Q&A

Metzger on Disaster Preparedness

Disaster preparedness in the spotlight after Hurricane Katrina

By Kathleen Carr

September 06, 2005CSO — CSO magazine editor Kathleen S. Carr spoke to Peter Metzger about the effects of Katrina on disaster preparedness and the CSO role. Metzger, a vice chair of executive search firm Christian & Timbers, was a former military aide in the Reagan White House. He has recruited the global security teams for some of the world's largest companies and serves as CSOs career counselor.

On how Katrina will elevate the role of CSO...

Hopefully, Katrina is cumulative evidence that these events are real. This isnt a terrorist attack, but the results are the same. People need to think constantly about what we can do in the event of a total failure. This means planning how to identify employees and duplicate record keeping. Redundant systems must be kept in another location besides headquarters.

On rebuilding New Orleans...

I believe its nearly an impossibility to rebuild the economic structure of New Orleans. CSOs need to think about ways to react to these events. This applies to small businesses as well as Fortune 100 companies. In this day and age you need to think about these events all the time. This is part of a CSO's responsibility.

On what the current relief effort says about U.S. disaster preparedness...

If you look at the Federal Emergency Management Agency (FEMA), I think it has done an adequate job given the circumstances and severity of the incidentits clear that a lot of things conspired to make this the perfect storm. We now recognize that this event is analogous to a biohazard attack or a dirty bomb attack, and we are systemically unprepared to deal with it, socially, economically or personally. If we cant improve on our national, state and local programs, we set ourselves up for continued problems like this.

On the importance of redundant systems...

This screams to the need to have not only central business operations but also some kind of redundant facility that can have some semblance of recorded information, such as employee identification, document and data retrieval. If theres nothing left, where do you start rebuilding? Remotely locating redundancy is step number one.

On why physical security is increasingly tied to business risk and business operations...

Sadly, all you have to do is look at what happens to the human condition within 48 hours. We experience fear, then loss, then anger, hostility and on to attacking the very people trying to help us. Some of that is lawlessness, but it speaks to the need to be well planned and rehearsed. Until we see these things, we dont know how quickly civil disobedience can break out. Its going to take 30,000 National Guardsmen to keep the peace. People revert to basic survival and will do anything to get water or food to their family in order to survive. We cant plan for that, but we can have enough things in place to recognize that this is going to happen. Whats happening is real, this is not make-believe. Threat analysis and prevention become really important. Disaster recovery is the last part of the plan but were seeing how important it is now.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

Enabling Compliance with Converged Mainframe Security and Storage

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Rolling the dice with your security? Take the Self-Assessment Test now

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Digital Identity Protection and Data Security Get Personal

Welcome to the age of Service-Oriented Security (SOS)

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Configuration Assessment: Choosing the Right Solution

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

IDC Defines an Identity and Access Management Submarket

Using Likewise to Comply with PCI Data Security Standard

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

The Case for Business Software Assurance ~ Securing Your Applications