Showing posts with label continuity. Show all posts
Showing posts with label continuity. Show all posts

2025-10-24

Diverted


 

Image from Pixabay

On board flight KL1540 from Alicante to Amsterdam, a call was made for a medical doctor. Moments later, the captain announced that the plane had to divert to Paris due to a medical emergency.

And then things suddenly go differently than you're used to. The tone shifts from friendly-businesslike to measured-strict. The descent feels noticeably steeper than usual. The cabin crew is instructed to check seatbelts and tray tables "if time allows." There's no time left to collect trash with a cart. Once on the ground, you're quickly parked and emergency services arrive.

After everything around the patient is taken care of, you want to return to normal as quickly as possible: onward to Amsterdam. For that, the captain had to "make the necessary calls," for example to refuel and to arrange a new landing slot at Schiphol. He also mentioned choosing not to order extra catering, as that would take additional time. He did take a moment to walk through the cabin to answer any questions.

In IT, you sometimes have to divert too. Something stops working in one data center but still works in another; it's redundantly designed, as we like to say. Failover comes in different flavors. In some systems, it happens automatically and users don’t notice a thing. The system detects something is wrong and switches to "the other side." In other cases, administrators must detect the issue and manually switch things over. And unfortunately, not every situation allows for failover, and users must wait until the problem is resolved.

Just like in aviation, in IT you want to return to normal as quickly as possible after a diversion. You need to plan ahead, because there are often many dependencies that require a specific order. You document the procedures in plans and – very importantly – you regularly practice those plans. Partly to get familiar with them, and partly to catch errors in the plans. Better to encounter those errors during practice than in real life.

Sometimes there's no time to practice – or rather, no time is made. Imagine if pilots weren’t given time to train emergency procedures. And then during takeoff – a fairly critical moment – an engine fails. You don’t want the pilots looking at each other in confusion. No, they should routinely (on autopilot, so to speak) perform the correct actions. Those actions have been thought out, documented, and thoroughly practiced. So that things end well when something goes wrong.

But it can get worse: when no attention is paid at all to the continuity of a process. Sure, you can make the deliberate decision that it isn’t necessary, but in the cases I’m referring to, the topic isn’t considered at all. Out of ignorance, helplessness, lack of time – who knows. Maybe you're thinking of the recent massive AWS outage (Amazon’s cloud service), but feel free to look around your own organization too.

Flight KL1540 arrived two hours later than planned at Schiphol. Not a big issue for passengers whose final destination was Amsterdam. But there were also people on board who had a connecting flight to Kristiansand, in southern Norway. Not many flights go there from Amsterdam. I fear those passengers had to divert to a hotel.

 

And in the big bad world…

 


2025-03-28

The phone isn't working

Image from Pixabay

My grandparents' phone number was 1331. Those four digits were all you needed to reach them. If you called from further away, there was also the area code 04454.

In those days you knew the numbers of family and friends by heart. Other numbers were kept in a special telephone directory: you set a slider to the first letter of the surname, pressed a button and the thing popped open and showed a card with all the names and numbers that belonged to that letter. Handwritten.

At home we didn't have a telephone at all for a long time. You could live with that in the seventies. And the one time you really had to call someone, you knocked on the neighbours' door and gave them a quarter (of the old Dutch currency, the guilder). Or you went to the telephone box in the village. You needed quarters there too. Those were important coins. Too bad they don't exist anymore.

When we finally got a phone, four digits were still enough. Ours were 4006. PTT was the monopolist and everyone had the same device: the T65, with a rotary dial and a curly cord. It sat in the living room and if you were busy in the kitchen, with the door closed, you would sometimes miss a call. And you only knew that when the caller tried again later ("Weren’t you at home?"). That's why my parents had that same PTT install an extra bell in the hall. You paid rent for that, just like for the T65.

Many years later I bought – hesitantly – my first mobile phone. A Panasonic, with an antenna that stuck out about two centimeters above the device. The device had a small LCD display and physical keys. You could call and text with it. Compared to the T65, the number of functions was doubled. Wow!

Look where we are now. Almost everyone walks around all day with a computer in their pocket, which you also happen to be able to make phone calls with. This can be done in various ways. Via your SIM card (the old-fashioned way of calling, with a phone number of ten digits nowadays), but also – with or without live video – via other apps. You can even use it to hold meetings, as we know since the covid pandemic – if necessary with people in all corners of the world. Most people have thrown their landline out the door. Or never had one.

