A Decontamination Game Changer

Last week, the way we remove chemical contamination from victims of a terror attack or chemical accident has changed… well, not quite yet, but it should soon.  A partnership between the US Department of Health and Human Services’ (HHS) Office of the Assistant Secretary for Preparedness and Response (ASPR) and the University of Hertfordshire in England and Public Health England found that “…removing clothes removes up to 90 percent of chemical contamination and wiping exposed skin with a paper towel or wipe removes another nine percent of chemical contamination.  After disrobing and wiping with a dry cloth, showering and drying off with a towel or cloth provides additional decontamination, bringing contamination levels down 99.9 percent.”

100_2534

Essentially, what they discovered was that despite recommendations for doing so, victims have often not been required to disrobe for decontamination.  When victims would progress through a decontamination (water spray down), much of the chemical they have been exposed to remains in the clothing and trapped against the skin.  Clearly this is not effective.

I see this new methodology being a significant change to how we decontaminate victims.  As the study hypothesizes, decontamination is much more effective when the chemical is wiped from the body after the victim disrobes.  Following this, they may progress then through a water spray.  This, essentially, adds a step to the typical protocols used in North America, Europe, and other locations.  I’m told the wipe methodology has been used in Japan for some time now.  I also believe that wipes have been in use by the US (and other) military forces for units in the field.

Links of interest:

HHS Press Release on the study.

Implementation of new protocols in the UK and other European nations

Many thanks to my colleague Matt for passing this information on to me.

As with any new procedure, the devil is in the details.  Standards must be established and adopted, supplies and equipment must be identified and obtained, personnel must be trained, and exercises must be conducted to validate.

I’m interested to hear opinions on these findings and recommendations, as well as thoughts on implementation in the US and abroad.

© 2016 – Timothy Riecker, CEDP

Emergency Preparedness Solutions, LLC Your Partner in Preparedness

 

Battling Wild Fires and Perspectives

Hello readers!  Apologies for my absence over the past couple of weeks.  I’m grateful, especially as a founder and company partner, that we’ve been so busy as of late.  The design, conduct, and evaluation of a couple of great exercises for one client; the design of several impactful training courses for another; along with preparations for two new contracts have had our small business buzzing with activity.  We will be recruiting a lot of people for one of those contracts, so stay posted on the blog (www.triecker.wordpress.com), my LinkedIn profile, and both my personal (@triecker) and our company (@epsllc) Twitter accounts, as well as the company website (www.epsllc.biz) for more info.

Although I’ve not been blogging for the last couple of weeks, I’ve still been keeping up on current events.  The wildfire in Fort McMurray, Alberta, Canada has been consistently one of the biggest stories as the fires still continue to spread, having caused massive devastation to property and the environment, and having displaced around 100,000 people.  Hundreds of vehicles were abandoned during evacuations, either due to mechanical trouble or lack of fuel.  The Canadian Red Cross, partnering with federal and provincial governments, is providing tens of millions of dollars in direct aid to impacted individuals and families.  Thousands of workers are being evacuated from the oil sands area north of the Fort McMurray, stalling more than a million barrels of production each day.  Firefighters, law enforcement, military personnel, and other resources are battling dry conditions, high temperatures, and winds in this massive and constantly shifting fire.  Other provincial and local governments and even citizens are helping to shelter and care for evacuees, many of which have lost much of their property.

One thing I often find interesting is the difference between perspectives, especially between public safety and citizens.  While our focus in public safety is… well… to make sure the public is safe, we always have to keep tabs on perception.  Take the seemingly conflicting reports of these two articles, for example.  The first article, published Thursday May 5, tells the story of residents evacuated from an area who are questioning the organization of response efforts and general preparedness of officials.  One individual tells of no police officers to guide evacuees out of town.  The second article, published on Saturday May 7 tells of military and police overseeing evacuations across the incident.  I believe I read these two articles back to back, causing the dichotomy of the two to really jump out at me.

Truth, of course, likely lies in both articles.  Yes, thousands of public safety and military personnel are involved and doing what they can.  Some evacuation orders, as indicated in the first article, are sudden, based upon rapidly changing factors, giving public safety little time to mobilize to the new area.  There must also be a consideration that evacuation orders may have been issued without proper coordination of resources.  Any of these things are possibilities, especially in the fast moving environment of wild fires.  Still, they provide opportunities for us to learn and improve.  Not knowing the details of what may or may not have transpired, I am always reluctant to speculate.  As with all incidents, events, and exercises, however, once the work is done, we have an excellent opportunity to review and evaluate information in a collaborative manner to identify strengths and areas for improvement.  Organizing these notes creates a corrective action plan, the implementation of which will, over time, make us better at what we do.

© 2016 – Timothy Riecker

Several New CyberSecurity Efforts in the News

Over the past few days, there have been media releases about several new cybersecurity initiatives that should have broad reaching benefits.

