time, made a very hard and costly decision. Made in the spirit of saving lives. I was also in Mexico City when Mayor Marcelo Ebrard made the tough decision to shut that giant city down, when faced with H1N1 - again, to save lives.
But, it turns out, none of those events turned out to be as bad as the "hype" made them seem.
So, what about next time?
My guess? People will die. They will die because of complacency. That John Wayne attitude that says, "How bad can it be? I survived the last one!"
As I write this, there are several new storm systems developing in the Atlantic and one predicted for the Gulf of Mexico. We are not yet at the peak of Hurricane Season 2011. We've just had a 5.9 earthquake on the EAST COAST.
Seriously, Are You Ready?
Or are you COMPLACENT?
Wednesday, August 24, 2011
Hurricanes and Earthquakes
Last year, I gave a presentation on the probable impacts of a Cat 3 storm hitting NYC. Well, today we are faced with a possibility of all that occurring. Here are a few points from my presentation:
According to a 1995 study, a category three hurricane on a worst-case track could create a surge of up to 25 feet at JFK Airport, 21 feet at the Lincoln Tunnel entrance, 24 feet at the Battery, and 16 feet at La Guardia Airport. These figures do not include the effects of tides nor the additional heights of waves on top of the surge.
In the event of a hurricane, authorities would focus their efforts on moving those in low-lying areas of the city- roughly 3.3 million people- to higher ground. However, New York can provide shelter for only 800,000 people, leaving the potential of more than 2 million people to fend for themselves.
A category 3 storm would put Wall Street under 10 feet of water in moments, its winds would turn skyscrapers into perilous wind tunnels.
A major hurricane in New York would create a national setback of enormous proportions.
So, what about earthquakes? In NYC? Yep, very possible and has already happened -
The city can expect a magnitude 5 quake, which is strong enough to cause damage, once every 100 years, according to the report addressed in the following link. (Magnitude is a measure of the energy released at the source of an earthquake.) The scientists also calculate that a magnitude 6, which is 10 times larger, has a 7 percent chance of happening once every 50 years and a magnitude 7 quake, 100 times larger, a 1.5 percent chance.
http://www.gothamgazette.com/article/iotw/20080929/200/2660
So, the question is, ARE YOU READY?
According to a 1995 study, a category three hurricane on a worst-case track could create a surge of up to 25 feet at JFK Airport, 21 feet at the Lincoln Tunnel entrance, 24 feet at the Battery, and 16 feet at La Guardia Airport. These figures do not include the effects of tides nor the additional heights of waves on top of the surge.
In the event of a hurricane, authorities would focus their efforts on moving those in low-lying areas of the city- roughly 3.3 million people- to higher ground. However, New York can provide shelter for only 800,000 people, leaving the potential of more than 2 million people to fend for themselves.
A category 3 storm would put Wall Street under 10 feet of water in moments, its winds would turn skyscrapers into perilous wind tunnels.
A major hurricane in New York would create a national setback of enormous proportions.
So, what about earthquakes? In NYC? Yep, very possible and has already happened -
The city can expect a magnitude 5 quake, which is strong enough to cause damage, once every 100 years, according to the report addressed in the following link. (Magnitude is a measure of the energy released at the source of an earthquake.) The scientists also calculate that a magnitude 6, which is 10 times larger, has a 7 percent chance of happening once every 50 years and a magnitude 7 quake, 100 times larger, a 1.5 percent chance.
http://www.gothamgazette.com/article/iotw/20080929/200/2660
So, the question is, ARE YOU READY?
Saturday, July 30, 2011
Standards
One of our RF1 clients asked us, "Why should we be worried about 'standards'?" This was in relation to work that we're currently doing for this entity. So, what's the answer?
In general standards generate efficiencies and competitiveness in the sectors that adopt them.
Prime examples of successfully adopted standards include the Internet Protocol (IP), Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), General Packet Radio Service (GPRS) and Hyperlink (HTML). Could you imagine the state we'd be in if EVERYONE who developed an "app" just did their own thing, their own way? You don't have to look back too far to get my drift. For those of us of a certain age, just click back to the battle between VHS and BETA formats for VCR's. For those of you who don't know what a VCR is, look at the issues today in resolving 3D TV standards.