But what if all of that suddenly stops working? No one is reachable anymore, at least not by phone. You can only communicate with each other indirectly. By email or via chat apps. What impact would that have on our social and professional existence? Many subjects benefit from live interaction; if they have to be done via email, the 'conversation' can easily go the wrong way because one person misunderstands the other.

If telephony and video conferencing were to fail for a long time, we would undoubtedly go back to the office more often. Then it would be like it used to be: working from home for a maximum of one day. Everyone has their own personal preference, but I cherish working from home. One day a week in the pandemonium (and, admittedly, also joining in the chatter) is enough for me.

What do we do to prevent a company-wide blackout? Diversity plays a key role. In the Netherlands, there are three mobile networks (Vodafone, Odido (elsewhere still known as T Mobile) and KPN (the heir to PTT!)). All other providers piggyback on these networks. It is financially and from a management perspective attractive for organizations to place their telephony with one provider. But if something goes seriously wrong there, the entire organization immediately has a blackout. So it would be better to spread your chances. You should even make sure that the employees of a team are not all with the same provider. I see a nice administrative challenge…

But is it worth it? We never have long-term failures, do we? In the current climate, I no longer dare blindly assume that it will remain that way. There are strange forces at work in the world. At some point, those forces could benefit from a country becoming paralyzed. We would rather not think about that. And that is precisely why we have to do it.

 

And in the big bad world…

 

2025-01-31

Internet-free days

Photo by author

Our solar panels have the structure of potato gratin on this cold morning. I don't know what nature intends with this, but it looks like the work of an ice artist. Meanwhile, the sun is stretching; it woke up ten minutes ago, I see its red glow reflecting in the windows of houses a street away. Soon its rays will melt the solar panels (well, the ice on them) and then production can begin.

Recently I fitted the smart meter with a box that sends the current measurements to an app on my phone. This allows me to see (almost) in real time how much electricity is being used in our home. We are already practicing hard to use as much of our own solar power as possible: “Can the washing machine be turned on yet?”, is a question that rings through the house often. We then look at the current yield, but also at the short-term sun forecast. Because if the washing machine is turned on now and a thick dark cloud moves in front of the sun in five minutes, you still pay the bill. You do have to keep in mind that appliances like that do not use a lot of power continuously, but mainly when heating the water. With a bit of luck, I can break even on a sunny winter day. That bodes well for the summer.

So, for the energy management of our house, things look rosy. However, if you zoom out to the level of the nation, there’s a much more pessimistic picture: we are in a real energy crisis. There are reports of companies that cannot be connected to the electricity grid. Not because insufficient electricity is being generated, but because the network is congested. Strangely enough, this phenomenon has two contradictory causes: on the one hand, the high demand for electricity, for example because companies are switching from natural gas to electricity, and on the other hand, the high supply due to all those solar panels and wind farms. Think of it as an overcrowded highway: if there is a traffic jam on it, you cannot get on or off.

Our data center has a sturdy emergency power supply. If the mains power fails, batteries seamlessly take over, long enough for the diesel generator to get up to speed. As long as there is diesel, the data center will continue to operate. Grid operators predict that the power will fail more often in the future. So we are lucky to have our own energy building. But of course this facility is not intended as a remedy for grid congestion. In the trinity of information security – confidentiality, integrity, availability – this is a measure to ensure the availability of the service, but it was never intended as a power plant for permanent use.

Data centers are notorious for their power consumption. Pounding computer chips consume power and produce heat, and have to be cooled down because they don't like to get too hot. Even though most computer equipment in a data center has no moving parts, you need earplugs when you go inside. Every device has a fan, and then of course there is a large installation to dissipate all that blown-out heat. Especially the mega data centers of the tech giants, such as Google and Apple, are known for their enormous energy bills. We no longer store our photos on our phones, but in the cloud; in those data centers, that is. And all those millions of photos of the entire world population consume a lot of energy.

Artificial intelligence is a fairly new energy guzzler. With some embarrassment I asked ChatGPT the following question: “How much energy did answering this question cost?” Because it was a simple question, it estimated the consumption between 0.1 and 1 Wh (watt hour). Because it also understands* that I have no idea what that means, it gave a few examples: with 0.1 Wh you can light a 10 W LED lamp for 36 seconds, and 1 Wh is enough for 1 minute of YouTube on your phone. If the questions get more complicated than mine, the energy consumption increases tenfold, ChatGPT estimates. For a difficult question you have to give up ten minutes of YouTube if you want to keep it somewhat energy neutral.