Timothy Riecker

First, Govtech.com reported on New Jersey’s consolidated fusion center-style approach to cybersecurity.  About a year ago, the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) was formulated, following the model of the National Cybersecurity Communications Integration Cell (NCCIC).  Co-located with the NJ State Emergency Operations Center and with support from the NJ Office of Homeland Security and Preparedness intelligence resources, the NJCCIC is keeping a watchful eye on cybersecurity matters internal and external to state government and sharing information with the private sector. This is a model effort that will hopefully grow and change based on identified opportunities in both New Jersey as well as other states who have yet to build such a capability.

EDM Digest recently reported on an initiative from the National Governor’s Association to form a multi-state working group, or academy as they are calling it, to create strategies to fight the evolving cybersecurity threat.  States contributing to this effort include Connecticut, Illinois, Louisiana, Nevada, and Oregon.  While not states we would usually think of as being on the forefront of cybersecurity issues, each does have significant business and industry which will hopefully serve as partners and resources in this endeavor.

Lastly, US Representatives Richard Hanna (R-NY) (who represents my district) and Derek Kilmer (D-WA) introduced the Small Business Cybersecurity Act to help American entrepreneurs protect themselves from cybercrimes and create cybersecurity plans that meet their business’ needs.  Co-sponsors of the bill included a range of Representatives of both parties from across the nation.  The release states that three out of every five cyberattacks target small businesses, and with small businesses making up a significant portion of the US economy, it is vital to help protect them.  I couldn’t agree more!  The intent of the bill is to create no-cost legislation to leverage the expertise of Small Business Development Centers (SBDCs) around the nation as an information distribution point for cybersecurity preparedness.  Let’s hope this one passes!  Express support for the bill to your Congressional Representative!

All in all, it’s encouraging to see continued effort toward cybersecurity protection, preparedness, and response.  As with the preparedness efforts we see in emergency management, I hope soon these efforts in cybersecurity will become more unified and closely knit.  While they all technically fall under the President’s Cybersecurity Strategy, we need to ensure connectivity of these efforts to help prevent duplication of effort and minimize holes.  We also want to ensure that access to services and resources that are available are comprehensive and streamlined to the greatest extent.  Let’s keep cybersecurity in mind and continue this work!

© 2016 – Timothy Riecker, CEDP

DOT Releases New Emergency Response Guidebook

PHMSA 05-16
Tuesday, April 26, 2016
Contact:  Artealia Gilliard
Tel.: 202-366-4831

DOT Releases New Emergency Response Guidebook

2016 ERG Cover

More Than 1.5 Million Free Copies to First Responders Nationwide

WASHINGTON – The U.S. Department of Transportation’s (USDOT) Pipeline and Hazardous Materials Safety Administration (PHMSA) today released the 2016 Emergency Response Guidebook (ERG2016), providing first responders with an updated go-to manual to help respond to hazardous materials transportation accidents during the critical first minutes.

PHMSA will distribute more than 1.5 million free copies of the guidebook to firefighters, emergency medical technicians and law enforcement officers across the nation.  Emergency first responders will use the ERG2016 to identify specific risks associated with compromised hazardous materials, and the recommended safety measures and procedures they should take to protect themselves and contain the incident as quickly as possible.

“We take the safety of this nation and its emergency responders very seriously,” said U.S. Transportation Secretary Anthony Foxx. “Our goal is to make sure that these first responders have the most current and accurate safety guidelines possible for use during that initial phase of a hazmat incident.”

The ERG contains an indexed list of dangerous goods and the associated 4-digit United Nations identification numbers. The ERG also identifies the general hazards those dangerous goods pose and  recommends safety precautions in remediating a hazmat incident. For example, if emergency first responders arrive at the scene of an overturned tractor trailer displaying a USDOT hazardous material placard, they would use the guidebook to identify the material associated with the placard and how best to respond.

“The ERG is an invaluable tool during the initial stages of any hazmat transportation emergency. Taking the proper action during those critical first minutes impacts the safety of both the first responders and the people they serve,” said PHMSA Administrator Marie Therese Dominguez.

The 2016 version of the ERG includes general revisions, expanded sections and added guide pages for absorbed gases. Updated every four years as a collaborative effort of the USDOT, Transport Canada and Mexico’s Secretariat of Transport and Communications, the ERG2016 is available free to public safety agencies in all states, territories and Native American Tribes through designated state emergency management coordinators’ offices.

PHMSA has also partnered with the National Library of Medicine (NLM) to provide a free Smartphone version of the ERG2016.  NLM also develops and distributes the Wireless Information System for Emergency Responders. The mobile application will be available this spring.

