Increasing dependence on tech demands board-level IT representation

There is an organisational disconnect between the board and the IT department on disaster recovery.

We asked over 400 UK IT decision makers how their Recovery Time Objective (the length of time it takes to restore IT systems following a disaster) compared with the expectation of the board. Around a quarter (26 per cent) said their recovery times were slower than their boardโ€™s expectation, and a further quarter (24 per cent) didnโ€™t know if they were meeting its requirement. The results reflect what we see in the real-world. There is a lack of agreement on recovery requirements for businesses. ย 

Organisations that do business continuity planning well have recovery objectives agreed and approved by the board. This is important because it sets the goals for business continuity and individual disaster recovery plans. ย Without a consensus agreement, those recovery plans just arenโ€™t working towards a common end.

When planning a business continuity plan, there is a question we must all address. How quickly do you need your IT system back after a disaster? ย Ask the accounts team about billing systems or a sales team about its CRM and the answer is likely โ€œASAPโ€. It is possible for an IT team to deliver that kind of speed of recovery but it comes at a high cost. ย 

Beyond that initial, knee-jerk reaction, if you get teams to think about how they would be able to continue working, using alternative methods you start to get to a more realistic recovery need. ย But ultimately the business continuity team needs to collate this information and weigh the costs and implications of downtime against the cost of recovery solutions.

Once the business sets these objectives, itโ€™s then the responsibility of the IT department to deliver on them โ€“ to build the internal capability or to select a service provider to help them meet that requirement. ย Itโ€™s therefore vital that these projects are adequately funded. Itโ€™s pointless to set a very aggressive recovery time but not provide sufficient budget to deliver on it.

A growing reliance on technology

For that reason, these decisions must also consider expected changes over the short-medium term. The board must factor in that if changes are made to the objectives, it will take time for IT to then source and implement new solutions to meet them.

We were recently told a story by an IT Manager who had just suffered an IT outage. He carried out a successful recovery and had the business back up and running in two days. ย After the incident, he was called in to explain himself to the board. They asked why it took such and unacceptably long time. He then showed them that the recovery went exactly according to plan and met the recovery times they had agreed two years prior.


This example highlights a specific issue:

  1. There is a growing dependence on technology from all areas of business
  2. There is an increased expectation of uptime

Even in a very short period, for that particular business, the requirement changed. Business continuity plans, risks and mitigation plans should be reviewed and updated every year. But also, consider that the average lifespan of a solution is around 36 months (depending on depreciation lifecycle or supplier contract length). It is therefore important to plan sufficiently far ahead.

The case for IT representation on the board

This disconnect over disaster recovery also points to a larger issue. Weโ€™ve recently seen numerous high profile IT incidents, such as the troubled TSB IT migration and the recent British Airways data breach. It reinforces why organisations simply canโ€™t afford to sideline technology to the back office any more.

These arenโ€™t supporting functions โ€“ they are the critical operations of the business. It is our opinion that there is a need for greater IT representation at the board level. There is a need for someone with specialist knowledge to be able to translate the specifics of how technology is enabling the businesses โ€“ as well as the risks it brings.

The board sets the tone for a firmโ€™s digital future, but it is also accountable for the ramifications of tech failures across the entire business. As weโ€™ve seen from our research, itโ€™s clear opinions differ between stakeholders within an organisation. Having a digital leader in place embeds the board with a more realistic understanding of the companyโ€™s IT capabilities, opportunities and threats.

+ posts

Peter Groucutt, Managing Director, Databarracksย 

Prior to forming Databarracks with hisย co-directors Peter spent several years in various operational and financialย riskย management roles within the banking sector latterly developingย applications to monitor V.A.R (Value Added Risk) acrossย banksโ€™ treasury andย hedged products.

In 2000 Peter combined his passion for sailingย with his skills in application development to set up his own company buildingย ship monitoring and harbour management software including the integration ofย S.A.R. (search and rescue) using GPS andย Radar. This proprietary platform isย still in use by some major harbours today.

Unlocking Cloud Secrets and How to Stay Ahead in Tech with James Moore

Newsletter

Related articles

How AI is Transforming Customer Communication Management

Business communication has evolved over the years. Today, it's...

Investment Opportunities for Startups and Technologies in AIย 

Although artificial intelligence developed from niche technology has become...

Four Surprising Lessons I’ve Learned Leading Tech Teams

Techies. Geeks. Boffins. Whatever your organisation calls its IT...

A Business Continuity Cheat Sheet

Right, let's be honest. When you hear "business continuity,"...

Challenges of Cloud & Ultima’s Solution to Transform Business

With the way that AWS and Microsoft dominate technology...