I still remember the car-free Sundays from my youth. Because of the oil crisis, the streets were quiet on ten Sundays. Just imagine that, because of the grid congestion, you cannot use the internet at certain times, for example because the nearby industrial estate needs that power more urgently than you do. Or that the grid operator encourages you at certain times to turn on the washing machine, the tumble dryer and the dishwasher all at the same time because otherwise they cannot dissipate the generated energy. Or imagine that they take care of it themselves remotely.

The solar panels have now thawed and are supplying only a modest amount of electricity. The washing machine is running, so we are still buying electricity at the moment. We are not yet at the point where we can fully adjust our household to the weather, and it won’t be possible in the Netherlands. Not as long as there are no efficient, affordable batteries.

*) ChatGPT and its colleagues don't “understand” anything they say, but you get my drift.

 

And in the big bad world…

 

 

2023-04-14

A year without internet

 

Image from Pixabay

It was a pleasant spring day, that April 14, 2022. Sunny, light wind, twenty degrees (68 °F). But the day started foggy. Not only from a meteorological point of view, also digitally. At 7:53 am the internet started to malfunction. An hour later all screens were black. Worldwide. That was a year ago. The internet is still broken, despite all the smart cyberheads who have weighed in on this. We've been thrown back, cyber-wise, to the floppy era.

Could such a horror scenario ever materialize? At the risk of the wish being father to the thought: I don't think so. After all, the internet is designed to survive the failure of part of the network. It has no all-important component that, if it fails, shuts down the entire Internet. The design has a military background, where availability was of the utmost importance, and this mechanism is of course also very useful in civilian society. Despite the improbable nature of this figment of my imagination, I would like to pretend that the first paragraph actually happened for the duration of this blog. In terms of information security, you could say dryly that there is an availability problem. That's nice, but that observation won't help you much if you can't pull out a recovery plan that lives up to its title.

I try to comprehend what the prolonged absence of the internet would mean. Let me take a look at myself first. For starters, I wouldn't be sitting at my desk at home right now, but in the office. Five days a week. Because working from home without internet is not possible. Well, of course I could write a blog or a memo, save it on my laptop and put it on the intranet at the office (sorry external readers, no blog for you). But that online meeting that I had this morning, that really couldn't have been done. I would have cycled to the office through the cold spring sun. Speaking of cold: without the internet I really wouldn't have known what the weather was like a year ago, and I couldn't have started this blog with the weather report from then.

It's fifteen minutes by bike for me and I find my office blindly, but suppose I had to go to an unknown destination. Would my navigation have worked? Yes and no. GPS is separate from the internet; it comprises a bunch of satellites in orbit and an antenna in my navigation device that picks up the signal from those satellites. So I know where I am and which way I'm going. However, without internet I have no current maps. If I'm lucky, the necessary maps will be in the system. If not, I have to provide the coordinates to tell the system where I want to go. But how do I find out? And I miss up-to-date traffic information anyway, so I may end up in a big traffic jam and arrive too late at my destination.

Well, I still have some old paper road maps lying around somewhere and the signposts haven't been abolished yet either; I would find my way completely without electronics. For digital natives – young people who were born with a smartphone in their hands, who don't even realize there was ever an internet-free era – analogue navigation could be a big challenge. They don't even know how to unfold a map, so to speak, and they see right through signposts.

The demand for many types of personnel would explode. Webshops no longer work - you have to go to the store for everything, which means that they need more staff. Fortunately, there are suddenly many redundant people at the distribution centers of large webshops. The tax return has to be on paper like in the old days, and all that paperwork has to be processed manually. Where do you get so many well-trained tax officials? If I want an appointment at the dentist, the barber or a restaurant, I have to call – fortunately we have not yet shut down our telephone networks under the guise of “there’s Skype and WhatsApp, who needs POTS?” (Plain Old Telephone System).

Travel agencies would shoot up like mushrooms. Because we can no longer book a nice holiday from our easy chair. You have to plan your holiday well in advance, because the travel agency has to send a paper application to the tour operator and in the meantime you have to keep your fingers crossed, because the travel agency cannot check availability online either.

And my work? That continues. Because luckily we have our own large data center, in which the systems run that our own army of IT specialists makes and maintains. We have years of work to do on that. Because security is a process, right? We throw all our energy into this job, without distraction from external emails and social media. And we only hear the news of the day in the evening, when we watch the news via the hastily restored analogue cable TV.