A copy of the new ERG2016 is posted online at: http://phmsa.dot.gov/hazmat/outreach-training/ergPrint copies of ERG2016 are available for sale to the general public through the U.S. Government Printing Office Bookstore athttp://bookstore.gpo.gov and other commercial suppliers.

The mission of the Pipeline and Hazardous Materials Safety Administration is to protect people and the environment by advancing the safe transportation of energy and other hazardous materials that are essential to our daily lives.  PHMSA develops and enforces regulations for the safe operation of the nation’s 2.6 million mile pipeline transportation system and the nearly 1 million daily shipments of hazardous materials by land, sea, and air. Please visit http://phmsa.dot.gov or https://twitter.com/PHMSA_DOT for more information.

Exercising the Recovery Mission Area

It doesn’t happen often, but when it does, I get pretty excited about it – I got a blog request!  Last week, Darin, a LinkedIn connection, messaged me with a request to post my thoughts on exercising the recovery phase (or mission area) of emergency management.  His idea, as he expressed it to me, came from discussion at a Public Health Preparedness conference he was attending, where they were discussing ESF 8 (Public Health and Medical Services) continuity of operations and recovery exercises.  Challenge accepted!

When it comes to Recovery exercises, my first thought is that they are horribly underutilized.  We conduct a lot of exercises in the Response mission area, but it’s a rare occasion that we even mention Recovery.  The reasoning here is pretty easy – Response is sexy.  It’s the lights and sirens, saving lives, put out the fire, pull people from the wreckage kind of stuff that makes a big impact.  Recovery is often viewed as slow, tedious, bureaucratic, engineering kind of stuff.  Well… yeah… but there is a lot more to it.  Since when we plan exercises, one of the first things we do is to identify what Core Capabilities will be tested, let’s look at the Core Capabilities of the Recovery Mission Area.  Within each, I’ll mention some ideas you can incorporate into exercises.

The Big Three – Planning, Operational Coordination, and Public Information and Warning.  These Core Capabilities are found in every mission area and are sometimes applied differently.

  • Planning – Yeah, we should have recovery plans. I would argue that we have entered the recovery phase when all or most of the first two incident management priorities have been addressed – Life Safety and Incident Stabilization.  Sometimes these are resolved quickly, sometimes they take some time.  There are some fairly complex issues to be addressed in the recovery phase (many of which we will identify through the Core Capabilities), and we don’t do them often, therefore we should most certainly plan for them.  Remember, we exercise plans and capabilities – therefore our plans (and policies and procedures) are a significant focus when it comes to Recovery exercises.    This Core Capability is where continuity of operations plans will also fall.  Can your organization survive the lasting impacts of a disaster?
  • Operational Coordination – Recovery activities often involve organizations that had little to no activity during the Response phase. Most of these organizations are non-traditional responders who don’t usually operate under more strict command and control models, such as ICS, but in the Recovery phase of a disaster, I certainly advocate that they do.  Many of these agencies, typically the human services types of organizations, are very good at coordination and cooperation, as their daily priorities dictate that working with others is how needs are addressed.  The big challenge we often see here, though, is the introduction of some other organizations – typically those with regulatory responsibilities.  Regulation usually requires bureaucracy.  Bureaucracy usually requires time – lots of time – especially when exceptions are requested.  It’s really important to consider all stakeholders when planning an exercise to ensure that you get a chance to see how they interact, what the information flow and chain of authority looks like, what benefits they bring, and how they can work together in a timely fashion for the common good.
  • Public Information and Warning – We often take for granted the role of public information and warning in the Recovery phase. There are many benefits to keeping external stakeholders informed of what’s going on during Recovery.  Consider elected officials, business and industry, and special interest groups, along with the general public.  Your PIO and possibly your JIC should be just as involved in Recovery phase exercises as they are in those for the Response phase.

Aside from the ‘big three’, the Recovery mission area shares a Core Capability with the Response mission area – Infrastructure Systems.  Long-term restoration and rebuilding of infrastructure can lead to lengthy discussions in a Recovery-focused workshop or tabletop exercise.  What are the priorities for rebuilding?  Who will do it?  How will it be funded?  What are the completion timelines?  Will it be rebuilt the same or differently?  What are the impacts of doing it differently?  Who is impacted by this?  What do we do while we are waiting for it to be rebuilt?  Who makes decisions?  All important things to consider.

The first unique Core Capability in the Recovery mission area is Economic Recovery.  I was recently asked to present at a conference for a niche professional association comprised of professionals found in government, private sector, and non-profits.  While we will be covering topics in Hazard Mitigation and Preparedness, the biggest focus will fall within Economic Recovery.  Economic Recovery involves businesses reopening and people getting back to work to serve customers, make money, and become customers themselves.  After a disaster, it is absolutely vital for a community to get back on its feet, and the center of that is the local economy.  While many disaster impacts may be a relative drop in the bucket for larger companies, smaller businesses may have a hard time recovering – the central pieces of this are infrastructure restoration (see previous paragraph) and cash flow.  The SBA, USDA, and even IRS have mechanisms to assist with cash flow issues.  And don’t forget insurance!  Bring these and other stakeholders to the table to discuss economic recovery.  Consider priorities and mechanisms that must be in place to meet needs to support these priorities.  Your local chamber of commerce and other business associations will certainly want to be part of these exercises.  Does your jurisdiction have a business operations center (BOC)?  If not, consider it.  If you do, exercise it!

