Learning from Hurricanes Harvey and Irma

What disaster recovery readiness means for accountants.

By Donny C. Shimamoto

Think back just a short while ago when you first found out that Hurricane Harvey was poised to hit Texas. Or when you first heard Irma was about to hit Florida.

MORE: Focus on Cyber Risk, Not Just Security | Making IT Matter to Accountants | IT Nerds Need Budget Help | 8 Ways to Wrestle Software Subscriptions Into Submission | IT Hardware Gets Even More Complex (Great!) | How Accounting Geeks and Techie Nerds Can Play Nicely Together
GoProCPA.comExclusively for PRO Members. Log in here or upgrade to PRO today.

If a hurricane or other natural disaster were coming to your town would you know what to do to ensure that the damage and impact to your IT environment was prevented or minimized?

Do you know how to bring all your systems back up once the threat has passed? If something happened to your office, is your data backed up somewhere offsite? How quickly would you be able to get replacement equipment in place so that you can get operations running again? Do your employees know how restart operations without access to the computer systems?

Disaster Risk Increasing

The frequency of natural disasters seems to be increasing each year, and our reliance upon computer systems to run our businesses has been increasing every year too. This combination means that we are at greater risk of a natural disaster interrupting our businesses and the potential impact when that disaster occurs is even greater than before. More than 40 percent of businesses never reopen after a disaster, and for those that do, only 29 percent were still operating after two years (source: FEMA via Forbes). Will your business be one of those casualties?

Disaster recovery plans are much like a traditional fire drill and evacuation plan. Someone has to think through what has to happen, people need to be informed what to do, and you need to practice doing it at least once a year. Just as doing fire drills can help save human lives, disaster recovery drills can help save your business. Disaster recovery plans have two major components: disaster preparedness and business recovery.

Implement Preventive Measures to Reduce Impact

Disaster preparedness is having thought through the possible threats in the event of a disaster and developed plans to prevent or minimize damage. For example, if flooding were to occur, is all of your equipment raised off the floor so that the water doesn’t damage it?

Some of you may be thinking that your office is above the first floor so the risk of that is low. Well, how about flooding caused by a water pipe bursting on an upper floor, or flooding caused by the water sprinklers being triggered because of a fire in the building? These may not be major water events, but they can cause pooling and depending on how much water there is and how well the area drains, a significant pool of water may develop in your office. So you could take preventive steps to elevate your equipment above potential water pools and ensure that there isn’t anything on the floor that would deter drainage.

Address Business Processes for Recovery

Business recovery is having thought through what it would take to resume operations if the various threats materialized and how you would deal with the varying levels of damage they could cause. Some of the key questions to consider are:

  • Are you able to operate manually (i.e., without your systems back up and running.)?
  • If the answer is no:
    • Do you have detailed procedures ready to get your systems back up and running?
    • If equipment was damaged, how quickly and from where would you get replacements?
    • Is it possible to leverage cloud infrastructure solutions to get yourself back up and running faster?
    • If the office itself was damaged or inaccessible, do you have your data backed up somewhere offsite?
  • Are you reliant upon an IT server provider to get your systems running again?
    • If yes, where are you in the priority list compared to all the rest of their customers?
    • Have you discussed business resumption and system priorities with them so that they know which systems are mission-critical so should be brought back up first?

This list is just a starting point for developing your business recovery plan. Some of these questions also feed back into the disaster preparedness area. For example, if you can’t operate without your systems, then you should have a warm or hot site available so that you can resume operations with a minimal amount of downtime.

If you are able to operate manually, another thing to consider is how will you get all those manual transactions recorded in your systems once they are back up? Will someone have to do data entry? Can you do batch posting? This is particularly important if any of your planning or forecasting processes are based on prior year metrics.

And what controls have you built into your manual procedures to ensure that employees aren’t able to commit fraud and to help prevent manual errors? Automated controls are great, because the system enforces them, but when the system isn’t there, how has your risk posture changed? What is the risk that someone will take advantage of the control deficiencies?

Do You Need Business Interruption Insurance?

Lastly, you can also transfer some of this risk and purchase business interruption insurance to cover the loss of revenue. In this case, what you want to ensure that you are able to do is quantify the amount of revenue that was lost. Check your policy to see whether it dictates how lost revenue will be computed. If it doesn’t, ask your insurance agent. In the event of a catastrophic loss where your systems are destroyed, do you have the data available somewhere else to be able to quantify your claim?

Being Prepared for Both Disaster and Recovery is Key

Disasters like Harvey and Irma seem to be occurring more frequently. It is important for every business owner to protect their business by proactively taking measures to minimize the impact from the disaster and enable the quick resumption of business activities.

Accountants and finance managers should also ensure that they are prepared to get the information needed from manual procedures back into financial systems, and in the worst-case scenario of a catastrophic loss, to be able to substantiate the business interruption insurance claim. Being prepared will help to ensure that your business doesn’t become one of the casualties of the disaster too.