Well, I'm going to drop this blog in de pillar-box.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2023-02-03

Vicious circle

 

Image from Unsplash

A reader had ended up in a vicious circle and shared his story with me, with the opening sentence: “Maybe I have a nice input for your blog.” Well, he was right. His experiences are instructive and can prevent other readers from ending up in the same situation.

Colleague Mark de Wals's iPhone was broken. That in itself was annoying enough, but for Mark it was only the beginning of a vortex that he struggled to get out of. Oddly enough, that vortex was partly caused by two excellent security measures that Mark had taken: he used a password manager and he applied two-factor authentication (2FA, also known as MFA, with M for multi). How can these measures, which I wholeheartedly recommend to everyone, get you into trouble? And, more importantly: how do you stay out of trouble? Wait for it, but above all: learn from it.

Mark wanted his iPhone repaired (it wasn't completely dead, by the way). Before handing over the device, he performed a reset. This ensures that all data, including all accounts, are erased - it is then as if the device came fresh from the factory. It's nice to know for sure that the repairman can't poke around in your data, isn't it? The downside is of course that you have to set up the device again after the repair. Many people don't like that; for many, this is the main reason for postponing the purchase of a new device until the old one can no longer be used. But since the repairman will often need access to the device, you can hardly avoid such a reset.

When the device came back, Mark sat down for it. One of the first things the iPhone asked for was its Apple ID password (“Your Apple ID is the account that gives you access to all Apple services and allows all your devices to work together seamlessly.”) That password was in Mark’s password manager – which was not yet accessible because the device had not yet been set up. But don't worry: thanks to the cloud, the password vault could also be accessed via his laptop.

Mark typed in his password, to which the iPhone responded with: fine, and now you have to approve this login in your 2FA app. Ouch, that app was also on the iPhone – and therefore inaccessible! Voilà a textbook example of a vicious circle: you need that app to get the device going, but the app runs on the same device.

Eventually Mark requested a reset from Apple. That involved an email and a text message. Fortunately, Mark was still able to receive and read the code from the text message. Apple allows a few days to pass if you request a reset from them for security reasons. Those were two scary days, but then Mark received an email and a text message with verification codes. With that he was able to access his account again.

Mark has a few tips for us. The first one concerns the fact that he does not use a real SIM card in this device, but an e-SIM – which stands for embedded SIM and means that the card is built into the device. Your provider therefore does not send a SIM card, but uses the e-SIM. What if you need to receive a text message with a verificaation code, but you can't access your phone? With a physical SIM card, you simply put it into another device and read the message there, but that is not possible with an e-SIM. If the latter is secured with a PIN code, you will not see the received code on the lock screen as long as you are not logged in. Mark had turned off that PIN code since the device itself is protected and you cannot remove the e-SIM from the device anyway.

The next tip is the most important: make sure you keep your most important passwords somewhere you can always access them. Marks password manager ( LastPass ) offers the possibility to share passwords with others. Through this option, he can always retrieve the passwords of his email and his Apple ID. And if another family member also has an Apple ID, you can authorize each other to help each other reset your password.

Android also works with email addresses and phone numbers for account recovery. For this you need a different e-mail address than the address that is linked to the account. But be careful not to use an address that only forwards incoming mail to your primary account - after all, you cannot access it in such a situation.

Mark's experiences teach us that it is important to take measures in advance to escape from such a situation. Check this weekend if you have your affairs in order.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English. 

 

2023-01-27

Scattered clouds

 

Image from Pixabay

Just when I had pretty much accepted that the statement “the cloud is someone else's computer” is very boomerish, an important cloud service collapsed on Wednesday: Outlook, Teams and other Microsoft services no longer worked. What is it with that cloud?

In 2016 I gave a presentation entitled The cloud is not a light cloud dessert (‘cloud dessert’ is a straightforward translation of the Dutch ‘wolkentoetje’, which is a fluffy dessert here in the Netherlands). The title slide featured a photo of Captain Kirk from the science fiction series Star Trek, followed by that series' intro. I slightly modified the epic words spoken in the intro in my subtitles:

Cloud: the final frontier

These are the storages of the computing enterprise

It's never-ending mission

To explore strange new servers

To seek out new privacy and new legislations

To boldly go where no byte has gone before.