Health and Social Services.  This is the heart of all matters related to ESF 8 (Public Health and Medical Services), which Darin mentioned.  While this Core Capability is an extension of the Response mission area Core Capability of Public Health, Healthcare, and Emergency Medical Services; it is also so much more.  ESF 8 activity after disasters can last months or even years, particularly with ongoing issues such as medical monitoring and psychological impacts.  Eventually many of these services are absorbed into the system of regular service providers, but for a time the circumstances of the disaster may require some special coordination or monitoring.  The coordination needed involves an amalgamation of organizations at all levels of government, not for profits, and the private sector.  This can involve ongoing coordination with insurance companies, general practitioners and specialists; and must address the needs of everyone fairly and consistently, regardless of any differences, including their own financial resources or insurance coverage.  Tracking data related to the care and services provided is often important, but consideration must be given to HIPAA and other privacy laws.  Exercises can benefit from scenarios, such as exposures to radiological, biological, or chemical sources, which will drive discussion on the types of services to be provided, who will provide them, at whose cost, and for how long.  Many of these discussions should include topics of how to avoid social stigmatization of clients, sharing information between organizations, and the full range of social services that individuals and families may require.

Housing is typically the hardest nut to crack in all of disaster recovery.  Relative to need, there is little government owned housing stock available.  What is available may require waiting lists and relocation to access.  While many home owners are insured, we know that it takes some time for home owners to receive payment from insurance companies, and insurance is rarely at 100% coverage for losses.  Those that don’t own their own homes are often the left with the most dire situations.  While ‘FEMA trailers’ have provided some medium-term solutions, there are many issues to address.  I posit that plans at all levels are inadequate to address housing needs after a disaster.  If you have a plan, get a good exercise team to write a great scenario to test it.  If you don’t have a plan, conducting a workshop to identify and address major planning issues is the way to go.  A housing exercise is probably going to be one of the more eye opening yet depressing exercises you’ve ever done.

Lastly is the Core Capability of Natural and Cultural Resources, which focuses on the recovery of libraries and museums, documents and art, as well as helping to restore our own environment after a disaster.  Activities can range from restoring a historical landmark to major engineering projects to restore a wetland.  These activities can involve a great deal of technical expertise as well as regulation.  FEMA, the EPA, and the National Parks Service are often big players in these types of activities.

As for what types of exercises to conduct, that’s largely dependent upon the status of your plans and if you have conducted exercises on these plans before.  I always suggest starting with discussion-based exercises.  We often forget about seminars, which are more about conveying information than obtaining feedback, but are still valuable for discussing initiatives and new plans.  Workshops not only support the planning process to develop plans, they can also serve to facilitate a detailed review of a plan in its final draft stages.  Most Recovery exercises I have experience with have been tabletop exercises, which use a scenario to provide context to discussion questions for a group of stakeholders.  This is a great way to exercise decision making and to talk through the key tasks associated with plans.  Disaster recovery involves a lot of policy-level decision making, which is ideal for a tabletop.

Operations-based exercises for disaster recovery are found much less often.  Drills can certainly be conducted to test focused aspects of plans and procedures.  Drills in Recovery can help identify strengths and weaknesses of our processes, both for ourselves and for those we are trying to serve.  Functional exercises are broader and more encompassing than drills.  Much can be gained from a Recovery mission area functional exercise, but make sure that it’s grounded in reality.  Most jurisdictions don’t have an EOC activated for Recovery mission area activities. If you don’t, don’t try to run an exercise within that environment.  Some functions, however, may be run, at least for a time, from some sort of operations/coordination center, such as a health operations center (HOC).  With a good scenario focusing on addressing longer-term issues in the aftermath of a response, they can be done successfully.  Be sure to develop a pretty solid ‘ground truth’, however, to support the exercise, as much of Recovery is dependent upon what was done in Response, so players will need this context.  With a bit more complication, a functional exercise could be run virtually, with people participating from their own regular work stations as they often do during Recovery operations.  Testing Recovery plans in full scale exercises is significantly challenging based on the array and type of activities.  Because of the focus of activities, continuity of operations plans are likely among the most suited for full scale Recovery mission area exercises.

I’m curious to hear about your experiences exercising Recovery mission area plans and capabilities.  What ideas do you have?  What best practices have you found?