As they evolve, standards can generate linked effects which exist where the more parties that adopt a particular way of doing something, the greater immediate benefit is achieved to new parties who subsequently adopt the same way of doing it, as well as increasing the value to those who have already adopted it. These linked effects can generate greater economies of scale as costs reduce for example, as mobile phones and the GSM, CDMA and GPRS standards have grown in popularity, the cost of purchasing a handset has reduced significantly. Standards can also increase competition. If a standard approach to development, construction or deployment exists between different suppliers, the choices to the consumer become more broad, therefore leading to a more competitive environment.
Possibly the single most important benefit of standards relates to operational efficiencies. New participants can benefit from the lessons learned by earlier adopters of the process or technology-at-hand.
All this having been said, as evidenced by the references to the cellphone "standards" (GPRS / CDMA / GSM), the best thing about standards is, there are so many to choose from! Don't go blindly into an approach without doing some homework.
In general standards generate efficiencies and competitiveness in the sectors that adopt them.
Prime examples of successfully adopted standards include the Internet Protocol (IP), Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), General Packet Radio Service (GPRS) and Hyperlink (HTML). Could you imagine the state we'd be in if EVERYONE who developed an "app" just did their own thing, their own way? You don't have to look back too far to get my drift. For those of us of a certain age, just click back to the battle between VHS and BETA formats for VCR's. For those of you who don't know what a VCR is, look at the issues today in resolving 3D TV standards.
As they evolve, standards can generate linked effects which exist where the more parties that adopt a particular way of doing something, the greater immediate benefit is achieved to new parties who subsequently adopt the same way of doing it, as well as increasing the value to those who have already adopted it. These linked effects can generate greater economies of scale as costs reduce for example, as mobile phones and the GSM, CDMA and GPRS standards have grown in popularity, the cost of purchasing a handset has reduced significantly. Standards can also increase competition. If a standard approach to development, construction or deployment exists between different suppliers, the choices to the consumer become more broad, therefore leading to a more competitive environment.
Possibly the single most important benefit of standards relates to operational efficiencies. New participants can benefit from the lessons learned by earlier adopters of the process or technology-at-hand.
All this having been said, as evidenced by the references to the cellphone "standards" (GPRS / CDMA / GSM), the best thing about standards is, there are so many to choose from! Don't go blindly into an approach without doing some homework.
Sunday, July 24, 2011
It's Hurricane Season, Folks - Are You Ready?
So - Are You Ready?
What should you be doing...RIGHT NOW...to prepare? Here are a few guidelines:
What Steps Should be Taken?
For the Enterprise
Organizations should have a “ready response” initiative in place that will enable them to communicate and respond immediately following a disaster. Ready response could entail pre-staging essential communications equipment, durable mobile communications vehicles, call centers and disaster recovery sites outside the impacted geographic area, mobile command centers and physical security to protect physical assets. The next critical step is to choose the key people, and their alternates, to implement the plan. Take appropriate steps to ensure that they understand their roles and responsibilities in advance.
Organizations should also have a well–written and well-exercised DRP and BCP. Standards such as CobIT, ISO 17799, NFPA 1600 and others are excellent, proven guidelines for such plans. This author suggests that those plans should be aligned with frameworks such as the National Response Framework, the National Incident Management System and the National Critical Infrastructure Protection Plan, as well. I suggest that because, in an incident of national significance, your facilities, employees, distribution systems and infrastructure may become an integral part of a broad-based response effort.
For the Individual
Develop an emergency plan, make sure that everyone in your family knows about it an practices it. No matter what the disaster, the most basic element of planning is to agree on at least two places for families to meet in the event that one’s home becomes unsafe. Develop a solid communications plan – in many cases, it will actually be easier to call long distance than locally. Have a coordination point outside of your local area that family members can contact.
Think of how many displaced families could have been reconnected if this type of preparedness had taken place prior to Katrina.
Part of your planning effort should include the assembly of a “go kit”, containing important papers, prescription pharmaceuticals, non-perishable food, water, batteries, a battery-operated or hand crank-powered weather radio, etc.