See, that cloud is someone else's computer, that's just a fact. It simply means that you do not use your own equipment, but – depending on the chosen model – you use the infrastructure, a development platform or a complete application for end users of your cloud supplier. As a private person you are mainly familiar with the latter variant; chances are that the photos you take with your phone are stored in the Apple or Google cloud – and not on the phone itself. Your Word and Excel files are no longer on your laptop, but in the Microsoft cloud. LinkedIn, WhatsApp, Twitter, Zoom, Teams, Netflix: all of them are cloud services.

Why do companies use the cloud? Suppose you have a company that receives an enormous number of customers once or a few times a year, much more than in the rest of the year. Think, for example, of online shops around the holidays, the tax authorities during the period when everyone files a tax return or a ticket seller for a world star concert. You must have experienced that such a site told you: sorry, currently too busy, please try again later. That situation will occur more likely in organizations that have all the equipment under their own management, in their own data center. They have a limited amount of servers and storage and network capacity there. To avoid this, such a company would have to oversize its data center. A lot of equipment is just sitting there for a large part of the year.

The tempting thing about the cloud is that you purchase their services as needed, and that you can scale up and down quickly. The cloud is elastic, as they say. Cloud providers have huge data centers, with which they serve many customers from all over the world. Because they are so large, and not all customers peak at the same time, they can distribute their enormous capacity among all those customers. If one asks for more, it will not be at the expense of another customer. In addition to this flexibility, the cloud has another important advantage: you do not have to maintain and secure everything yourself. Moreover, for many organizations, a cloud supplier can do this much better than they could do themselves.

But then something like last week happens. Azure, Microsoft's cloud service, had an outage that affected users worldwide. That is quite exceptional, because the major cloud suppliers have built data centers all over the world, which also work as each other's backup. But in this case there was a network problem, which also affected the link between those data centers. If something like this happens in your own data center, only your customers will be affected. Many companies with their own data center are more likely to have disruptions affecting their customers than companies that live in the cloud, because of the elasticity and flexibility of the cloud. But the number of affected customers is much smaller: only the customers of that company are affected. A comparison forces itself upon us: flying is much safer than driving a car, but if an airplane crashes, there are often many casualties.

In my Star Trek intro I mentioned 'strange new servers'. The word ‘strange’ has multiple meanings. But 'unknown' in particular applies here: the cloud is a black box for us into which we put things, hoping that we will also get something out of it when we need it. If it fails to do so, you are just as powerless as if you were on a stranded train. It's just a matter of how comfortable you feel about that.

 

Solution

Last week I challenged you to discover which parts of the blog were written by me and which by ChatGPT. You can find the solution here.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2022-05-20

Wet laptop

 

Picture from author's collection

Last night my daughter (14) came to me: "Dad, my screen is not working." She has a separate screen in her room for her laptop. According to the old adage check cables first I checked that both ends of the cable were in place. I then grabbed another HDMI cable to find out if her cable might be the culprit. No result.

She came home just before the end of the world yesterday (it's been quite stormy here), so I asked if her things had gotten wet. Well, not really, only the cap had come off her water bottle in the bag. But luckily that water bottle was empty. She thought.

I opened the laptop and immediately saw that something was wrong: it was damp in several places. First I took out the battery and patted the damp spots dry with tissues, and I gave the HDMI port the same treatment. The speakers also had to be dried, because no sound came out of the laptop, as my daughter reported reluctantly. I loosened quite a few screws in order to reach several spots. That I dare to do so, I owe largely to a colleague, with whom I once went to a computer fair a long time ago, where we bought individual parts and then put together a PC ourselves.

It’s been said one should put a telephone that has fallen into the toilet or into the sea in a bag of rice, because the rice absorbs the moisture. I hesitated for a moment whether I would give the laptop such a treatment, but decided against it because I was afraid that the rice grains would get stuck in various places and that didn't seem like a good addition to the hardware. Instead, I grabbed the hair dryer and worked the guts of the laptop on a low setting—for both heat and blowing power.

“Never use a hair dryer”, I just read in two different articles, which looked up because I really wanted to know more about that rice advice (no one is talking about that, by the way). Ouch, that hair dryer wasn't such a good idea, because the heat can damage the sensitive parts and the wind can blow the moisture in the direction of extra moisture-sensitive parts. Fortunately, the hair dryer was on low; I'm pretty sure the laptop itself produces more heat than it endured from my action. And the laptop wasn’t like soaking wet, so I don’t think that a lot of moisture could have been moved. But I didn't unscrew enough components to see everything.

