Cybersecurity – What is the Government’s Role with Business and Industry?

The National Institute of Standards and Technology was charged by the President with the creation of a framework for improving critical infrastructure cybersecurity, which they accomplished in February of 2014.  This framework and associated documents provides information on critical steps that business and industry, working with the federal government, should take in the protection, prevention, detection, response, investigation, and recovery from a cyberattack.  The importance of this is not only the theft of private information of customers, as occurred in the hacking of Target databases, but most importantly (and the intention of the NIST document) the protection of our nation’s critical infrastructure – most of which is owned and operated by private industry.  What about state governments?  Do they have a role?

Working with various states around the nation, it has been interesting to see how they perceive their role in cybersecurity.  Some are very hands-on, while others are far too comfortable in the back seat.  State governments, it seems, are working to protect the cyber infrastructure they control (their own computer systems and data), but the position they take in respect to the private sector covers the whole spectrum of proactive to wait-and-see.  One wait-and-see-er explains their position away saying that if they don’t own the cyber infrastructure they can’t do anything to protect it.  Interestingly enough, this particular argument came from a larger state which is the recipient of higher cuts of homeland security grant program (HSGP) funds than most and has a significant amount of critical infrastructure, including several nuclear power plants.  They seem to have little interest even working with business and industry to come to common understandings, discuss threat indicators, share ideas, and talk about procedures and priorities.

On the other hand, there are states, both large and small, who see benefit to working with their business and industry to protect critical infrastructure and data interests.  While they acknowledge some challenges with the state not owning the cyberinfrastructure of these companies (nor do they want to), they see nothing but benefits in the formation of cybersecurity working groups and conducting cyber preparedness activities, particularly exercises.  This is the smart approach.

Given the number of cyberattacks that occur every day, it seems inevitable, just like any disaster, that a successful cyberattack on a critical sector of our infrastructure will certainly occur sometime in the future.  Are we prepared?  What are your states doing to prevent, protect, and prepare for such occurrences?  What are we missing?

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

WWW.EPSLLC.BIZ

News in Emergency Management

Regrettably I’ve not posted in a few weeks due to a very busy schedule.  While that hasn’t broken, I did want to take some time to ensure that my readers have seen some recent news that has been circulating in emergency management as of late.

First, the FEMA mobile app has updated and is now providing the ability for users to receive weather alerts from up to five locations across the nation.  This is a particularly handy feature for those who have family and friends in other states or those who travel frequently to different areas.  With hazardous weather season upon us, be sure that you use the FEMA mobile app or other state or local alerting service to ensure that you, your family, and organization receive alerts.

Second, DHS has provided an update on the status of the LLIS (Lessons Learned Information Sharing) Libarary.  From the release I received this morning…

Dear LLIS.gov User,

This spring, the Lessons Learned Information Sharing (LLIS) program will make a significant change. The LLIS.gov website will cease independent operations and will consolidate its content with the Naval Postgraduate School’s Homeland Security Digital Library (HSDL.org) and FEMA.gov.

One of the advantages of this move is that LLIS.gov content such as lessons learned, innovative practices, after-action reports, plans, templates, guides, and other materials will be consolidated with the already substantial database on HSDL.org. This change will allow the homeland security and emergency management communities to find relevant information in one place. FEMA’s LLIS program will continue to produce trend analyses, case studies on the use of FEMA preparedness grants, and webinars relevant to the whole community. These products will be available to the public on FEMA.gov.
They don’t give any timeframe for this migration aside from stating that they will provide updates in the coming weeks.  Personally, I think this is a move that makes sense by consolidating some great sources of information.  I’m also happy to hear that FEMA will continue providing some data and trend analysis, although I’m hopeful that the information they provide is of greater value than what I have seen in the past.  I’m also curious if this will be somehow integrated into the new Data.gov site.  It’s unfortunate that LLIS has been pulled down for so long while they have sorted all this out.

Lastly, good news for coastal communities and those who have suffered inland tropical storm damages in the last few years – the prediction for the 2015 hurricane season is that we will have lower than average activity.  A link to the annual predictive analysis can be found here.

