Effectiveness of DR plans questioned
New survey raises concerns over disaster recovery plans
LONDON – Although almost all UK companies back up their critical IT systems and data, more than a quarter of them still do not have a disaster recovery plan in place, according to the 2008 Information Security Breaches Survey (ISBS), which was carried out by a consortium led by PricewaterhouseCoopers on behalf of the Department for Business, Enterprise & Regulatory Reform (BERR).
The survey found that half of those that do have plans fail to test them and that 15% of companies do not take their backups off site. This is despite that fact that 92% of businesses now consider disaster recovery planning an important driver of their IT expenditure.
Some 68% of companies polled believe business continuity in a disaster situation is a very important driver of their information security expenditure, and a further 24% say it is important. Only 2% say it is not very important. And UK businesses are certainly improving their protection: 99% of UK companies back up their critical systems and data, with 86% doing this at least on a daily basis. Some 85% of all UK companies take their backups off site (up from 76% two years ago); 91% of large businesses take their backups off site. Seventy-two percent of all UK businesses have a disaster recovery plan in place, up from 58% two years ago. Of which, 91% of large companies have a disaster recovery plan.
However, there are still concerns about the effectiveness of these controls. The survey found that 28% of companies do not have a disaster recovery plan in place, almost half of the disaster recovery plans have not been tested in the past year, 10% of companies with a disaster recovery plan do not store backups off site, 31% have no contingency plan in place in case of a systems failure or data corruption incident and a further 10% found their contingency plan to be ineffective.
The south-west has now overtaken London as the region with the most disaster recovery plans in place (possibly as a result of last year’s floods), but fewer of these plans are tested than in other regions.
“It is encouraging to see that almost every UK business makes backups and the vast majority now take these backups off site. The risks are well understood; it does not take an incident to raise awareness,” said Chris Potter, a partner at PricewaterhouseCoopers who led the survey. “The number of companies with a disaster recovery plan has gone up. However, experience shows that plans are only effective if regularly tested. It is a concern that only half of plans have been tested in the past year.”
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Technology
FX options: rising activity puts post-trade in focus
A surge in electronic FX options trading is among the factors fuelling demand for efficiencies across the entire trade lifecycle, says OSTTRA’s commercial lead, FX and securities
Dismantling the zeal and the hype: the real GenAI use cases in risk management
Chartis explores the advantages and drawbacks of GenAI applications in risk management – firmly within the well-established and continuously evolving AI landscape
Chartis RiskTech100® 2024
The latest iteration of the Chartis RiskTech100®, a comprehensive independent study of the world’s major players in risk and compliance technology, is acknowledged as the go-to for clear, accurate analysis of the risk technology marketplace. With its…
T+1: complacency before the storm?
This paper, created by WatersTechnology in association with Gresham Technologies, outlines what the move to T+1 (next-day settlement) of broker/dealer-executed trades in the US and Canadian markets means for buy-side and sell-side firms
Empowering risk management with AI
This webinar explores how artificial intelligence (AI) can strip out the overheads and effort of rapidly modelling, monitoring and mitigating risk
Core-Payments for business leaders: why real-time access to payment data is key to long‑term business success
Business leaders require easy access to timely, reliable and complete information across post-trade processes. Aside from the usual requirements of senior managers to optimise for risk, revenues and costs, they increasingly need to demonstrate to their…
Risk applications and the cloud: driving better value and performance from key risk management architecture
Today's financial services organisations are increasingly looking to move their financial risk management applications to the cloud. But, according to a recent survey by Risk.net and SS&C Algorithmics, many risk professionals believe there is room for…
Machine learning models: the validation challenge
Machine learning models are seeing increasing demand across the capital markets spectrum. But how can firms improve their chances of gaining internal and regulatory approval for these type of models?