FACTS
Summary of iPremier
• Founded in 1996 by students at Swathmore college
• One of a few web-commerce success stories • Sells luxury, rare, and vintage goods online
INTERNET RELIABILITY IS CRITICAL!!
• Fiscal Year 2006
• Profits were $2.1 million
• Sales of $32 million
QData
• Steady provider of:
• basic floor space
• power
• connectivity
• environmental control
• physical security and
• high-level “management services”
• Hosted most of iPremier’s computer equipment
• “Colo”
• QData’s hosting facility close to office
• Network Operations Center (NOC)
• Secured Monitoring Location
• Qdata had not been quick to invest in advanced technology and had been experienced difficulty in retaining staff
PEOPLE
BOB Turley- CIO
Joanne Ripley – technical operations team lead
Wanda Spangler – VP business developments
Leon Ledbetter – Ops
Jack Samuelson – CEO
Tim Mandel – CTO
Peter Stwart – legal counsel
• 4:31 AM: Leon Ledbetter reports the website is locked up, customer support is receiving calls and support has been getting
“ha” emails.
• 5:27 AM: Joanne Ripley realized shortly after she reached a Qdata console that iPremier was the recipient of a SYN flood from multiple sites that was directed at the router that runs the firewall.
• “Ha” emails received every second iPremier’s Choices
• At the time of the attack, pull the plug?
• Could lose logging data
• Only way to assure credit card data is not being stolen
• After the attack: rebuild the system? • Would shut down business for, at a minimum, 24-36 hours
• “The only way to be sure”
Ending The Attack
Every time Joanne tried to shut off the attacking IP address it would automatically trigger attack from two other “zombie” sites The emails stopped at 5:46 AM
Aftermath actions iPremier instituted several security measures after the DoS attack:
• Restarted all production equipment
• File-by-file examination
• Plan to move to more modern hosting facility • Created an incident-response team
Backup and redundancy planning and testing / disaster recovery
• Encrypt critical customer data
Updated Virus signature files and security patches
• Actively monitor for future attacks
Develop a business continuity plan (test it end to end including suppliers and keep it updated)
Hire an independent audit team who report into the board/ security audit
A risk management program should identify, analyze, evaluate, treat, monitor and communicate the impact of risk on IT processes.
The IT risk framework also has three major domains- risk governance, risk evaluation and risk response.
Develop an IT governance framework
• Unclear of who is in charge of decision making
• Bad relationship with colocation facility
• Poor firewall to prevent intrusion
• No formal internal emergency plan
• Limited information as to what transpired
In computing, a denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a machine or network resource unavailable to its intended users.
CONCERNS FOR THE COMPANY
Busy growing and protecting its profits and delivering new features to benefit customers
The cost of more modern facilities was considerably higher, two to three times as expensive on a per square foot basis
Move might risk service interruption
Felt personal commitment to Qdata
PROBLEM IS POOR PLANNING ON THE COMPANIES BEHALF
BUSINESS CONTINUITY PLAN
Business continuity planning (BCP) "identifies an organization's exposure to internal and external threats and synthesizes hard and soft assets to provide effective prevention and recovery for the organization, while maintaining competitive advantage and value system integrity
Risk management
Creating a business continuity plan
A BCP typically includes five sections:
1. BCP Governance
2. Business Impact Analysis (BIA)
3. Plans, measures, and arrangements for business continuity
4. Readiness
Related Documents: Winning: Business Continuity Planning Essay
myself. Precise: Many of the techniques of e-business strategy have become a very important aspect of their long-term success in the market and competitive organization. According to CioIndex (2008), based on an e-strategy to create shareholder value. Other word, the "new" world competition "new" business model helps to identify now with Internet-based ecosystem. This report emphasizes the importance of today's changing business e-strategy, browse companies to adapt to modern e-commerce…
Strategic Plan Update Amy Chin STR/581 October 25, 2010 Charlotte F Strategic Plan Update—Final Version Executive summary Kudler fine foods is a premium food retailer whose business is primarily based on sales of bakery, meat, seafood, produce, dairy, and wine. It has ambitious plans but the tightening economy threatens its quality proposition and further expansion. A strategic focus on Kudler fine foods is to improve the level of convenience offered to customers. This strategy would…
Innovation for Film and TV Production1 Chun Ouyang Kenneth Wang Arthur ter Hofstede Marcello La Rosa Michael Rosemann Business Process Management Group Queensland University of Technology Brisbane, Australia Katherine Shortland David Court Australian Film, Television and Radio School Sydney, Australia Abstract: Film and TV productions, a key area in production screen business, comprise of processes with high demand for creativity and flexibility. However, despite the era of fast developing…
HENLEY BUSINESS SCHOOL UNIVERSITY OF READING MANAGING PEOPLE AND PERFORMANCE ASSIGNMENT • Identify, with justification, a critical issue relating to people that impacts effective performance within the organisation. • Based on your analysis, develop your recommendations and an outline plan to address the issue to improve organisational performance with clear justification for your proposed approach. • Identify the benefits and risks…
Espresso, located in the CBD of Parramatta, offers high quality Campos coffee to those in the local area. With thorough research previously conducted, XS Espresso specifically attracts publics who are coffee drinkers in the local area, commuters, business people and young adults aged 18-24. XS Espresso has been having difficulties attracting a large amount of consumers and promoting brand awareness due to the fact that it has only been recently established. However, by addressing their opportunity…
(VCA). We stand ready to assist VCA create a unified message about the importance of the agency to key stakeholders like government officials, various chambers of commerce, key stakeholders, and of course, the general public. Imprenta is an award-winning marketing, public relations and communications firm with specific experience in the travel and tourism industry. Imprenta has worked with Visit California and served as industry relations liaisons for Los Angeles and Southern California districts…
1. EXECUTIVE SUMMARY J Sainsbury plc is a UK based company, into grocery, related retailing an financial services business. The study is primarily to do financial assessment of this company and its performance relative to its peers and industry. Seeing the last 5 years report, it is evident that company was in a bad share 3 years ago, and now its in the stage of recovery. Starting 2004, there has been a major change in the board, as well as management. Since then company has taken several large…
B203 Business Functions in Context – Revision Notes Introduction * Communities of Practice (Wenger, 2007) - are groups of people the come together to share knowledge and experiences and learn from one another whilst providing a social context for that work. Three characteristics are crucial: 1. The Domain - It has an identity defined by a shared domain of interest. Membership implies a commitment to this and therefore a shared competence that distinguishes members from other people…
Scenario The San Juan Cell Phones Scenario Summary talk about this company that manufacture cell phones where Maria Perez, a business development specialist, secured an order of 100,000 units with this major chain, which is an opportunity to the company to increase their production and their profit. Cell phones are very important to the community these days for business, to keep in touch with the family or just to feel independent and secure. The first cell phone was created in 1973 by Martin Cooper…