That’s all for now.  Stay safe.

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

www.epsllc.biz 

Dispatch Transition to EOC Operations

Within the LinkedIn discussion thread of one of my recent posts on applications of ICS, I was prompted to consider that one more awkward element for an EOC operation can be the transition or integration of dispatch with the EOC.  Consider that during ‘routine’ operations, it is dispatch who is supporting field operations and tracking critical actions.  Many jurisdictions encounter a difficulty when activating an EOC locally to support a growing response – what to do with dispatch?

The EOC’s traditional role as ‘expanded dispatch’ aids a field response by providing a greater level of coordination far beyond the tools normally available to most dispatchers by facilitating direct access to agency representatives who are dedicated to supporting the needs of the incident.  Under routine operations, Command (or Logistics) is contacting dispatch directly (usually via radio) to request resources.  Upon activation of an EOC, these requests must be routed to the EOC.  In some jurisdictions, EOCs are co-located with dispatch (at least in the same building), making this transition a bit easier in regard to technology and people, but some jurisdictions have these buildings separated.

How do you solve this awkward dilemma of ICS/EOC interface?  First of all, it needs to be thought through and planned PRIOR to an incident!  This is when we can do our best work, ideally bringing all relevant stakeholders to the table, mapping out processes and procedures, and identifying equipment and technology issues needed to support it.  With everyone together, talk through what you want to do given the circumstances you have.  Each idea likely has pros and cons that have to be weighed.

Some possibilities… Keep all resource orders going through dispatch. In doing so, you are not interrupting the ‘normal’ communications link with field operations.  In this circumstance, though, you need to consider how the dispatcher will transfer the resource request to EOC Logistics.  Since you likely do not want Logistics to be accessing the PSAP system, the dispatcher will likely have to enter the request into another system, such as EOC management software (something they likely don’t use often).  This can be time consuming so it will likely require the dispatcher to be solely dedicated to this incident.  The scope of resources (or ideally missions) is also beyond what a dispatcher usually deals with (thus the reason for activating the EOC), so it would likely require some additional training and use of dispatchers with greater experience.

Another option is to bring the dispatcher into the EOC.  Sometimes physical separation, despite technology, can make things awkward.  If the jurisdiction has the technological ability to bring a dispatcher into the EOC as part of the Communications Unit, they can interact with field operations and facilitate communication better.  The need to enter the resource/mission request into a formal system which is assignable and trackable still exists.

Another option is to pull dispatch out of the incident.  This can cause significant disruption to the incident but is manageable if pre-planned, trained, and exercised.  At this point in an expanded incident the need to use radio communications beyond field operations may be exceeded.  Field Logistics can interface directly with EOC Logistics via phone or other technology to communicate resource requests.  This methodology gets the request directly to EOC Logistics for them to handle.

There are certainly other models and possibilities that exist.  What experiences do you have?  What have you seen work?  What have you seen fail?

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

WWW.EPSLLC.BIZ 

Flooding – ’tis the Season

In central New York we have experienced 50+ degree (F) weather for the first time in months.  With the warmer weather has come the melting of a fair amount of snow which accumulated through the winter.  Winter temperatures rarely reaching above freezing up here resulting in little melting of snow through the season, so it’s all occurring now. Coupled with spring rains and storms, flood watches and warnings have been issued here and in other locations around the nation.  If you haven’t already, now is the time to prepare for flooding!

Aside from the measures that homeowners, business owners, and facility managers can take (sump pumps, doorway dams, sand bags, and flood barriers), jurisdictions need to be prepared for the impacts of flooding.  If electronic gauges don’t exist in your streams and rivers, be sure to have someone periodically measure and report their depth and progression toward flood stages.  Ensure that culverts are clean and open for the flow of water, and have personnel, equipment, signage, and barriers ready to deploy to address trouble spots and close roads.