Don’t count on help for at least three days after a major disaster event. It may not be there.
Remember that any emergency is local first. FEMA IS NOT A First Responder!!
You should be prepared to be on your own for at least 72 hours. I repeat: FEMA is NOT a First Responder! Go to the FEMA website http://www.fema.gov/areyouready/ ; That may be the only help anyone gets from FEMA until well after any emergency. It’s full of good advice, including a list of items to be included in a “go kit”.
Remember that a Hurricane is one of the very few disaster you can see coming. That said, the advice her will help you be better prepared for ANY disaster.
Stay safe.
What should you be doing...RIGHT NOW...to prepare? Here are a few guidelines:
What Steps Should be Taken?
For the Enterprise
Organizations should have a “ready response” initiative in place that will enable them to communicate and respond immediately following a disaster. Ready response could entail pre-staging essential communications equipment, durable mobile communications vehicles, call centers and disaster recovery sites outside the impacted geographic area, mobile command centers and physical security to protect physical assets. The next critical step is to choose the key people, and their alternates, to implement the plan. Take appropriate steps to ensure that they understand their roles and responsibilities in advance.
Organizations should also have a well–written and well-exercised DRP and BCP. Standards such as CobIT, ISO 17799, NFPA 1600 and others are excellent, proven guidelines for such plans. This author suggests that those plans should be aligned with frameworks such as the National Response Framework, the National Incident Management System and the National Critical Infrastructure Protection Plan, as well. I suggest that because, in an incident of national significance, your facilities, employees, distribution systems and infrastructure may become an integral part of a broad-based response effort.
For the Individual
Develop an emergency plan, make sure that everyone in your family knows about it an practices it. No matter what the disaster, the most basic element of planning is to agree on at least two places for families to meet in the event that one’s home becomes unsafe. Develop a solid communications plan – in many cases, it will actually be easier to call long distance than locally. Have a coordination point outside of your local area that family members can contact.
Think of how many displaced families could have been reconnected if this type of preparedness had taken place prior to Katrina.
Part of your planning effort should include the assembly of a “go kit”, containing important papers, prescription pharmaceuticals, non-perishable food, water, batteries, a battery-operated or hand crank-powered weather radio, etc.
Don’t count on help for at least three days after a major disaster event. It may not be there.
Remember that any emergency is local first. FEMA IS NOT A First Responder!!
You should be prepared to be on your own for at least 72 hours. I repeat: FEMA is NOT a First Responder! Go to the FEMA website http://www.fema.gov/areyouready/ ; That may be the only help anyone gets from FEMA until well after any emergency. It’s full of good advice, including a list of items to be included in a “go kit”.
Remember that a Hurricane is one of the very few disaster you can see coming. That said, the advice her will help you be better prepared for ANY disaster.
Stay safe.
FEMA Camps
I have to tell you, it makes me laugh out when I Google "FEMA Camps" and see all the crazy BS out there. As some of you may know, we have been operating such camps for 3 years. Contrary to "Google World", they are NOT interment camps, death camps or concentration camps. Just comfortable, convenient paces to lay your head and eat when responding to disasters.
At least that's what FEMA tells us...
At least that's what FEMA tells us...
Sunday, June 12, 2011
Haiti Today: Still the same?
So, we have a new government in Haiti. One that was duly elected by the popular vote. Let's hope that Mssr. Martelly will step up the pace of recovery. I don't mean the grandiose areas of “recovery” – shopping malls, the Presidential Palace, business centers. I mean the most basic of things, like REAL shelter for the Haitian people, still living in tarp cities.