As always, thanks for reading!

© 2016 – Timothy Riecker, CEDP

Emergency Preparedness Solutions, LLC – Your Partner in Preparedness!

“No Battle Plan Survives Contact With the Enemy”

This quote is credited to a German military strategist named Helmuth von Moltke, who served in several wars in the mid-1800s.  He had a certain theory of war, understanding that several strategies must be identified in planning, as it is difficult to ascertain exactly what will happen after first contact with the enemy.  What can we in emergency management learn from this?

First off, we should all recognize that it’s a rare occasion that anything goes according to plan.  That is a reality which we must identify as a foundation of our planning efforts.  These realities are part of our planning assumptions.  In essence, we simply don’t know exactly what will happen, when it will happen, where it will happen, or what the impacts will be.  We also can never be completely certain about the resources we will have available to us to respond.

Based on these planning assumptions, we should not count on our plans working from the moment an incident occurs.  Very simply, there is always some catch up that we need to account for.  Most importantly, we need to gain situational awareness to determine the scope and magnitude of the incident.  Once we have a reasonable degree of situational awareness (often we never know everything we would like to), we can start making decisions as to how we will respond.  These decisions should be guided by our plans.

Our initial response – what we do when we first run in approach, assess, and begin our initial life saving measures – may not have a solid plan, but the foundation of it does follow a certain algorithm.  Many disciplines, especially the traditional first response ones, often underscore the importance of a scene size up.  While this varies a bit based on our respective disciplines and the nature of the incident, the common themes involve seeking answers to the usual questions – who, what, where, when, why, and how.  As we begin to gain answers and process this information, we request and assign resources.  Our initial response is often unorganized.  We don’t know all there is to know about the incident.  We don’t have all of our resources readily available.  Mentally we are overwhelmed with information, trying to process everything quickly.  Eventually, though, we should begin to transition into our planned response, bringing order to the chaos.

While emergency and incident management isn’t war, there are certainly a number of parallels that can be drawn.  While von Moltke’s statement is often cited in our profession, devaluing the plans we create, I think the perspective of those who cite it is wrong.  We should not intend for our plans to be implemented immediately upon occurrence of an incident.  Rather than sticking a square peg into a round hole by trying to immediately apply our plans, our initial response should deliberately guide us to our planned response.

One of the chief elements of our plans is our organization – the incident command system (ICS) or incident management system (IMS).  Our ability to properly implement our plans is predicated on our ability to manage.  In a complex incident, one person cannot handle all the elements and tasks.  Delegation is necessary and ICS/IMS is the organizational model we should be following.  It is through our incident management organization that we manage resources, hopefully in accordance with a plan, which helps us to manage the incident.  The transition to managing the incident instead of responding to the incident can be a difficult one to make, especially for those not experienced with larger incidents.  Much time can be wasted resisting or struggling through this transition.  The transition, however, is a conscious and deliberate effort.  It won’t happen automatically.  It must be managed.

I’ve referenced in previous blog posts Cynthia Renaud’s paper “The Missing Piece of NIMS: Teaching Incident Commanders How to Function on the Edge of Chaos’.  Much of what I’m talking about in terms of managing our ICS/IMS through the transition of initial response into our planned response has also been cited by Chief Renaud.  The bottom line is that we can do better in our core ICS/IMS training to aid our incident managers in making this happen.  Much ICS training seems to have dropped the essential concept of scene size up/assessment, or simply glosses over it.  How can you make decisions about how to manage the incident if you don’t know what’s going on?  It’s also a rare occasion that ICS training has much mention of the planned response.  The focus is on incident action planning, which is certainly needed to guide us through tactical application, but courses often fail to indicate the indispensable reference of emergency plans when identifying objectives and strategies.  This is a clear disconnect in our preparedness efforts and must be fixed.  We can do better.

If you haven’t yet heard of my crusade to improve our current state of ICS training, there are a number of articles I would direct you toward.  Check them out here.

Of course I’m always happy to hear what you think – comments are welcome!

© 2016 – Timothy Riecker, CEDP

Emergency Preparedness Solutions, LLC – Your Partner in Preparedness!

7 Emergency Management Priorities for the Next Administration

Heritage.org recently published a piece outlining the top four homeland security priorities for the next administration, which can be found here.  It’s a thought provoking article that certainly identifies some important issues.  In the same spirit, I’d like to offer what I think are the emergency management priorities for the next administration.

1) Support an Effective FEMA Organizational Model

The Heritage.org model pointed out several issues with the DHS organization that need to be addressed sooner rather than later.  I’d like to add some FEMA-specific items to their suggestions, regardless of if FEMA is kept within DHS or not (honestly, I think that ship has sailed and FEMA is there to stay).