Ironically, water and wastewater systems have a significant vulnerability to flooding.  The EPA has issued Flood Resilience: A Basic Guide for Water and Wastewater Utilities that includes worksheets, videos, and flood maps to guide water and wastewater system operators through identifying their flood risk and vulnerability and mitigation options available to them.  Along with that effort, they have issued a Flooding Incident Action Checklist.

Most importantly, make sure that flood awareness is not a unilateral effort.  Involve emergency managers, elected officials, and first response organizations.  Review plans, policies, and procedures and ensure they are up to date.  Consider related actions, such as notification and warning, evacuation, and flood fighting measures.  Preemptive messaging to property owners/residents and business owners to help them be aware and prepared for flooding is also crucial; and make sure everyone knows how to receive local weather alerts so they are aware of any imminent flooding dangers.

Stay dry!

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

www.epsllc.biz

The Human Aspect of ICS and Overcoming Transitional Incidents

Most often when we consider the Incident Command System (ICS), we think of boxes in an organization chart, forms to be completed, and specific processes to be followed.  True, these are, in essence, aspects of ICS, but they alone will not pave the way to success.  What we must remember is that ICS is conducted by people.

Typically the most difficult aspect of a complex incident is the transition from what we normally do and how we normally respond to elevating our response to a more appropriate level given the scope of the incident.  The groundwork for this transition lies in our initial response, which many experienced responders know can set the tone for the entire operation.  This initial response is based largely on the decisions we make with the information we have.  While there are policies, plans, procedures, play books, checklists, and myriad training that help to inform us, it all comes down to the human factor.  People make decisions based upon the stimuli they are presented with and their own experiences.

Chief Cynthia Renaud in her paper The Missing Piece of NIMS: Teaching Incident Commanders How to Function in the Edge of Chaos discusses approaches to initial response as an oft forgotten aspect of how we teach ICS.  While we know that responders conduct initial responses all the time, there is a significant difference in scope between a routine incident and a complex incident.  This difference in scope requires a different and more open mindset.  While our size up actions may generally be the same, we need to think bigger and this kind of thinking is difficult to train.

The implementation of the ‘bigger’ (i.e. beyond what is routinely used) aspects of ICS is also a challenging mindset for responders.  These aspects of ICS, such as the initial delegation of other organizational aspects and the need for a written Incident Action Plan, do not come easily when they are not practiced.  The fact of the matter is that the implementation of ICS requires a conscious, deliberate decision accompanied by people with knowledge and skilled intent to guide its expansion suitable to the incident at hand.  It also requires a bigger picture mindset recognizing the need to expand the management of the response proportionate to the complexity of the incident and the resources required to address it.  When is it needed?  How do we do it?

One problem is that most of the people we count on to manage these initial responses are trained to manage tactics, not large incidents.  They excel at managing a handful of resources in a rapid deployment and resolving an incident quickly.  This is exactly what they are needed for and they do it well.  Chief Renaud indicates a need to train these first level supervisors to recognize complex incidents for what they are and give them the tools (and authority) to implement broader measures, including an expanded implementation of ICS.

I’m a firm believer in ICS, but I know that people have to drive it.  It’s not something we can put on autopilot and expect it to bring us to our destination.  It has to be consciously and deliberately implemented.  When people criticize ICS, I often find that their criticism is due to false expectations and inappropriate implementation.  With that, I firmly believe we need to do a better job at training to address these issues and help responders better understand the system and demystify its use.

How do we make our training better for the average (non Incident Management Team) responder?  How do we help bridge this gap between the routine and the complex?

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

www.epsllc.biz 

Ebola Reflection Measures our Preparedness

NBC News recently posted an article citing a report published by the Presidential Commission for the Study of Bioethical Issues.  The link provided to the report in the NBC News article doesn’t seem to work, but I’ve found what I believe to be the report here.  The focus of the report is on the ethical challenges faced by the US in responding to this issue.  The report summarizes a variety of ethics related concerns and considerations in this ongoing response and paints a fairly accurate picture of our failures and what needs to be addressed – at least within the topics it discusses.

