May 2018

Hand reaching out/think cirrus/disaster recovery
Blog

Top steps for a simple IT disaster recovery plan

Don’t be caught short. Enterprise networks and data access can go down without warning.  You can’t stop it from happening, but with a good disaster recovery plan you can be better prepared for the unexpected. Expect the unexpected – always!   We know you’ve already got a disaster recovery (DR) plan in place to protect your enterprise’s data, employees and business. But how thorough is your disaster recovery plan? When was it last updated and tested? Have you taken into account new technologies and services that can make it easier to recover from disaster? Here are a few things your IT disaster recovery plan should include. An analysis of all potential threats and possible reactions to them Your disaster recovery plan should take into account the complete spectrum of potential interrupters to your business. As part of the plan you should spell out a recovery plan for each scenario. Of course, not all scenarios are equally likely to occur. So as best you can, try to anticipate which potential disruptors are most probable. Sadly, cyber attacks are becoming a more likely scenario so, cyber attack planning might take precedence over some natural disruptors in your planning. A business impact analysis (BIA) To effectively determine DR priorities, put each major information system through a business impact analysis. A BIA identifies and evaluates the potential effects (i.e. financial, safety, regulatory, legal/contractual, reputation) of natural and man-made events on business operations. Completing a BIA for major IT systems will allow for the identification of system priorities and dependencies.  The BIA examines three security objectives: confidentiality, integrity, and availability. Going through this process means that you’ll be able to establish priorities for your disaster recovery plan. Once you’ve completed the BIA contingency strategies can then be developed. You can find BIA templates and questionnaires online from Ready.gov and other sources.   People People and processes are just as important as technology when it comes to the Disaster Recovery Plans. Now is the time to think about behaviours, systems; essentially all the steps needed so that everyone can start work again as soon as possible. Also, identify by name the critical people charged with responding to a crisis. Have a VIP Crisis list and make sure the direct email, mobile number and home number is clear, correct and up to date. This list are the important people to contact in a crisis and they should know that they are being held accountable. Work with marketing and communications team as well as senior management to determine who will speak for your company to the victims, clients and employees in the event of a disaster. Know what you plan to say, how much you plan to reveal, and how you’ll reassure those who might be nervous of continuing business with your company.   Priorities Not everything in your business is worth saving or needs to be protected. Your proprietary information, of course, is. But any info that is for public release is not as important. Think of it as if your house were on fire. What would you grab as you run out the door?   Regular rehearsals Don’t forget that practice makes perfect. Know you have your plan it needs to be tested regularly. The team involved need to practice the processes and procedures that have been put in place, just like a fire drill, for example. If not regularly practiced, the plan is ineffective.   A consideration of DRaaS The growing practice of moving data operations into the cloud has helped give rise to disaster recovery as a service (DRaaS). These on-demand services have made DR easier and more economical, which in turn is enabling more organizations to be better prepared for disasters. When considering DRaaS, ask how the provider will test and validate recovery of your data and workflows, as some testing is more extensive than others. Act Today The biggest mistake most companies make is waiting until after a cyberattack or disaster to figure out what to do next.  

Blog

Can you operate in any weather?

Is it time to weatherproof your business? The last month has been a tumultuous one when it comes to the weather, with the beast from the east causing disruptions, and amber weather warnings for torrential rain and gale force winds becoming a nightmare for business owners. You’d be forgiven for thinking that any major natural incident could halt business operations. Right? Wrong! Here at Think Cirrus we pride ourselves on being able to work from any place at any time, as long as there is internet coverage. This means you can work as if you were in the office, when you’re not or you can’t be. There’s no excuse with modern technology why any business shouldn’t be able to operate remotely if employees are stuck at home.   This technology isn’t expensive, and in some cases is cheaper than using older systems. Here are a few easily accessible and affordable technologies that can weather-proof your business: Telephone Systems – VoIP (Voice over IP) VoIP systems are the ultimate no-brainer.   Not only do they give you the flexibility to connect to your internal phone system from almost anywhere (and in most cases, from many types of device) but pretty much without exception they are cheaper on rental and call charges than traditional systems. We use VoIP at Think Cirrus, so when our helpdesk guys can’t get into the office because of flooding or snow they simply plug their IP handsets in to their home broadband connections or fire up the VoIP app on their smartphones and are immediately able to deal with support calls. VoIP is great if you have home workers or multiple offices – calls between internal extensions are always free regardless of where they are (including overseas which is a godsend for a few our clients). It’s handy for part time workers who need to work seamlessly from home, or for busy MDs who spend a lot of time out of the office but still need to be part of the system to receive and make calls. Cloud Computing ‘Cloud’ is a huge subject to cover here, but in summary – your data and software no longer needs to be confined to an internal computer network.   With cloud you can access your files, folders, emails and software remotely, usually from almost any device. The benefits of cloud are wide-ranging, from flexibility, resiliency and backup and compliance through to saving both money and the environment. Remote connectivity to your office network (VPN) VPN – Virtual Private Networking – isn’t new by any means but is still a great way of connecting remotely to an internal IT system that hasn’t yet embraced cloud computing (and in some cases, systems that are in the cloud too – though that’s getting a bit technical).   Essentially, a VPN creates a secure, encrypted connection between the device you’re using (e.g. a home PC) and your business computer network, allowing you to access internal resources via a secure link. We’re happy to say Think Cirrus practices what we preach when it comes to remote access, and the team are able to remain fully operational during times of adverse weather. We use a combination of all of the above – we have a VoIP telephone system allowing all staff to connect in from home, and we can also connect mobile phones and tablets to the system if necessary. Our systems run in the cloud – our data is stored in a secure online datastore so we can access it from any location and any device, our email server is online and of course our helpdesk is hosted in the cloud.   We use a secure VPN connection to connect into the office in case we need to access our internal servers. So, if you’d like your business to continue making money whatever the weather, isn’t it time you made your business weatherproof?

Think Cirrus/GDPR Blog/EU Flag
Blog

GDPR: Think Cirrus Perspective

GDPR DEADLINE IS COMING The GDPR deadline is nearly here and it seems to be the responsibility of Marketing and IT agencies to educate the masses about GDPR and what they need to do in order to prepare for compliance when the law changes.   This post explores what we’ll be doing at Think Cirrus HQ to help bring our clients significantly closer to being fully compliant before the regulation is introduced on the 25th May.   As you’ve probably heard the new legislation introduces tougher fines for non-compliance and rumour has it that SMEs will be specifically targeted by these spot-checks because they often ignore this type of legislation.   Any business that has customers is affected so there is still time left we’re encouraging all business owners to  get their head around the regulations now, before it’s too late! You may be aware that data security plays a prominent role in the new GDPR regulation. In comparison to the current Data Protection Act the new regulations follow a stricter set of rules for businesses in relation to security however the requirements from an IT perspective are fairly simple.   To give our clients a little peace of mind our technician’s will be focussing on the following five key areas to ensure customers are on the right track to compliance. Those areas being: 1. Firewalls 2. Secure Configuration 3. User Access Control 4. Malware Protection 5. Patch Management Most businesses should have all of these key elements put in place as part of general good business practice.   For our technician’s, it’s a case of reviewing what measures are in place for our customer base, documenting them and reviewing regularly to ensure everything’s working correctly and running efficiently.   If you’re concerned about your compliance plans or want to learn more about the measures your organisation should be putting in place before the regulation is enforced then please get in touch 

Scroll to Top