The Three-Legged Stool of Resilience: Navigating the Boom (Resources for County IT Professionals )
Unforeseen disasters can strike at any time, and our digitally reliant world is experiencing more frequent and more sophisticated attacks. The same can be said for county officials as they turn to technology to solve complex problems and improve operations. Whether it’s a storm, cyberattack, or water main burst, your community turns to county officials for answers and leadership during turbulent times. Often, during significant events, it can be chaotic and confusing. But what ensures that essential government services – elections, tax filing, emergency response – can continue through the chaos? To keep the government upright during a disruption, county officials can turn to three essential plans: Continuity of Operations, Incident Response, and Disaster Recovery.
Together, these plans build a solid foundation that won’t crack or wobble when things get tough. Just like a stool needs three legs to stand, government resilience requires these plans to work seamlessly. If you’re missing one leg, or it’s cracked and in disrepair, the stool – and your operations – can fall over when stability is needed most.
Leg 1 – Continuity of Operations Plan (COOP)
This plan ensures that essential services and functions can continue no matter the disruption, whether it’s emergency response, elections, etc. Define who’s in charge of each function, where operations will take place if primary buildings are inaccessible, and how staff will keep serving your communities. Typically, these plans are applied organization-wide, but they can be tailored to essential services too. For example, you may want to consider a carve out for election operations due to their unique requirements and key dates. It’s possible your elections office already has a COOP plan, and if so it will be important to align them with your county-wide strategy. The plan should also focus on immediate and short-to-mid-term operations.
Some key elements to consider:
- Identify critical services, personnel, and mandated operations
- Orders of succession and delegation of authorities
- Vital documents and records
- Alternate facilities
- Pre-plan communications to internal and external stakeholders
- Resuming normal operations
- Integrate with IRP and DRP planning and testing
Leg 2 – Incident Response Plan (IRP)
This leg is more focused on rapid response and cybersecurity. It’s a structured and repeatable approach to identifying, responding to, and recovering from cyber incidents or other technical issues. Typically, they are developed in a manner that’s focused on managing an incident – to help responders navigate each step of the process and ensure stakeholders are updated along the way. So, when an incident or breach is first detected, this plan kicks in. It’s a playbook for containing and remediating threats promptly.
Some key elements to consider:
- Identify members of a response team
- Define types of incidents, including severity, that cover different types of threats. The playbook won’t be the same for all cyber threats.
- Understand how to triage and escalate potential issues
- Train staff how to report suspicious activity
- Define procedures to contain and eradicate malicious activity
- Pre-plan communication to internal and external stakeholders
- Document lessons learned
- Integrate with COOP and DRP planning testing
Leg 3 – Disaster Recovery Plan (DRP)
Finally, there’s the DRP. Sometimes, this plan gets less attention than the other two, but it is a critical player in your arsenal of tools. Think of the DRP as the resurrector – what is needed to restore systems and data. Regardless of the incident, this plan ensures you’re not rebuilding from scratch. For example, if there’s a hardware failure that takes your primary data center offline, the DRP would outline a timeline and process to failover to secondary systems, and eventually restore primary systems. The DRP is especially vital when minutes or hours are critical in providing essential services, such as when you’re in the middle of administering an election or responding to a large-scale emergency or public health event.
Some things to consider:
- Identify, document, and maintain an inventory of systems and assets
- Consider your recovery time and recovery point objectives, which may change throughout the calendar year, depending on the critical service.
- Implement frequent backups
- Identify and implement infrastructure redundancy (i.e., power, networking, and hardware)
- Create detailed steps on how to failover between primary and secondary systems, including the restoration of data.
- Integrate with COOP and IR testing and planning
A truly resilient government needs all three plans working in tandem. Regardless of your role in county government, everyone plays a part in strengthening critical infrastructure. Take a moment to connect with your colleagues and leadership to create, review, and update any plans. When a disaster strikes, you don’t want to be caught off guard because extended downtime can paralyze essential services and cost your organization big money. According to a report by IBM and the Ponemon Institute, organizations with established plans were able to reduce breach costs by more than half. Similarly, organizations that lack incident plans and preparation spend more days, on average, to stop and recover from the incident. This gives new meaning to making every second count – because seconds do matter.
Even though threats continue to evolve and are on the rise, the good news is that you aren’t alone; there are plenty of resources at your fingertips. A few have been highlighted below. The bottom line is that planning and maintenance of existing plans can pay off. You wouldn’t want to sit on a dusty or broken stool, would you? Together, these plans can build and strengthen your county’s foundation and can ground your team during chaotic times. Being prepared is no longer a nice-to-have; it’s a necessity. So, make sure there are three legs under the stool to prop up your county government. Your citizens will thank you and feel safer for it.
Next Steps for your County:
You might be thinking, “What can I do to improve our plans or get started?”. Whether you already have plans or are just beginning, here are some pragmatic, manageable steps to take:
- Build a multi-disciplinary planning team
- Identify critical services and departments in your county and understand potential threats
- Understand the impact of disrupted services
- Reach out to peers and partners to compare practices
- Create or update your plans
- Schedule a tabletop exercise to train
- Establish a routine review period and training schedule
Helpful Resources to Jump Start Your Journey:
Below are some resources that may support creating or updating your plans.
CISA’s Incident Response Plan Basics
NIST Incident Response Recommendations and Considerations for Cybersecurity Risk Management (NIST SP 800-61r3)
The State and Local Election Cybersecurity Playbook, Harvard Kennedy School, Belfer Center for Science and International Affairs
Election Cyber Incident Communications Coordination Guide, Harvard Kennedy School, Belfer Center for Science and International Affairs
Cyber Incident Response Planning Materials for Municipalities, MassCyberCenter
Contingency Planning, U.S. Election Assistance Commission
IT Disaster Recovery Plan, Ready.gov