Photo credit: Forbes.com

Photo credit: Forbes.com

As you might expect from a report on bioethics, it is very public health focused.  While they do make mention of very public health centered topics such as clinical drug trials, they do cover topics which are much more broadly rooted in emergency management and homeland security, such as community and responder education, and ethics associated with quarantine.  This report, while fairly focused, opens a virtual Pandora’s box of issues related to our domestic response to Ebola.

Needless to say, our collective response to this matter was horrible.  Public health policy and guidance was a moving target for weeks; responders were ill prepared to handle potentially infected persons; and the collective of society, politicians, and public safety were largely reluctant to deal with matters of quarantine much less prepared for it.  Was this our first consideration of something like Ebola?  Of course not.  Didn’t we have preparations in place?  Kind of.

Back in the late 90s, pushed mostly by the Nunn-Lugar-Domenici act of 1996, preparedness efforts for state and local responders were funded to enhance our capabilities in dealing with WMD incidents.  Several years later, after 9/11 and the anthrax attacks, another surge of funding was pushed down to state and local governments from HHS/CDC for the purpose of bolstering public health preparedness including preparedness for WMD/weaponized biologicals and naturally occurring pandemic incidents.  These two programs alone, not including other related funding, fostered the creation of plans and organizations to support them, purchased entire stockpiles of equipment and supplies, trained tens of thousands of responders and public health workers, and encouraged exercises across the nation to test capabilities (it was actually these exercises which largely influenced the creation of what we now know as HSEEP).  A lot of good came from these programs, but when suddenly tested with the reality of implementation we seemed to fall apart.  Why?

First of all, many of these preparedness efforts occurred between 10 and nearly 20 years ago.  Many of the people initially trained in these programs have since retired from public service with their organizations losing a great deal of institutional knowledge.  While training programs have continued and still exist, there have been systemic gaps in tying this type of training to other preparedness efforts (planning, policy, equipment, etc.).  Some equipment purchased near the beginning of these programs has likely been retired as well.  Much of it still exists, but has been brought into the fold of other applications, such as HazMat – which is certainly appropriate, but yet again we see gaps, this time our ability to readily utilize equipment specifically for public health threats.

In my opinion many of the planning efforts we saw after 9/11 were misguided.  This started with the people who were doing the planning.  Many health organizations emphasized health care experience for these positions instead of EM or planning experience – which was their main function.  Certainly health care knowledge had some importance, but that could be supplemented through a good advisory committee (EM after all is a team effort).  Exacerbating poor hiring decisions was a lack of investing in the people that were hired.  Many organizations expected them to churn out pandemic influenza plans in short order, with little/no training on the planning process or integral systems that must be considered.  Further, much of the planning had been done in a vacuum – that is, it had been performed with little/no input from other stakeholders.  I had reviewed many of these plans, finding things such as inappropriate applications of ICS and wild assumptions of resource availability.  In no way were these plans realistic or applicable.

There were many exercises performed and most of them had great value.  The problem is that there were a lot of assumptions in these exercises and policy decisions made in the exercises were rarely challenged as they would be in reality.  The US Ebola response brought this all to light as decisions such as quarantine were being handled at the governor level and under significant controversy.  So in this recent response I ask why were decisions delayed and deferred to higher authorities?  Why were adequate local/regional plans not in place to address the care and handling of potentially infected persons?  Why did procedural issues take weeks to resolve?  The simple answer is that there was a lack of proper preparedness.

Back in October of last year, when Ebola was emerging in the US, I posted an article titled Preparing for Ebola – and Whatever Else May Come.  The article still has a great deal of relevancy since I’ve seen very little preparedness for future occurrences – only a harried response to the most recent incident.  There have certainly been a great deal of policies and procedures assembled for the current Ebola issue, but these have a feeling of being temporary, throwaway, or single-use documents, applied only for this instance instead of durable and lasting plans.  Many will keep them ‘on the books’, only to find that their hasty assembly wasn’t comprehensive enough for the next occurrence.  Emergency management and homeland security professionals, public health leaders, and elected and appointed officials need to take a step back and re-look at out preparedness efforts – especially in regard to public health issues.  While we should learn from what we have experienced, we also need to think comprehensively about what is needed.  Well considered policies need to be put in place, supported by our laws and responsibilities to protect the public while also considering protection of civil liberties.  Other preparedness efforts such as planning, training, and exercising need to continue to occur but must have their connections strengthened and intentional.  Exercises need to test plans and policies and challenge decision makers who are certainly making difficult decisions that may include ethics and moral issues in the consideration of caring for few while protecting the greater society.

