News & Events

News & Press Releases

Nov 25, 2009—RTO & ROI - The Business Case for Disaster Recovery

Tom Hinkel, Director of Compliance

Your ability to recover from an unanticipated business interruption is a direct function of your specific recovery procedures, and according to the most recent FFIEC guidance, "...recovery time objectives (RTOs) are now much shorter than they were a few years ago, and for some institutions, RTOs are based on hours and even minutes." All Business Continuity Plans (BCPs) should begin with a comprehensive business impact analysis, which is designed to identify the most critical processes and functions and establish an RTO for each. Once the RTO is established, resources are allocated and specific procedures can be implemented to assure that the processes (and their interdependencies) are recovered within that RTO. Finally, testing will validate that the recovery procedures are effective.

Once the RTOs have been established by senior management, the BCP committee (or equivalent) will determine the best recovery method for each function. For example, in a traditional money center institution, cash handling functions typically have a lower (shorter) RTO than loan origination, meaning a quicker recovery time requirement. The teller functions rely on multiple interdependencies, such as core connectivity, WAN, LAN, Active Directory user authentication, and application software. All components must function properly in order for the teller functions to operate, and your specific recovery and testing procedures should include all interdependencies.

For example, let's say the business impact analysis has determined the following recovery time objectives for these critical functions:

Functional Area RTO (Days)
Teller Functions
<1
CSR Functions
1
Electronic Services - Debit Card
1
Electronic Services - Internet Banking
2
Electronic Services - ACH
2
Electronic Services - Merchant Capture
3
Loan Origination
4
Loan Servicing
5
Loan Administration
5
Accounts Payable
10+

Using the teller functions as a further example, a work flow analysis has identified the following interdependencies to the teller process:

Teller Function
arrow pointing right

Software

Hardware

LAN

Core

Facility

- OS - PC - Server - WAN - Security
- TellerPlus - Teller Printer - DHCP
- Scanner - AD
- Laser Printer - SQL database

Since the RTO of the main Teller function is less than 1 day, software, hardware, LAN, core and facilities must all have an established RTO of less than 1 day. If testing does not validate recovery within the RTO, there are 3 options:

1. Increase the RTO to fit your current recovery capabilities. This could increase risk in other areas, such as regulatory, reputation, operational, or strategic.
2. Allocate additional resources to the recovery process. This could include staging spare equipment, hosting critical servers off-site, and utilizing online data vaulting.
3. Keep RTO's and recovery procedures as is, and hope you never have a disaster (not really an option, but more common than you would think).

Depending on the threat, disasters can affect any or all of the following: people, processes, technology, or facilities. A server hosting solution can potentially eliminate technology and facilities from consideration, thereby shortening the recovery process. Additionally, in the case of teller function, the institution would also require a physical facility for customer access, however, with a server hosting solution, they would not require a server and database rebuild, which is the single most time consuming part of the recovery process. Based on these requirements and FFIEC RTO guidelines, Safe Systems has developed a comprehensive solution to address both server hosting solutions (Continuum), and physical facility recovery through our strategic partnership with Recovery Solutions.

There is generally an inverse relationship between recovery time and cost, i.e. the shorter the RTO, the higher the financial investment. This is only logical, because the most critical functions are those that carry the most significant risk of financial loss to the institution. Considering options such as a Safe Systems' hosted server solution in your recovery planning will help you to assure that your RTOs are achievable. Equally important is that any such solution includes periodic tests in order to validate all recovery assumptions. To learn more about Hosted Services, Disaster Recovery, and our solutions, please contact your Account Manager.

For media inquiries, please contact:

Marketing Department
770.752.0550
info@safesystems.com


All News & Press Releases:

 

 

 

Is Your Financial Institution's Data Backup System Really Working?

Are you confident you have an effective and compliant disaster recovery plan?

 

Client Testimonials

“I appreciate all that Safe Systems does to keep us in compliance with the FDIC and regulators. The examiner could tell that we have worked hard on getting the IT area to where it is today. Safe Systems Managed Services made it much easier.”

Dawn Kelley
The Commercial Bank

group of people

“Safe Systems Managed Services offers a vast array of options to help us maximize our IT staff’s time, productivity, and budget in a way that is completely scalable to meet our specific needs as we grow and change.”

Leesa Anderson
State Bank of Cochran

group of people

“The focus on financial institutions has allowed Safe Systems to gain invaluable experience that we can tap into and learn from as we change to grow our network infrastructure to meet the needs of the bank.”

Leesa Anderson
State Bank of Cochran

group of people

“Safe Systems Managed Service is the BEST thing since sliced bread!!! GREAT JOB!!”

Glenda Miller
Williamsburg First National Bank

group of people

“Safe Systems has the BEST support team …everyone is full of personality and they each have their own way of making you feel IMPORTANT!!”

Kathy Godwin
Williamsburg First National Bank

group of people

“It’s easy to talk positively about my experience with Safe Systems. EVERYONE I’ve talked to has been overwhelmingly helpful. Thanks for providing top-notch service, and always doing so in a friendly manner.”

Mathew Tomlinson
Flint Community Bank

group of people

“The expertise that Safe Systems provided during the implementation of the Bank and on the ongoing assistance they give has enabled HNB to score very well on all of our regulatory and internal audit IT examinations.”

Michael Carleton
Herald National Bank, NYC

group of people

“With Safe Systems Managed Services, patching my servers and workstations is automated, I get daily reports and my servers and workstations stay patched with the latest Microsoft Updates. Which is great for audit time!”

Robert Gay
The Bank of Bonifay

group of people

“I wanted to let you know we just completed an IT audit, and the auditors were very complementary of and impressed with your NetComply product. This was the first time they had seen it in action.”

David Reynolds
InsBank

group of people

“We always receive exemplary customer service from Safe Systems. The entire group of engineers have always provided superior courteous service. This encompasses minor problems to the complex. I believe we receive an excellent value for the dollars we spend with your company.”

Charles Knight
United Americas Bank

group of people

“I could not ask for a better company to put my trust in when maintaining my network. As a Platinum customer, I don't worry about anything because I know I have knowledge, experience and professionalism standing behind me with the Safe Systems staff. Wouldn't go anywhere else!”

Nicole Rinehart
American Pride Bank

group of people