In the event of a disaster, you have to act quickly, but if you have to think about what exactly to do at that very moment, you may end up doing things you shouldn't have done. A wet laptop must be switched off completely as soon as possible, all plugs must be removed and then you dry it as well as possible inside and out. So far I've done the right things. At that point I should have done what I only did this morning: get information about the next steps. And of course it would have been even better if all this had been ready knowledge.

I pointed out to my daughter that she should have come to me as soon as she noticed that the laptop was damp – because she certainly had. She looked taken aback when I told her that her laptop would be left open to dry for at least a day. “But then I can't do anything for school!” she exclaimed indignantly. Yes that's right. And this event also reminds us that she should not store her files on the laptop, but on the NAS (hard drive in our home network). I told her this long ago, but after that I never checked whether she actually acts upon my directive, and whether she understands how to do it at all.

Moral of the story: as soon as you know or suspect that something is wrong, you must report it to a competent authority. My daughter should have brought the damp laptop to me right away. And if you come across something in your work that could harm security, report this to the service desk and/or the security officer. And of course informing your manager is always a good thing – they are supposed to be able to tell you what to do (see previous sentence). Don't try anything yourself, except of course pull the plug from a smoking device and things like that.

The laptop is now sunbathing on the windowsill. Hopefully it will recover.

There will be no new Security (b)logs for the next two weeks.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

 

2022-05-13

Resilience

 

Image from Pixabay



Barely recovered from World Password Day, the calendar shows us a campaign from an adjacent field: from 16 May we celebrate Business Continuity Awareness Week. And because business continuity management (BCM) is about as important as information security, this event also deserves attention in the Security (b)log.

BCM is the field that – as the name suggests – is concerned with the continuity of business operations, under what they call ‘unfavorable circumstances'. The word disaster plays an important role in this. The BCM people want to prevent these, and if one does occur, they want to control it as best as possible. Disaster is defined as an unexpected event with such negative consequences that regular problem-solving activities are insufficient to restore the normal situation. In addition to the continuity of the business process, they also have an eye for the safety of employees and visitors and for the reputation of the organization.

The motto of the upcoming special week is 'building resilience in the hybrid world'. Now I'm always a bit wary of mottos of conferences and other activities, because they’re often a bit pompous, while in the end it's about filling the program with contributions that are as appealing as possible and which are preferably presented in a nice way. Anyway, let's peel this motto off.

That hybrid world from the motto, that is of course the world we live in since the coronavirus conquered the world. Before the world became hybrid for us office workers, it was almost pure: we worked in the office, people with young children might have a fixed working day at home, a single daredevil didn’t show up at the office on two working days. During the pandemic, this turned into a situation that was even purer than the old one, but completely at the other end of the scale: from one day to the next we were all working entirely from home. In those two years I went to the office five times to do things that could only be done there. And then you still needed permission from your department head.

When the light came into view at the end of the covid tunnel, we started doing the opposite of what we used to do: we went to the office once in a while. And we prepared for that new hybrid world, because one thing was certain: we would never go to the office full-time again. And that impacts the way in which we have to look at continuity management. That is a statement, not necessarily a fact.

There is a data center just outside my residential area. I pass there every now and then and every time there is at most one car inside the gate. And that's basically how it should be: a technician only comes by when something is wrong, or for routine maintenance. In contrast, the complexes that house our own data centers also have an office function. A few thousand employees walked around every day, pre-corona. In our hybrid world, that has changed drastically. On any given day of the week, more colleagues work from home than at the office. What does that mean in the event of a disaster?

On the one hand, this is a disadvantage, because you are much less likely to have the necessary people present to cope with the event, simply because they are not in the office at the time. But yes, “together” is something very different today than it used to be. We meet virtually just as easily, although many will agree that in certain situations you can work together more smoothly if you are together in real life. In the event of a disaster, you may consider this flexibility as a luxury.

On the other hand, working from home is an advantage, for exactly the same reason: many people are not in the office. If it is a physical disaster, such as a fire, you do not have to worry about colleagues who are not there. An evacuation will be completed more quickly and the number of potential victims will be smaller. Furthermore, if part of the office workplaces are no longer available due to the disaster, you do not have to search for an alternative location: the affected employees have to 'just' work from home continuously for a while. Nowadays you no longer have to perform technical feats for this, because the necessary infrastructure is already there.

However, the reasoning in the two preceding paragraphs only applies if the disaster has not affected the infrastructure required for working from home. We must develop the necessary resilience there, insofar as this has not already happened. The rest of BCM is business as usual for which hardly anything changes in the hybrid world.

By the way, today is Friday the 13th. A perfect day to talk about disaster.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...