These are not easy things to be done – which supports the need to work on them now, when we aren’t facing an imminent disaster.  While Ebola certainly wasn’t a health care crisis and there were a lot of things done right, there is always room for improvement – especially when the next biological occurrence could be a crisis.

What have you and your organization learned from the Ebola response?  What gaps have you addressed?  What do you feel still needs to be addressed?

© 2015 – Timothy Riecker

Do You Have an Emergency Management Committee?

Comprehensive emergency and disaster management, effectively done, cannot be done by one person alone.  The best emergency management and homeland security practices are performed by teams.  The practices of emergency management and homeland security are so ubiquitous and multifaceted that we rely on the participation and input of persons in related professions, and in fact professions generally not seen as related, to be successful.  Because of this, both government entities and corporations alike often embrace a team approach to emergency management.  Do you?

Division of Responsibility – Unity of Effort

Aside from the chief elected official or chief executive officer, no one person has the direct ability to ‘command’ the forces of a jurisdiction or corporation.  The trouble with this is that these CEOs are generally not experts in disaster management.  Effective organizations learn the necessity of delegation early on which, while the CEO is still ultimately responsible, those delegated to are functionally responsible for their respective areas.  Laws and regulations often make these delegations mandatory for both jurisdictions and corporations.  While each of these delegations has their own functional responsibilities, they still operate as part of a greater organization and must work well together achieve maximum effectiveness.

The ability of these stakeholders to work together in a unity of effort is certainly important during a disaster, but it’s not the only time they should get together to talk about disasters.  Yes, many of these individuals will see each other during (hopefully) regular staff meetings, but these meetings typically involve briefing the CEO on current or upcoming activities, discussions on hiring and budgets, or being briefed on new policy.  While these are all important discussions they usually leave little room to discuss topics on emergency management and homeland security.

EM/HS certainly warrants its own meetings and workshops to accomplish important tasks such as a periodic threat and hazard identification, plan creation and updates, exercise planning meetings, and discussions on training, grants, and preparedness investments.  This group should also be making policy recommendations to the CEO and ensuring that preparedness efforts are permeating the entire jurisdiction or organization.  Their work together in preparedness efforts will strengthen their relationships and increase their knowledge of each other’s functional responsibilities and capabilities.

Who Should Participate?

In any of the mission areas of emergency management and homeland security (Prevention, Protection, Mitigation, Response, and Recovery – or in activities related to preparedness for any of these) there are often related or even overlapping interests amongst department heads.  The emergency manager, fire, police, EMS, and public works/highway are often at the forefront; but other departments and positions such as parks and recreation, clerk, human resources, finance/treasurer, and zoning can all (and should) have some degree of input.  Larger jurisdictions may have their own health and human services departments which are also important participants.  There are similar positions within corporate organizations that have the same interactions and hold the same importance in this regard to these organizations.  Also be sure to consider external partners such as utilities, major employers, and not for profits and social groups?  Perhaps your EMS provider is a third party or your law enforcement is provided for by a Sheriff’s Department or State Police – be sure to include them as well.

This ‘whole community’ list can grow very quickly and often times not all members are needed for the group to function effectively.  The best practice in emergency management committees is to take a tiered approach – with a core group addressing most matters but with the support and augmentation of an expanded group to include other departments and organizations whose participation is called upon when needed.

Emergency management and homeland security are team efforts which require the active participation and input of all stakeholders to be effective.  Don’t just rely on your emergency manager to get the job done.  They need support from the entire organization to ensure that your jurisdiction or corporation is prepared to address the worst, save lives, and minimize losses.  Some emergency managers view such committees as ‘oversight’ or an unnecessary bureaucracy, but success lies in collaboration.

