Daniel Schraibman talking at Fieldfisher and Nelson Mullins Riley & Scarborough's Cyber Security and Crisis Management event.

Do you have an offline crisis plan at your firm?

Why Every Business Needs an Offline Crisis Management Plan

At a recent Cyber Security and Crisis Management event hosted by Fieldfisher and Nelson Mullins Riley & Scarborough, we explored how organisations can prepare for an increasingly complex and interconnected threat landscape.

Thank you to Tim Bird for the invitation to speak, and to Scott Sherman, Katy Spicer, Kirsten Whitfield, Quinton N., Ericka J., Farheen Ishtiaq-Stansfeld, Martin Rose, Alex Harbin, Lydia Marref and John Armstrong FREng for the engaging conversations and insights.

Preparing for systemic risks

One of the key issues discussed was the need for organisations to think beyond the risks that directly affect their own business.

Traditional crisis management planning tends to focus on scenarios such as a cyber attack, data breach, ransomware incident or major operational disruption. These remain important considerations, but organisations also need to prepare for systemic risks, events that can affect the wider infrastructure on which businesses depend.

Attacks or disruption affecting subsea pipelines, electricity infrastructure, telecommunications networks and internet cables could have consequences far beyond the organisations directly targeted. A company may find itself facing a serious crisis without access to some of the basic systems it normally relies upon to respond.

What happens if the power or internet goes down?

Modern businesses are heavily dependent on digital connectivity. Crisis teams may rely on email, messaging platforms, cloud-based systems, online documents and video conferencing to communicate and coordinate their response.

But what happens when those systems are unavailable?

An effective crisis management plan should consider how the organisation would operate if it lost access to power, the internet or critical communications infrastructure for an extended period.

This could mean identifying:

· Alternative methods of communication between crisis management teams.

· Offline copies of critical contact information and business continuity documents.

· Physical locations where crisis teams can meet if remote communication is unavailable.

· Alternative sources of power and communications.

· Clearly defined roles and responsibilities that can operate without access to normal IT systems.

· Procedures for making critical decisions when usual information and communication channels are disrupted.

The objective is not necessarily to predict every possible scenario. It is to ensure that an organisation can continue to make decisions and respond effectively when its normal systems are no longer available.

Is your crisis plan truly resilient?

Cyber security and crisis management are increasingly interconnected with the resilience of the wider infrastructure on which businesses depend.

It is therefore worth asking a simple question:

If your organisation lost power and internet access tomorrow, could your crisis management team still function?

For many organisations, the answer may reveal an important gap in their current resilience planning.

An offline crisis plan can provide an additional layer of preparedness, helping organisations remain capable of responding when the systems they normally depend upon are unavailable.