Deals from Amazon

Wednesday, 25 May 2011

Data Backup Considerations

Data is vital to modern businesses.  Some say it's the life blood of a business.  After all we live in the information age.

But do we all protect data and information to the best of our abilities?  Do we ensure we can recover from its loss, corruption or theft?

In information security parlance are we properly protecting its CIA - Confidentiality, Integrity and Availability?

Most businesses take some steps to backup their data. This can be using traditional methods such as tape drives to newer techniques involving optical media, removable USB storage or even online backup solutions.

If you're not backing up your data then you should be. It's inexpensive and might just save your business one day.

But backing up your data is only half the story.  Having a backup is meaningless if you can't recover your data in the event of an incident.

You need to test that you can restore your data on a regular and random basis.  This exercises your solution and ensures it is actually doing what you expect of it.

Another consideration is the age and technology used.  If your infrastructure, devices and backup software are more than a few years old you may have other problems should you experience a significant incident or disaster with your systems.

If your incident takes out your current infrastructure can you replace it to actually recover your backups?

Without compatible technology and software your data may be inaccessible without expensive and time consuming 3rd party services.

Then there are online solutions.  There are many of them out there and they are fairly inexpensive but which one should you choose?

Depending on the data and the legal or regulatory requirements you may need to think very carefully. Your data may fall under one jurisdiction while it's residing on your servers and PCs in your office but whose jurisdiction is it under the control of on the backup storage?  What are their data protection, privacy and security laws like?

Is the data stored encrypted where only you can access it or can the staff at the service provider actually access your data, with or without your permission?

These are all things you need to consider when selecting a backup solution.  It isn't a simple choice based on price so think carefully and ask the questions above. They might just stop you going out of business.

In the meantime if you are looking for an online backup solution why not contact us on 0845 071 4690 or visit www.SecureThinking.co.uk and ask us these questions?

Wednesday, 11 May 2011

How's Your Business Continuity Plan?

Businesses are fragile things. They can be affected in their success by
a whole host of factors including market forces, consumer habits, and
changes in attitudes.
But many aspects of your business success are firmly held in your own
hands. You can develop an agile approach allowing you to change your
model based on market forces, you can adapt your products or services to
take into account consumer demands and you can keep track of people's
opinions to ensure you keep with current thinking and attitudes.
But how would you cope with a major incident that occurred to or in your
business?
Business continuity and disaster recovery are essential tools designed
to protect your business should the worst happen.
If you make use of technology in your business and particularly if it
forms the backbone of your operations you need to make sure you have a
Disaster Recovery Plan.
Disaster Recovery is the process of recovering your technical systems,
data and applications to a level which allows you to continue operating
your business.
Sometimes a DR solution will only recover key systems - just enough to
keep you going in the short term until a full recovery can be performed.
A technical disaster or incident can be caused by a number of internal
factors including technical faults, accidental damage caused by errors
or malicious activity.
Disasters can also be caused by external factors such as power cuts,
floods or property damage.
The key to an effective DR plan is to evaluate which systems,
applications and data are key to your operations and ensuring these are
recovered first. There is no point spending time and effort recovering
your marketing database when your customers aren't getting the products
they've ordered or the services they've bought.
Getting your DR plan right can mean the difference between having a
business in serious trouble and your customers not even knowing there
was a problem.
A Business Continuity Plan is similar in many ways to a Disaster
Recovery Plan. The main difference is that the BCP deals with more than
just technology.
Your BCP covers all aspects of your business, from offices and desk
space, communications, operations, to incident response, staff safety
and public relations.
Whether you decide your business needs a full BCP or merely a DRP you
should be aware that having one and making sure it is up to date and
tested can be the difference between your business surviving and growing
and it's complete failure.
There are many statistics out there but the general consensus is that
businesses experiencing a major incident and who don't have an effective
BCP will go out of business within 6-24 months of the incident.
You have insurance to cover you should the worst happen. A Business
Continuity Plan or at the least a Disaster Recovery Plan should help
protect you in the same way - by ensuring your business survives
whatever is thrown at it!
Our philosophy is simple - plan for the worst, hope for the best!
For more information or a free BCP/DRP consultation contact Secure
Thinking on 0845 071 4690 or visit http://www.securethinking.co.uk/

Monday, 2 May 2011

Information Security Posture - What's Yours Like?

Pretty much all modern businesses deal with information of some description. Whether it's basic day-to-day accounting data on your own business, financial records of other businesses and individuals, or detailed personal and medical files on thousands of people, information exists within your business.
Unfortunately, whatever information you have in your business there's a pretty good chance that someone else wants it. These people could be simple criminals out to make a fast buck, organised crime gangs running a profitable if somewhat corrupt operation, competitors willing to try a little industrial espionage, or even nation states using your business to gain international advantage.
And your size and stature doesn't always have to be substantial - indeed the Information Commissioner's Office here in the UK considers smaller businesses a weak link precisely because they are small and often unwilling to invest in effective information security controls, and because they frequently supply to or work on behalf of major corporations.
So we've established that your business handles information, and that a threat exists to that information. The next question is what are you currently doing about it?
If you have existing security controls in-place, are they effective, both in terms of costs and protection? Do your staff understand their role in protecting information? And can and should you be doing more?
Now unless you have an effective system for testing and assessing your information security controls it's doubtful you can answer these questions with any degree of certainty.
So how do you go about measuring the level of information security within your business?
The 1st option is to trust in fate and hope that you never experience a breach. The problem with this approach is that it relies on your organisation never being targeted. Now of course it may indeed never be targeted directly. But I'm sure you would agree that's not the most sensible approach. Especially when all evidence suggests such attacks are on the increase.
Another option is to implement a process of measuring your own security controls. If you have the skills and resources this might appear the best solution and that way you're not exposing your soft underbelly to 3rd parties. The downside of this is that like any internal process, you may be the victim of politics where the judgements and test results end up being skewed by internal issues and rivalries, making the results unreliable.
In addition, if reduced risk and improved security is your goal, with a long term objective of possibly gaining some kind of certification (such as ISO27001), then you really need an objective, unbiased opinion from a trusted business partner.
Which brings us to the 3rd option - find a suitable security assessment provider and have them do an assessment of your business.
Now obviously there are a number of solutions in this area. Fixed price offerings such as Secure Thinking's Quick Information Security Assessment (QISA) are primarily designed for small and medium sized organisations. If you are a lege business or need something more thorough you might opt for an assessment performed on a consultative basis by an experienced individual or business.
If you wish to go down the route of certification you might need help in choosing an appropriate certifying body and then assistance implementing the controls, policies and systems needed to obtain certification.
All of these services can be performed by a number of reputable companies, including Secure Thinking.
Whichever option you go for in the end you are far better off ensuring you properly assess your information security controls than simply crossing your fingers and hoping for the best. Your business and your customers are deepending on you!