What’s your approach?

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

www.epsllc.biz

Preparedness – ICS is Not Enough

Back in October I wrote a post about ICS training not being enough for EOC personnel.  You can give it a read to see my reasons, which essentially boil down to the specific role of the EOC (Emergency Operations Center) in the incident management structure and the unique processes which take place in an EOC both not being addressed in ICS (Incident Command System) training.

As I continue to work in various jurisdictions to enhance their preparedness, I am expanding my thoughts on ICS training not being enough – this time for all of preparedness.  In meeting with jurisdictions and discussing their current state of preparedness, many believe they are well prepared to respond to any incident simply because their personnel have received ICS training.  Why am I concerned by this?

Folks, in the grand scheme of things, ICS training alone does not teach you to do very much except how to function within a system.  First off, I’m a huge believer in ICS and the success it can help facilitate in incidents and events.  Not only have I seen it work, but I use it and advocate for it as a chief practice of emergency management.  I’ve been teaching ICS courses since 2001 and have led hundreds of course deliveries amongst the various levels.  That said, in seeing the faith that people are putting in ICS as their savior from disaster, I think that faith has become exaggerated and misplaced.  While ICS gives us guidance on structure, processes, and standards, it still doesn’t tell us HOW to manage the incident and its impacts – and it never well.

The structure, processes, and other standards that ICS provides – when properly applied – are greatly beneficial to our ability to manage a disaster.  Let’s not forget, though, everything else that is needed to be successful.  There is an abundance of training available for personnel to address identified needs to make them better at what they do and thus enhance the capabilities of the jurisdiction or entity.  Some of this may certainly include higher level and more functional training in ICS (i.e. position-specific and incident management team training), but we can’t forget that we must focus on our needs and developing to meet those needs.  More on identifying training needs here and here.

The best way of identifying those needs, comprehensively, is through our plans.  Planning is the cornerstone of preparedness and serves as the foundation of our response.  Planning to appropriate depth is not often performed and always needs to be enhanced (more training in the activities of planning is certainly an identified need!).  Once plans are in place, we need to train all stakeholders on the contents of those plans and of course exercise them.  The process of planning and the exercises we conduct will identify other gaps in preparedness efforts that the jurisdiction or entity should address.  These gaps are most easily analyzed through through five key elements – Planning, Organizing, Equipping, Training, and Exercising (POETE).  More on POETE analysis here.

When a plan is being written or reviewed, we need to follow the bouncing ball for each of the identified activities.  Is it enough for the plan to say that certain stakeholders will be contacted when an incident occurs?  Of course not – we need to identify WHO will contact them, HOW they will be contacted, specifically WHEN they will contact and what is the trigger event, and WHAT they will be told.  Also, what happens if someone is unreachable?  What actions are they expected to take?  Do they then need to make any notifications?  If they are doing nothing with the information, WHY are we even contacting them?  This simple task requires planning (process and decision mapping as well as a specific procedure), organizing (identifying specific personnel and alternates to do this), equipping (the equipment needed for them to make contact; including access, maintenance, operation, and redundancies), training (training and job aids in the procedures and equipment), and exercising (to ensure that all the previous elements function appropriately).

The example above is simple, but shows how far-reaching and complex a seemingly simple activity can be.  ICS training won’t address this.  While ICS practices should be penetrating the deepest aspects of our incident response organization, ICS as a concept is fairly high-level and conceptual.  While it helps structure our tactical resources, ICS itself is not a tactical application – it is simply the structure we perform in.  The processes it provides are not tactical processes, they are incident management processes, but we still need to know about the incident and what to do – ICS will not provide those answers.  ICS is a great tool, but just like a carpenter we must have a variety of tools to do the job properly.

What needs have you identified?

If you need assistance with your preparedness – planning, training, exercising, or needs assessments – reach out to Emergency Preparedness Solutions!

© 2015 – Timothy Riecker

Emergency Preparedness Solutions, LLC

www.epsllc.biz