Just last week, coincidentally the first week of the Atlantic Hurricane Season, Haiti was drenched by a slow-moving system known as “94L” – the second “invest” of the first week of the season. In that event, 23 Haitians died. They died because their makeshift “homes” were washed away. The following was posted in a report from the International Association of Emergency managers (of which, I serve as Sergeant at Arms):
HAITI: At least 23 people have been killed in flooding in Haiti. Most of the deaths occurred in the capital Port-au-Prince after torrential rain swept away houses, and flooded roads. Two children were buried alive when their home collapsed; two other people died in a tent city erected after last year's devastating earthquake. Haitian officials fear other such camps could be swept away during the hurricane season. Days of heavy rain swelled rivers and flooded camps built to house thousands of evacuees after the 2010 earthquake. Thirteen people were killed when landslides swept through the upscale suburb of Petionville. The United States National Hurricane Center warned the rains could also cause flash floods and mudslides in the Dominican Republic and Cuba.
Bottom line? It’s been almost 18 months since the earthquake. THINGS NEED TO CHANGE in Haiti.
Just last week, coincidentally the first week of the Atlantic Hurricane Season, Haiti was drenched by a slow-moving system known as “94L” – the second “invest” of the first week of the season. In that event, 23 Haitians died. They died because their makeshift “homes” were washed away. The following was posted in a report from the International Association of Emergency managers (of which, I serve as Sergeant at Arms):
HAITI: At least 23 people have been killed in flooding in Haiti. Most of the deaths occurred in the capital Port-au-Prince after torrential rain swept away houses, and flooded roads. Two children were buried alive when their home collapsed; two other people died in a tent city erected after last year's devastating earthquake. Haitian officials fear other such camps could be swept away during the hurricane season. Days of heavy rain swelled rivers and flooded camps built to house thousands of evacuees after the 2010 earthquake. Thirteen people were killed when landslides swept through the upscale suburb of Petionville. The United States National Hurricane Center warned the rains could also cause flash floods and mudslides in the Dominican Republic and Cuba.
Bottom line? It’s been almost 18 months since the earthquake. THINGS NEED TO CHANGE in Haiti.
Saturday, June 4, 2011
ICS - an interesting dialogue between professionals
I had an interesting dialogue on Link In today - I thought it was good enough to share here:
The post began with a question about how ICS should be considered and used in business. A good question. Here's the "jist" of the ensuing dialogue:
Roger Huder • ICS is nothing more or less than management by objective. You are simply dividing up a very large problem into manageable parts. You do not have to use Incident Commander, Logistics, Operations etc nomenclature, you can name them anything you want, the objective is to have clear lines of authority to manage a problem. If you are going to interface with the public sector they will have to use to the same naming scheme so outsiders will know who is who during a response. But ICS is nothing more than organizing to meet a specific problem rapidly and efficiently. The difficult part for many in the private sector to understand is the re-organiztion of their normal lines of authority but it works and works well to manage major crisis in or out of government.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • Agreed, Roger - management is management. BUT, as you also point out, if you are a custodian of critical infrastructure, ICS should be MANDATORY as an operating model. As an individual who recently spent 6 months in Louisian, supporting the MC252 Oil Spill Response, I can attest to the confusion created when private and public sector organizations "integrate" (violently collide?) in the course of a disaster response. ICS, like every other "standard approach" (nice that we have so many to choose from!), has it's warts - but it's still what we have all agreed to use. (at least in the public sector).
Roger Huder • I think the collisions comes not from the ICS structure as much as it comes from the two cultures. Businesses are used to making decisions in a specific and careful way with lots of checking the numbers. You and I both know when you have a fast moving disaster that will not hold still long enough to get a complete grip on all the facts that type of decision making must change. It is much more like the emergency decision making in the public safety community or the military in combat. The clash of these two types of decision making can lead to huge misunderstanding and how should I say it politely a less than optimum response.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • You're right on, Roger. This challenge is no different than that of "buy in" to the concept of Business Continuity. Most plans are done as acts of compliance, because most people tend to believe "it won't happen to me." Therefore, training and exercises are not taken with the degree of seriousness that should be had. I've been deep into every major disaster since 9-11, working with both public and private sector clients. That initial "WTF just happened?" is there - every time. One of the reasons FEMA has instituted the IMAT concept is just that - when you're in the stuff, as a victim AND a manager - the decision making process is impacted by the fact that your ability to reason is reduced to that of a sixth grader.
All that said, there is an old adage in the world of warriors: "The more you sweat in training, the less you bleed in battle."
