‘Enabling Safe Business’ is a series of events looking at the relationship between information security and the operations of the region’s public service organisations.
An in-person event where public sector procurement, IT security and business continuity experts learned about the impact of supply chain failures caused by cyber incidents, how to mitigate risks, practical tools that can help monitor suppliers and how not all cyber risks are technical. This builds on previous work around cyber resilience and incident management.
18th September 2019 Littlehaven Hotel, South Shields
This event was organised as a workshop to bring together people in a range of roles within organisations with responsibilities under the Civil Contingencies Act 2004. These responsibilities include responding to cyber incidents. The objective was to network, share knowledge and experience and progress the civic cyber resilience conversation forward in the north east region.The key messages and findings are applicable to all organisations:
Turn the ‘cyber’ conversation from being about IT security towards being about operational risk. Discuss likely impact of a cyber incident.
Talk with system owners, business managers and information asset owners. Involve colleagues from information security, information governance, information assurance, emergency planning / resilience, business continuity and business recovery. Don’t forget web teams and ‘digital’ sections.
Cyber incidents need not be cybercrime, nor malicious.
A cyber incident timeline consists of inter-related phases:
Business as Usual – Incident (and levels of escalation) – Business Continuity – Business Recovery and New Norm
Plan for common consequences rather than causes. For cyber these are:
Loss of data and voice communications
Loss of key line of business apps (including remote plant, boiler control etc.)
Compromised data / systems (including remote plant, boiler control etc.)
A Cyber Incident Response Plan should use the same framework as your other incident response plans. Think about:
An opportunity to bring together the IT management, IT security, resilience and business continuity colleagues from local public-sector organisations to share experience and discuss civic cyber resilience.
More and more services used by public services are being provided in the cloud and accessed online. We used to call these hosted systems – it’s all the same.With the growth of the ‘apps economy’ it is easier than ever for colleagues to process data using online services, sometimes without the knowledge of IT, information security or data protection colleagues.
“Enabling Safe Business: a closer look at cloud” is a half-day, free-to-attend workshop which aims to bring together key players from north east public services to explore:
Context
Trends towards cloud and types of cloud service
Risks
Impact on business of cloud failures
Risks from the growth of Shadow IT (including that nothing is ever FREE)
Mitigation
Information Security and Data Protection considerations of cloud
Ensuring we procure cloud services taking into account of the risks involved
The workshop will be held at a central location in the Region and should be of interest to