In building a bit of background for this article, I took a look at FEMA’s current strategic plan, knowing that the document already identifies some of their priorities.  Within in that list of priorities, they mention mission and program delivery, becoming an expeditionary organization, posturing and building capability for catastrophic disasters, and strengthening their organizational foundation.  To me, these four all directly relate to their organizational model.

Along with having a strong central administration of programs, FEMA needs to have agility in their program delivery.  This is best accomplished through the FEMA regional offices, which act as an extension of the ‘central administration’ by coordinating directly with states and neighboring regions to apply those programs in the best possible manner within the guidelines of the program.  While this is currently performed, it is not performed to the greatest extent possible.  John Fass Morton provides some great perspective on this approach in his book ‘Next-Generation Homeland Security’.  Info on the book can be found here.

2) Bolster Risk Reduction Programs

I write often about preparedness, as that has always been a focus of my career.  Risk reduction, however, is essential to eliminating or reducing the impacts of hazards on communities.  Risk reduction includes all aspects of hazard mitigation and resilience, which are ideally applied at the local level but supported by state and federal programs, policies, and resources.

While the National Weather Service has implemented and promoted the StormReady program, which encourages community resilience, the best program we have ever had in our field is Project Impact.  I’d love to see a revival of Project Impact (call it that or something else – I don’t really care), incorporating the concepts of StormReady as well as other best practices in risk reduction.  A big part of this program MUST be incentivization, especially access to funds that can be applied for in the present for hazard mitigation activities.

3) Build a Better Cybersecurity Program

This item was added to the list by a colleague of mine.  It’s also found on the Heritage.org list.  It must be pretty important, then.

Yes, there are a LOT of initiatives right now involving cybersecurity, but I think there can be more.  Jon, the same colleague who suggested this for my list has also stated repeatedly that cybersecurity is really a Core Capability that cuts across all mission areas – Prevention, Protection, Response, Mitigation, and Recovery.  The recent update of the National Preparedness Goal suggests this, but sadly doesn’t commit.

What do we need in regard to cybersecurity?  First of all, we need to demystify it.  There are plenty of people out there who have just enough tech savvy to turn on their computer, send some email, and post to Facebook.  While that may work for them, they are likely intimidated by talk of cybersecurity, hackers, and the like.  We need to continue programs in plain speak that will help to inform the average consumer about how to protect themselves.

Better coordination with the private sector will pay off heavily when it comes to cybersecurity.  Not only is the private sector generally better at it, they also have a tendency to attract experts through better incentives than the government can offer, such as higher pay.  Cybersecurity also impacts everyone.  We’ve seen attacks of all types of systems.  The only way to stop a common enemy is to work together.  Let’s think of it as a virtual whole-community approach.

4) Prepare for Complex Coordinated Attack

Another of Jon’s suggestions.  While terrorism is often quickly shoved into the category of homeland security, there is a lot that emergency management can assist with.  These types of attacks (think Mumbai or Paris) have a significant impact on a community.  They require a multi-faceted approach to all mission areas – again, Prevention, Protection, Response, Mitigation, and Recovery.  While law enforcement is clearly a lead, they must be strongly supported by emergency management as part of a whole-community approach to be successful. Preparedness across all these mission areas must be defined and supported by federal programs.

5) Infrastructure Maintenance

We have roads, bridges, rail, pipes, and other infrastructure that MUST be maintained.  Maintenance (or replacement) will not only prevent failure of the infrastructure as a disaster itself, but will also make it more resilient to impacts from other disasters.  Yes, these are projects with huge price tags, but what alternative do we have?

6) Continuity of Existing Model Programs

There are few things more infuriating than a new administration wiping the slate clean of all predecessor programs to make room for their own.  While every administration is entitled to make their own mark, getting rid of what has been proven to work is not the way to do that.  Eliminating or replacing programs has a significant impact all the way down the line, from the federal program administrators, to the state program people, to the local emergency managers who are often understaffed and underfunded to begin with.

Changing gears is not as simple as using a different form tomorrow, it requires research and training on the new program and costs time to re-tool.  While I would never say there is nothing new under the emergency management sun, as I believe we are still innovating, I’m pretty skeptical of some new appointee walking into their job and making wholesale changes.  While improvements can certainly be made, summary execution of successful programs does no one any good.  Let’s not make change simply for the sake of change.

Related to this, I fully support the efforts of FEMA in the last few years to gain comprehensive input on changes to documents and doctrine through the formation of committees and public comment periods.  This approach works!

7) Pull Together Preparedness Programs

NIMS, HSEEP, NPG, THIRA, etc… While each of these programs have their own purpose and goals, more  can be done to bring them together.  I’m not suggesting a merger of programs – that would simply make a huge mess.  What I’m suggesting is to find the connections between the programs, where one leads to another or informs another, and highlight those.  Things like better application of the Core Capabilities within HSEEP exercises to have a more effective evaluation of NIMS capabilities (I suggested this while being interviewed for a GAO report), or referencing the THIRA when building a multi-year training and exercise plan.  While some jurisdictions may already do this, these are best practices that should be embraced, promoted, and indoctrinated.  These links typically don’t add work, in fact they capitalize on work already done, allowing one project/program/process to be informed or supported by another, creating efficiencies and supporting a synchronization of efforts and outcomes.

There is my list of seven.  What are your thoughts on the list?  There are certainly plenty of other ideas out there.  If you had the ear of the next President, what would you suggest be their administration’s emergency management priorities?

© 2016 – Timothy Riecker

Emergency Preparedness Solutions, LLCYour Partner in Preparedness

A New NFPA 1600

Several weeks ago (I forgot to post it!) the National Fire Protection Association (NFPA) released the 2016 update of their 1600 standard, and with a slightly different name: Standard on Disaster/Emergency Management and Business Continuity/Continuity of Operations Programs.  More on the name change in a bit.

For those not familiar with NFPA 1600, if you are in the emergency management field, you should be familiar with it.  While not legally binding (unless specifically referenced by a law or regulation), NFPA 1600 is an excellent standard for modeling an emergency management program.  Like any good standard, it provides guidance on what components you should have, but doesn’t tell you how to do it. NFPA 1600 is also very complimentary to the Emergency Management Accreditation Program (EMAP), with no conflicts between these standards – mostly because EMAP foundationally references much of NFPA 1600.  NFPA 1600 can be found here.  The NFPA provides a free download of the standard (it is heavily copyrighted, so exercise prudence in how you handle it) or you can pay to obtain paper copies.

On to the changes in this update.  As mentioned, the title has been altered a bit by adding ‘Continuity of Operations’.  While it doesn’t say so, I’m guessing that some government-types may have approached NFPA 1600 a bit skeptically thinking that it was really intended for the private sector.  The thing is, business continuity is a specific function within emergency management, but largely follows many of the same processes, just with a particular focus.

Within the standard, the early section titled ‘The Origin and Development of NFPA 1600’ summarizes the evolution of the standard, and provides some information on the changes to the 2016 update.  They mention that “The purpose of the standard has been changed to reflect the Committee’s decision to emphasize that the standard provides fundamental criteria for preparedness and that the program addresses prevention, mitigation, response, continuity, and recovery.  In other words, “preparedness” is no longer just an element of the program – it is the program.” That perspective on preparedness is a great continued evolution of the concept within emergency management.  While the standard in emergency management used to be the emergency management cycle with preparedness as one phase, that is thankfully beginning to go away (although it’s still seen out there way too much for my taste).

old em cycle

The Old Emergency Management Cycle – DON’T USE THIS ANYMORE!

The truth is preparedness permeates everything we do – all phases (or mission areas) of emergency management.  That’s why there are five mission areas identified in the National Preparedness Goal (Protection, Prevention, Response, Mitigation, and Recovery).  Where is preparedness?  It’s the root of the document (literally… it’s in the name of the document).  Preparedness is addressed for each mission area.  We must prepare to protect, prepare to prevent, prepare to respond, prepare to mitigate, and prepare to recover.

As usual, I digress…

Back to NFPA 1600.  This 2016 update includes language within “crisis management planning to include issues that threaten the reputation of and the strategic and intangible elements of the entity as a result of an event or series of events…”.  Smart move.  These elements of crisis management are something we see in both the public and private sector and certainly should be addressed.

Since business continuity does remain a focus element of the standard, they have continued to enhance those aspects.  As such, they have included information on supply chain risk and information security within the document.  When considering business continuity, we can’t just look at our own operations.  The vulnerabilities of other organizations can certainly impact us, so examining supply chain vulnerabilities is wise.  As for information security, we have seen plenty of internal and external cybersecurity issues to justify that.  Although a bit late, I’m glad the NFPA is keeping up with technology and current trends and hazards.  They have also rewritten much of the business impact analysis section (within Chapter 5) to address continuity planning and recovery planning, with a specific differentiation between the two.

Lastly, they have added Annex C, a small business preparedness guide (good move NFPA!), and have added material on addressing the needs of persons with access and functional needs, as well as adding some information on the role of social media in crisis communications plans.

These are all positive changes for the NFPA 1600 standard.  I encourage everyone who is part of an emergency management program to take a look at it and see what it has to offer.  It’s good guidance and will probably provide some good ideas for helping you grow and maintain an impactful program.

For those interested, I have a couple of past articles on standards in emergency management:

Standards in Emergency Management Programs

Business Continuity and Emergency Management Standards and Requirements

 

© 2016 – Timothy Riecker

Emergency Preparedness Solutions, LLCWe are your Partner in Preparedness!

Don’t Just Take It From Me – There are Issues with ICS Training

The February 2016 edition of the Domestic Preparedness Journal highlighted, among other things, some concerns with ICS training in the United States.  First off, if you aren’t subscribed to the DPJ, you should be.  It’s free and they offer good content, with few extraneous emails beyond the journals.  Check them out at www.domesticpreparedness.com.

The specific article in this issue I’m referencing is Incident Command System: Perishable if Not Practiced, by Stephen Grainer. Mr. Grainer is the Chief of Incident Management Systems for the Virginia Department of Fire Programs.  Steve has a significant depth in ICS and understands all the nuances of preparedness and application.  I first met him when serving on the national NIMS steering committee with him several years back.

The title of the article is a bit deceptive – it’s not just focused on the issue of the training being perishable.  Right up front, Mr. Grainer, who is a longtime supporter and advocate of ICS, outlines a few shortcomings and constraints related to the application of ICS and ICS training.  He states that “little attention has been given to developing the students’ ability to recognize an evolving situation in which more formalized implementation of the ICS should be undertaken”.  This underscores one of my main points on the failings of the ICS curriculum.  We teach people all about what ICS is, but very little of how to use it.

After giving a few case studies that reflect on the shortcomings he highlighted, Mr. Grainer expresses his support for continued training, refresher training (something not currently required), and opportunities to apply ICS in ways that public safety and emergency management don’t do on a regular basis.  He summarizes by stating that not only does training need to continue to address succession and bench depth, but also the need to address how to maintain competencies and address misunderstandings in NIMS/ICS.

Yes, training does need to continue, but it must be the RIGHT training!  We continue doing a disservice by promoting the current ICS courses which fall well short of what needs to be accomplished.  Mr. Grainer’s mention of the need for our training to address better implementation of ICS, particularly beyond the routine, is perhaps a bit understated, but nonetheless present.  Refresher training also needs to be incorporated into a new curriculum, as these skills are absolutely perishable – particularly the aspects of ICS typically reserved for more complex incidents.

In the event you aren’t familiar with my earlier posts on ICS and my crusade for a better curriculum, check out these posts.  As I’ve said before, this isn’t a pick-up kickball game… this is public safety.  We can do better.

Shameless plug:  Assessments, Planning, Training, Exercises.  Emergency Preparedness Solutions does it all.  Contact us to find out how our experience can benefit your jurisdiction’s or organization’s emergency and disaster preparedness.  We are your partner in preparedness.  www.epsllc.biz.

© 2016 – Timothy Riecker

Emergency Preparedness Solutions, LLC

FBI vs Apple – iPhone Security

The struggle over encryption and device security continues.  This time it’s more visceral, representing the most relevant case on the side of criminal justice yet.  In the wake of the San Bernardino shooting, the FBI is seeking to gain access to an iPhone discovered in the vehicle where the shooters made their last stand with law enforcement.  The FBI is hoping to find additional evidence on this phone – phone records, emails, texts, etc. that might lead them to information on other conspirators of the attack, other potential targets and attackers, and anything else that might lead to prosecuting those involved in this attack or stopping future attacks.  Gaining access to this information is obviously extremely important.

The problem – the phone is locked with a passcode, and the FBI doesn’t know what that code is. While trial and error is certainly a viable methodology, Apple’s architecture limits passwords attempts to 10.  Once the tenth attempt fails, the iPhone will go into a sort of self-destruct, wiping all data from the device.  The FBI needs help, and they are seeking it from Apple.  Apple declined requests and is now being compelled by a federal judge who ordered Apple to assist the FBI in gaining access to the phone.  Apple is fighting the order – but why?

First of all, Apple states there is no ‘back door’ into their system that will allow them to bypass a security code.  On principal, they decided not to create one since if it exists, it can be exploited.  Based upon this, the FBI has requested that Apple at least disable the 10 attempt fail safe in the iOS programming, allowing the FBI to press on with many more attempts to crack the code.  Apple continues to refuse, again citing the potential for someone with criminal intent exploiting this.  Essentially, Apple feels they are protecting their customers from criminal acts and loss of personal information.  The CEO of Google recently voiced support for Apple’s stand.

This debate poses two strong arguments, each pulling at our values.  On one side, we need to support the efforts of law enforcement to prevent, protect, and prosecute.  The evidence gathered from a situation such as this can potentially lead to finding co-conspirators in these horrible shootings, and can potentially stop other crimes from occurring.

On the other side, there is also concern over preventing future criminal activity by those who would steal information.  Keeping in mind that what we have on our phones is not only a browsing history and Disney World selfies, but also private information such as bank accounts, and even access to business information; the theft of which can be devastating to individuals and entire organizations.

There are valid arguments on both sides, and consequences to action and inaction all around, with implications much broader than this one case.  I’m interested in seeing how this shakes out.

What are your thoughts?

© 2016 – Timothy Riecker