I try to encourage my private sector and public sector clients to be prepared. That means drilling the processes and concepts until you not just know them - you live them. You are so very right about the pace of things when in the midst of the fray. Laborious decision making processes are fuel to flames. Further, as you stated in your first post, "the objective is to have clear lines of authority to manage a problem. If you are going to interface with the public sector they will have to use to the same naming scheme so outsiders will know who is who during a response." ICS is well-defined in that regard. And, if you are a custodian of critical infrastructure (I use the word "custodian" because, if you operate a business that's critical to the wellfare of the nation or it's people, and you aren't doing the right things to operate in a disaster situation, you WILL be superceded by Uncle Sam (ask BP)), you MUST be able to work within the ICS structure. whew, that was a long winded tirade, no?
Roger Huder • No it was not too long, it could not have been said better. Our biggest hurdle is to get people to understand that "stuff"(put a less polite word in there) does happen. I've watched as people's thirty year careers go down the drain because they thought it would not happen on their watch. Just as you said the more you sweat before the event the better you will handle it. We need to put less emphasis on planning and more emphasis on training for response. I know some won't like that statement but the military has an old saying "no plan survives first contact with the enemy." I have found that to be true in emergency response and management. ICS is only the structure used to carry out decisions it will not make decisions for you. Bad decisions using ICS will only produce well executed bad decisions.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • Thanks, Roger. Your last sentence sums things up quite nicely. ICS is what it is. But, as long as we're quoting:
"He whose only tool is hammer, soon sees the world as a nail."
Nuff said, time for a beer.
*************************************************************
So, what do YOU think?
The post began with a question about how ICS should be considered and used in business. A good question. Here's the "jist" of the ensuing dialogue:
Roger Huder • ICS is nothing more or less than management by objective. You are simply dividing up a very large problem into manageable parts. You do not have to use Incident Commander, Logistics, Operations etc nomenclature, you can name them anything you want, the objective is to have clear lines of authority to manage a problem. If you are going to interface with the public sector they will have to use to the same naming scheme so outsiders will know who is who during a response. But ICS is nothing more than organizing to meet a specific problem rapidly and efficiently. The difficult part for many in the private sector to understand is the re-organiztion of their normal lines of authority but it works and works well to manage major crisis in or out of government.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • Agreed, Roger - management is management. BUT, as you also point out, if you are a custodian of critical infrastructure, ICS should be MANDATORY as an operating model. As an individual who recently spent 6 months in Louisian, supporting the MC252 Oil Spill Response, I can attest to the confusion created when private and public sector organizations "integrate" (violently collide?) in the course of a disaster response. ICS, like every other "standard approach" (nice that we have so many to choose from!), has it's warts - but it's still what we have all agreed to use. (at least in the public sector).
Roger Huder • I think the collisions comes not from the ICS structure as much as it comes from the two cultures. Businesses are used to making decisions in a specific and careful way with lots of checking the numbers. You and I both know when you have a fast moving disaster that will not hold still long enough to get a complete grip on all the facts that type of decision making must change. It is much more like the emergency decision making in the public safety community or the military in combat. The clash of these two types of decision making can lead to huge misunderstanding and how should I say it politely a less than optimum response.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • You're right on, Roger. This challenge is no different than that of "buy in" to the concept of Business Continuity. Most plans are done as acts of compliance, because most people tend to believe "it won't happen to me." Therefore, training and exercises are not taken with the degree of seriousness that should be had. I've been deep into every major disaster since 9-11, working with both public and private sector clients. That initial "WTF just happened?" is there - every time. One of the reasons FEMA has instituted the IMAT concept is just that - when you're in the stuff, as a victim AND a manager - the decision making process is impacted by the fact that your ability to reason is reduced to that of a sixth grader.
All that said, there is an old adage in the world of warriors: "The more you sweat in training, the less you bleed in battle."
I try to encourage my private sector and public sector clients to be prepared. That means drilling the processes and concepts until you not just know them - you live them. You are so very right about the pace of things when in the midst of the fray. Laborious decision making processes are fuel to flames. Further, as you stated in your first post, "the objective is to have clear lines of authority to manage a problem. If you are going to interface with the public sector they will have to use to the same naming scheme so outsiders will know who is who during a response." ICS is well-defined in that regard. And, if you are a custodian of critical infrastructure (I use the word "custodian" because, if you operate a business that's critical to the wellfare of the nation or it's people, and you aren't doing the right things to operate in a disaster situation, you WILL be superceded by Uncle Sam (ask BP)), you MUST be able to work within the ICS structure. whew, that was a long winded tirade, no?
Roger Huder • No it was not too long, it could not have been said better. Our biggest hurdle is to get people to understand that "stuff"(put a less polite word in there) does happen. I've watched as people's thirty year careers go down the drain because they thought it would not happen on their watch. Just as you said the more you sweat before the event the better you will handle it. We need to put less emphasis on planning and more emphasis on training for response. I know some won't like that statement but the military has an old saying "no plan survives first contact with the enemy." I have found that to be true in emergency response and management. ICS is only the structure used to carry out decisions it will not make decisions for you. Bad decisions using ICS will only produce well executed bad decisions.
Edward Minyard, CRISC, CISM, CBCI, CCM, ITIL • Thanks, Roger. Your last sentence sums things up quite nicely. ICS is what it is. But, as long as we're quoting:
"He whose only tool is hammer, soon sees the world as a nail."
Nuff said, time for a beer.
*************************************************************
So, what do YOU think?
Saturday, May 28, 2011
FEMA out of money?
According to a report in USA Today (May 27th):
The Federal Emergency Management Agency (FEMA) has $2.4 billion in its Disaster Relief Fund to last through Sept. 30 and is seeking $1.8 billion for the fiscal year that begins Oct. 1. Lawmakers from both parties say those sums are not enough to pay for the billions in damage caused by the extraordinary string of weather-related disasters this spring.
"FEMA will have to stop recovery efforts in 50 states in the spring of 2012" without additional money for disaster relief, Sen. Mary Landrieu, D-La., wrote in a letter to her colleagues. She heads the Senate panel that oversees FEMA finances.
So, how do you feel about that? Some folks have expressed the opinion that FEMA shouldn't do as much as they already do. My question to them is: "Who ya gonna call?"
The Federal Emergency Management Agency (FEMA) has $2.4 billion in its Disaster Relief Fund to last through Sept. 30 and is seeking $1.8 billion for the fiscal year that begins Oct. 1. Lawmakers from both parties say those sums are not enough to pay for the billions in damage caused by the extraordinary string of weather-related disasters this spring.
"FEMA will have to stop recovery efforts in 50 states in the spring of 2012" without additional money for disaster relief, Sen. Mary Landrieu, D-La., wrote in a letter to her colleagues. She heads the Senate panel that oversees FEMA finances.
So, how do you feel about that? Some folks have expressed the opinion that FEMA shouldn't do as much as they already do. My question to them is: "Who ya gonna call?"
Friday, May 27, 2011
Govenor's Hurricane Conference - New Orleans
Early next week begins the Louisiana Governor's Office of Homeland Security and Emergency Management (GOHSEP)Hurricane Conference. It's timed perfectly to happen right along withthe beginning of H-Season 2011 - I like that. With luck, all synapses willl be firing properly, allowing everyone to be as mentally engaged as they should be right now. Time to check the BS at the door and get serious about planning and preparedness.
Interestingly, in the 2011 DHS budget, though there are 12 DHS grant programs totaling $2.1 billion to assist states, urban areas, tribal and territorial governments, non-profit agencies, and the private sector, the TOTAL budget was actually REDUCED by $780 million from the FY 2010 enacted level, nearly a quarter of FY 2010 DHS grant funding.
Hmmm...let's review:
Heightened level of concern of OBL retributions? Check
Economic impact of the pay of police, firefighters and EMS? Check
Worst outbreak of tornadoes in history? Check
Significantly increased threat of 2011 hurricanes? Check
Border infiltration on the rise? Check
Elevated concerns about "lone wolf" terrorists? Check
So, sure, why not cut the funding needed to prepare and respond to these challenges? Thanks, Washington, DC, your timing is perfect!
