Business Resilience is a complicated topic, where the interdependencies between business, IT and OT technology are interwoven and often hard to discern.
It’s fraught with misunderstanding about what business resilience is and what it’s not. Terms like Business Continuity Planning/plans and Disaster recovery plans are treated as the same thing, but they are not.
Two plans, not one
In short a Disaster Recovery Plan will bring up the technical solution (IT/OT) so business can start their work.
A business continuity plan takes business area and business site considerations into play, so that for specific scenarios business processes can continue with alternative tools and methods or there is a re-allocation of business priorities.
A couple of examples would be moving manufacturing from one plant to another (if suitable for the business area) or dispatching goods to customers from other warehouses if the primary ones are suddenly unavailable.
The cost of unstated commitments
What is also complicated is that the interwoven relationship includes many unstated commitments and implicit trade-offs and no clearly nominated owners. Expectations are typically not stated in a common language and often you can see this very clearly when there is a disconnect between business expectations, business service recovery targets and the resourced infrastructure.
What is important to understand is that there is always a cost to pay and you have a choice about whether you make it up front by explicitly understanding and deciding the level of acceptable trade-offs or down the road when major incidents will disrupt business operations.
And in manufacturing IT/OT is a business cost centre and this brings its own complications, with optimisation efforts that sometimes block business resilience objectives.
The irony is that a function measured on cost is implicitly asked to hold the capacity that only proves its worth on a bad day.
IT and OT fail differently
Regarding IT and OT they have two different and one common challenge.
Some IT organisations are business oriented and focused however others are not and you can see this clearly in organisations that lack business input in disaster recovery planning.
Regarding OT in manufacturing, the key points are that OT resilience is built when the factory is commissioned and the following lock-in is actually an organisational governance issue.
For both IT and OT a resilient system design and architecture at planning/build phase is an undervalued measure.
Resilience also shows in major incident response, where the difference between a resilient organisation and one that’s not can be measured in days, weeks or months of response and recovery.
A simple check
A simple check is to ask what the DRP contains.
If it’s a sequence of startup instructions you don’t have a DRP. A well formulated DRP includes the most likely threat scenarios and specific DRP responses to each including key dependencies that need to be in order to initiate service restoration.
Related reading
- Recovery targets vs reality, on the gap between the recovery targets a business signs off and the capability that is funded to meet them.
- The manufacturing VM problem isn’t a VM problem, on why OT resilience is decided at commissioning and managed through compensation afterwards.
- Supplier lock-in is a governance problem, not a security problem, on the lock-in that follows commissioning and why it is an organisational governance issue.
I advise industry and energy companies on security governance and risk management. More about my work.
Connect: Follow for more insights on security governance and risk management on LinkedIn • Mastodon • Bluesky