Business Continuity and Cyber Incident Plan
v2.3
Purpose. This plan sets out how the firm keeps serving clients and meeting lodgement and payroll deadlines during a disruption, and how it responds to a cyber incident affecting client information or systems.
1.Critical services and deadlines
The firm's critical services are payroll runs, superannuation payments, activity statement and tax lodgements, loan settlements and insurance renewals and claims. Each has a deadline that does not move because the firm is disrupted. The plan identifies the staff, systems and data needed for each and the maximum tolerable outage, which is one business day for payroll and settlements and three business days for other services.
2.Scenarios
The plan covers loss of an office, loss of internet or power, unavailability of a cloud platform, ransomware or account compromise, loss of key staff and a pandemic or public health restriction. Each scenario has a response card with the first ten actions, who leads and who is contacted.
- Office unavailable
- Cloud platform outage
- Ransomware or account compromise
- Business email compromise and payment redirection
- Loss of key staff
- Public health restriction
3.Cyber incident response
A suspected cyber incident must be reported to the Compliance Manager immediately. The incident lead will isolate affected accounts and devices, reset credentials, preserve logs and engage the firm's IT provider and cyber insurer. No ransom will be paid without Managing Director and insurer approval. Client information affected must be assessed under the Privacy and Information Security Policy for notification.
4.Payment redirection fraud
Because the firm handles bank details for clients and their suppliers, any request to change a bank account must be verified by phone on a known number before it is acted on. Where a fraudulent payment is suspected the firm will contact the bank immediately to attempt recall and will notify the client and the cyber insurer.
5.Working from alternative locations
Staff can work from any of the three offices or from home using the firm's managed devices and multi-factor authentication. Parramatta work will move to Geelong and Brisbane in a prolonged outage. Paper files must not be taken home.
6.Communication
The Managing Director will decide what clients, regulators, lenders and insurers are told and when. Clients with deadlines in the disruption period will be contacted first. Regulators will be notified where a licence obligation or a reportable breach is affected.
7.Testing and review
The plan will be tested by a desktop exercise every six months and a restore test of backups every quarter. Outcomes will be recorded and the plan updated within 30 days.