Evolution of BCP and crisis management to answer cyber threat (By Xavier Fauquet, Formind)
Articles by the same author:
1
3
Introduction
The typologies of recent cyber-attacks and the multiplication of attacks push BCP managers in coordination with SSI managers to review and adapt their BCP strategy and crisis management organization. Those changes aim in particular to answer the following questions:
And more broadly, the CISO and BCP manager must answer the board members the following question: « Are we cyber-resilient? ».
BCP and Cyber threat
BCPs have usually been designed to respond to « classic » major disasters but do not take into account the specificities of a cyber-attack. Thus, in order to assess the ability of a BCP to participate in the response to a cyber-crisis, it is necessary to investigate the following elements and to update the BCP accordingly:
This BCP update requires a strong cooperation between BCP and IS Security teams, in order to share best practices to be applied to solve this type of crisis.
Cyber crisis management
Beyond the BCP aspects, the crisis management organization must also adapt to take into account the specificities of a cyber-crisis on several axes:
Ultimately, the management of this type of crisis and the rise for the need for cyber-resilience require: