Business Continuity: Command and Control Protocols
Looking at what progress has been made in the US financial market on disaster recovery following September 11th, Peter Vinella believes that there is need for a compulsory set of protocols.
A. We did acquire a lot of work with a couple of committees in US congress, and we’ve done work with the GAO (the General Accounting Office). That work was in understanding what lead up to September 11th from a vulnerability point of view. Also we did a follow up with the industry in response to the actual aftermath of the attack. We looked at it more from a governmental regulatory view rather than from an individual client point of view.
A. Although our clients were interested in business continuity, no one wanted to really talk about it. What we did do for the clients was look at it externally: the vendors, the counter parties, the financial utilities they relied on.
A. We’d go out and figure out who a client’s key vendors were. Most of our clients were financial institutions but a lot of the principles apply to corporate treasurers too. If you think you have a liquidity line with somebody – in the case of a liquidity crisis will they really be there for you? Will they lend you the money if they say they will? Can they lend it to you? On September 11th a lot of major sources of liquidity dried up. Due to no fault of their own the companies that our corporate relied on for funds just weren’t able to deliver the funds.
The second problem they had was a lot of their securities, especially those that were custodied at institutions which were affected by September 11th, didn’t have access to that collateral, they couldn’t move the collateral, couldn’t meet a lot of their security trading obligations, and they couldn’t use it for liquidity generation.
The third thing they started looking at was the vulnerabilities of intra-bank, intra-financial institution networks – Fedwire, SWIFT, ATM networks. There was a lot of concern around these. And it’s interesting that their concern shifted away from physical attack to cyber attack at that point.
A. As regulators started making suggestions on disaster recovery, individual institutions started responding. Within a year of September 11th most of the moves became industry-specific rather than company specific. The Securities Industry Association (SIA) came up with standards, the National Futures association did too. While I am focusing my comments on the US it really was a global effort.
A. The Bank of England and the FSA were even more aggressive in timescale, scope and effectiveness than the US was. That was, I think, due to a background of being used to attacks by the IRA. They already had centralised control in place so they knew how to respond. Secondly they already had a lot of regulations that talked about disaster recovery/business continuity. Thirdly the financial community in the UK had already discussed and worked through a lot of these issues already. On the other hand I think in the US there was such a period of shock and denial after September 11th that it took a while for it all to sink in and for people to respond. That was the difference in the US – before September 11th most people thought about disaster recovery in terms of power outages in their building or mechanical failures.
A. The SIA, the Bond Markets Association, the Futures Association have got together and tried to deal with some of these problems but they are all still very superficial. They haven’t dealt with some of the core problems, for example how do you back up people or individuals? When people started looking at the cost of these plans of full redundancy, they back away. The progress that has been made has had more to do with technology than addressing all of the weaknesses.
A. People recognise that disaster recovery and business continuity preparations are an issue. There are three levels to this problem. At the first level we have the low-level technology – redundant servers, redundant networks – that sort of thing. The industry has started to look at its system-wide utilities and has seen to it that there is a lot of redundancy built into them. On that level a lot of progress has been made.
The financial utilities – the big depositories, the exchanges, the custody clearance banks – have tried really hard to improve their vulnerability, e.g. extra computers or a second site. The financial utilities have done a reasonable job with that. But other than that there is still an issue with replacing personnel.
The third layer of the problem is the command and control layer and this is where the least progress has been made. What I mean by command and control is “if there is a problem what do I do?” Knowing what to do in a given situation so that if there is a problem you at least know what you are supposed to do would be very useful. Right now it is up to companies to voluntarily adhere to directions that are primarily given out at the time of the crisis. This can be confusing. What we need is a prescribed set of compulsory protocols that say under X circumstances you do Y. The fact that there are no guidelines as of yet is much worse for a financial institution than for a corporate.
A. For example if I am a large corporate I could have five or six banks and that can help to give me natural diversification. A corporate treasurer himself is probably not going to be the target of a terrorist attack. Corporates also have the advantage that much of their business would already have a business continuity/disaster recovery aspect to it although they may not have extended this to the treasury department yet. If you are a chemical manufacturer you already have disaster recovery because it is part of your core business. So what the corporate needs to do is apply those same standards to the treasury function. This is where I have seen most of the problems on the corporate side – they haven’t looked at problems like “what happens if my major bank is down?” or “what happens if there is a virus in the system so I cannot do automated transfers?” Also, what about if you have outsourced your treasury function? How does that affect you? So I think from a corporate point of view it is more about planning than anything else and coming up with better contingencies.
A. The President’s Working Group on the Financial Markets (made up of the head of the Fed, the head of the SEC, the secretary of treasury, and the CFTC) should come up with a set of protocols at the command and control level. You don’t want people saying ‘well now what do we do – do we trade or not? Do we move money – do we not move money?’ It would be good to have a list of the types of outages, and what people should do in each case. You’d probably want some rules that say that if a number of institutions can’t do business the market will close. Secondly if there are issues with secondary liquidity pools based on cash movements, or on access to securities, there should be some rules of engagement.
These financial utilities, like stock exchanges for example, should have to prove that they have back up sites that work. They should have to prove their resilience. I don’t propose to have regulations that require companies to spend huge amounts of money but there should be basic performance metrics that say under these conditions you have to be able to do X, Y and Z.
A. If I was a corporate treasurer and I went to a bank and the bank says here are all the things I have in place to make sure that if there is a problem you still have access to your money I’d rather bank with him and pay him a little bit of a premium than a bank that doesn’t really address business continuity.
I think financial institutions need to start looking at business continuity as being of business value rather than something that we have to do. Companies will be prepared to pay a premium for it just like with insurance.
Corporates need to be asking their financial institutions questions and financial institutions need to be asking other financial institutions that they deal with BCP questions.
A. Just don’t assume you have access to assets just because you have a contract with a financial institution. In a deep liquidity crisis people don’t honour or have to honour lines of credit. Treasurers in my experience do not look at this – they assume that those lines of credit are always good. I think it is really important for corporations to look at the fact that these banks give them access to money through a network and if these banks don’t have access to that network they can’t give them the money. This is why diversification is so important for companies – don’t keep all your money in one place.
If there is no market demand for business continuity from banks then that is really the corporate treasurers’ fault. If they don’t think they need these kinds of protections and are willing to pay a small premium for them then they have made a business decision, and that’s OK, but at least they are going in with their eyes open. Corporate treasurers should be asking not only to see the BCP plan but to see the result of the test of those plans.
Cost savings from the trend towards creating shared service centres or centralising treasury can increase your risk to BCP problems. Business continuity is something that needs to be considered when thinking about your treasury’s strategy – when your company is thinking about developing a more centralized approach to treasury, or developing a shared service centre you need to consider that these centralized structures can increase your risk to BCP problems. But there is no magic formula on business continuity: there are no right and wrong answers. It really depends on the individual organisation and knowing what the company’s risk appetite is. It’s about understanding what your risk is – both internally and from your vendors – understanding what you are willing to pay to mitigate that risk and then understanding what the best way to spend that money is in order to reduce your risk.
If I was a CEO of a company I would like to ask my CFO and treasurer how sure they were that the people they are relying on to provide my company’s business continuity services are really going to be able to deliver them in a crisis.