UK: 0845 519 9021   IE: 01 969 7866info@itsslimited.com
Blog
Home / Governance and Strategy / Lessons on IT Business Continuity from Ulster Bank IT failure review

Lessons on IT Business Continuity from Ulster Bank IT failure review

0

The recent outcome of a review of major IT systems failures at the Ulster Bank, which left many customers unable to access their money for up to a month provides lessons for all businesses, not just large ones or those in the financial sector.

Unplanned events can have a catastrophic impact on a business and having a considered Business Continuity Plan of some sort is essential for there to be an appropriate degree of resilience.

With IT underpinning the operation of many businesses IT Service Availability and Continuity planning can often be the most important consideration when developing Business Continuity plans.

The responsibility for Business Continuity rests at Board level and it is essential that Directors are fully informed and aware of the risks and business impact associated with IT interruption and the measures that have been taken to safeguard the business. In the absence of an IT Director all too often businesses can, in the absence of a Board member with the necessary mix of Technical insight and Business awareness, be blissfully unaware of the significant IT related risks that the business is running. Often it is only when disaster strikes do the questions get asked and by then it is too late.

In the case of the Ulster Bank fingers are being pointed at ‘Outsourced providers’ of IT services which seem to be a mix of the RBS Group and other offshore service providers. The rationale for pushing blame in that direction seems to be that if the Ulster Bank had kept operation of its own systems ‘in house’ then the risks of such an interruption would have been recognised and mitigated.

This all sounds a little bit like little Johnny saying ‘its not my fault I was told to by my mum!’. The Directors of a business have the responsibility to control the risks associated with business activities no matter whether the activities are being undertaken by in-house staff or external service providers. In many cases outsourced providers are better placed to reduce the level of IT operational risk due to economies of scale and strength in depth of expertise but in all cases there must be transparency of operation and risk management.