So, how do we do more with less? My suggestion is to develop stronger public / private partnerships. Outsource what you can, without impacting your day-to-day operations, or - most importantly - public safety.
Why?
Top 10 Reasons Organizations Outsource
1. Reduce and control operating costs
2. Improve organizational focus
3. Gain access to world-class capabilities
4. Free internal resources for other purposes
5. Resources are not available internally
6. Accelerate reengineering benefits
7. Function difficult to manage/out of control
8. Make capital funds available
9. Share risks
10. Cash infusion
Source: Survey of Current and Potential Outsourcing End-Users
The Outsourcing Institute Membership, 1998
So, why not consider carefully those elements of preparedness, response and mitigation that you can safely and effectively hand off to a trusted partner? It just makes sense. By establishing pre-event contracts, incorporating your partner into your daily operations and having regular exercises, you KNOW WHAT TO EXPECT when the stuff hits the rotary oscillator.
Interestingly, in the 2011 DHS budget, though there are 12 DHS grant programs totaling $2.1 billion to assist states, urban areas, tribal and territorial governments, non-profit agencies, and the private sector, the TOTAL budget was actually REDUCED by $780 million from the FY 2010 enacted level, nearly a quarter of FY 2010 DHS grant funding.
Hmmm...let's review:
Heightened level of concern of OBL retributions? Check
Economic impact of the pay of police, firefighters and EMS? Check
Worst outbreak of tornadoes in history? Check
Significantly increased threat of 2011 hurricanes? Check
Border infiltration on the rise? Check
Elevated concerns about "lone wolf" terrorists? Check
So, sure, why not cut the funding needed to prepare and respond to these challenges? Thanks, Washington, DC, your timing is perfect!
So, how do we do more with less? My suggestion is to develop stronger public / private partnerships. Outsource what you can, without impacting your day-to-day operations, or - most importantly - public safety.
Why?
Top 10 Reasons Organizations Outsource
1. Reduce and control operating costs
2. Improve organizational focus
3. Gain access to world-class capabilities
4. Free internal resources for other purposes
5. Resources are not available internally
6. Accelerate reengineering benefits
7. Function difficult to manage/out of control
8. Make capital funds available
9. Share risks
10. Cash infusion
Source: Survey of Current and Potential Outsourcing End-Users
The Outsourcing Institute Membership, 1998
So, why not consider carefully those elements of preparedness, response and mitigation that you can safely and effectively hand off to a trusted partner? It just makes sense. By establishing pre-event contracts, incorporating your partner into your daily operations and having regular exercises, you KNOW WHAT TO EXPECT when the stuff hits the rotary oscillator.
Thursday, May 26, 2011
"It is Wisdom We Need"
In the essay "Open Sesame" by Henry Miller (included in his book "Stand Still Like the Hummingbird"), Mr. Miller makes the statement,"Every great sage has maintained that it is impossible to impart wisdom. And it is wisdom we need, not more knowledge, or even 'better' knowledge. We need wisdom of life, which is a kind of knowledge that only initiates thus far have been known to possess."
Wow, how true is this, particularly in the field of preparedness and continuity planning?
While there are several definitions of the word "initiate", Mr. Miller clearly uses the one which implies, as defined by Merriam-Webster: (noun)a person who is instructed or adept in some special field. I'd even go a step further: A person who is experienced in a special field, gained through living that experience.
Wisdom. Yes, that's exactly what is needed.
And, as long as I'm quoting from great thinkers, try this one on for size:
I have never let my schooling interfere with my education. - Mark Twain
Wow, how true is this, particularly in the field of preparedness and continuity planning?
While there are several definitions of the word "initiate", Mr. Miller clearly uses the one which implies, as defined by Merriam-Webster: (noun)a person who is instructed or adept in some special field. I'd even go a step further: A person who is experienced in a special field, gained through living that experience.
Wisdom. Yes, that's exactly what is needed.
And, as long as I'm quoting from great thinkers, try this one on for size:
I have never let my schooling interfere with my education. - Mark Twain
Subscribe to:
Posts (Atom)
