0% found this document useful (0 votes)
6 views15 pages

Crisis Management and Security Plans

Uploaded by

John King
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views15 pages

Crisis Management and Security Plans

Uploaded by

John King
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

13

CRISIS MANAGEMENT, BUSINESS CONTINUITY, SECURITY RECOVERY, AND


BUSINESS RESUMPTION PLANS

The company may face a crisis situation in its premises or supply chain due to the following
threats/security violations:

 Terrorism/ Bomb threat in the facility


 Terrorism threat in the supply chain
 Fire / Explosion/ Natural calamities
 Dangerous Substances & Devices
 Compromised infrastructure
 Contraband Smuggling
 Human Trafficking
 Cyber Threat/ Attack – Trade data lost
 Flash strike by the workers

A. TERRORISM/BOMB THREAT IN THE FACILITYS

Definition:

 Threat call or email from terrorists that they are going to attack the facility,
 Threat call or email from terrorists that they have planted a bomb inside the facility,
 Physical terrorists attack in the facility,
 Terrorists taking hostage of employees of the company,
 Terrorists kidnapping key personnel and demand ransom from the company.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing above crisis situation in the company:

1) All employees shall be trained on the likely happening of such events, the precautionary measures
to be taken, handling of actual threat, reaction needed etc.

2) All employees shall be instructed to inform the factory manager and security head in case if they
receive any threat call. The company will then immediately inform the nearest police station.

3) When a call from outsider providing tip that a bomb has been planted inside the facility, the call
receiver should inform the Asst. Security Officer immediately. He/ She should activate the fire alarm
to evacuate the employees out of the facility. After employees are evacuated then a thorough search
TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL
14
of the entire facility should be carried out with the help of metal detector to find out the bomb. Police
should be informed of such call and their assistance should be sought immediately.

4) All employees shall be trained in the evacuation procedure.

5) Emergency assembly point shall be marked in the premises for easy identification.

6) Emergency contact numbers shall be displayed in the facility.

7) Receptionist/Security guard shall be trained on how to handle the caller when he is calling to
make a threat to the facility or sharing any info about bombs being placed.

8) All employees shall be informed through notice board displays about any terrorism incident in the
country/state/district/city/region.

9) All employees shall be instructed “Not to Panic” in case of any terrorism threat and instead
instructed to follow the common sense to avoid any danger to human lives/property/finished
products.

10) If an employee finds someone in the facility not wearing company issued identity card or visitor
badge, then he/she should inform the presence of such person(s) to the security guards immediately.

11) The employees shall be given cash reward or gift or any kind, if they bring to the attention of
factory management about any security lapse or security violation incidents. All the employees are
encouraged to report any security related incidents.

12) Internal Conspiracy/Unlawful activity/ Theft/ Fraud:

All the employees should know each other very well. In case any employee finds suspicion in
activities of fellow employees, he/she should watch the pattern of activities of such person closely
and inform the Factory Manager/ HR Manager about the same.

When an employee notices or is aware of meeting of a group of employees secretly inside or outside
the campus, he/she should inform the Factory Manager/ HR Manager about the same.

When an employee notices his /her fellow workers consume any liquor or drugs or smoking or doing
any unlawful activity such as robbing/ stealing or any fraud activity, he/ she should bring to the
attention of the Factory Manager/ HR Manager about the incident, the name of the persons involved,
location etc. A through enquiry of such persons shall be conducted and suitable disciplinary action
shall be taken as per the certified Standing Orders of the company.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


15
13) Access Controls/Cargo Integrity:

All the employees should wear the company issued identity card always. Whenever company officials
ask for the identity card, they should show the card to them.

All the employees should access the areas where they are instructed to work and should not access
other areas unless they are asked to do so by their superiors.

The loading bay, packing area, finished goods storage area, HR office and security room are
“Restricted Zones” in the facility. Only authorized employees are allowed access to such areas and
other employees should not enter the zones without authorization from their superiors.

All the visitors are issued with visitor badges upon entry into the facility. If any person found inside
the facility without wearing ID card/ visitor badge, the employees should bring to the attention of
the Factory Manager/ HR Manager about the same.

When visitors are visiting inside the facility, they shall be escorted by the company officials or security
guard. When a visitor is found without escort, the employees should inform their superiors about
the same immediately.

A list of authorized employees’ name with photo shall be displayed in the entrance of Restricted
Zones for easy reference to other employees/visitors. When an authorized employee found any
unauthorized persons in the Restricted Zones, he/ she should bring to the attention of his / her
immediate superior about such persons.

During container loading, only authorized persons are allowed access to the truck, container, loading
area. If a security guard or an authorized employee finds any unauthorized persons in loading area,
trucks or container, he/she should immediately detain the person and hand him/ her over to the
factory management. After enquiry of such person about his background and if he/ she turns out to
be a suspicious person, he/ she will be handed over to the police department.

14) Receiving and opening mails:

Only the security guards are authorized to receive mails / couriers/ posts/ parcels.

Upon receipt of such mails, the security guard should screen the cover using a handheld metal
detector. No mails will be handed over to the addressee without screening.

If no suspicious items found through metal detector, the mail will be handed over to the addressee.

In case of any suspicious material detected, the guard should open the mails and check the contents.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


16
In case such mails contain any illegal materials or contrabands or bombs etc., then it should be
immediately brought to the attention of the Factory Manager/ HR Manager. The factory management
should inform about this detection to the local police and seek their directions.

A thorough investigation about the sender of such mails will be conducted and the gathered details
will be shared with the Police dept.

A register will be used to record the incoming mails, couriers, parcels, and posts.

B. TERRORISM THREAT IN SUPPLY CHAIN

Definition:

 Any person trying to hijack the truck/container through forced means,


 A call to driver from a terrorist or an outsider that a bomb has been planted in the vehicle,
 Any person trying to sneak into the vehicle when the vehicle is parked for a meal or rest stop
during the transit.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the supply chain:

1) The truck drivers shall be trained on the likely happening of such events, the precautionary
measures to be taken, handling of actual threat, reaction needed etc.

2) The truck drivers shall be informed of the emergency contact numbers such as Factory Manager’s
mobile number, HR Manager’s mobile number, Asst. Security Officer’s mobile number, Shipping
manager’s mobile number etc.

3) The truck drivers shall be instructed to inform the facility, shipping manager and police department
immediately, if they come across any untoward incident during the transit.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


17
C. FIRE / EXPLOSION/ NATURAL CALAMITY

Definition:

 A fire accident in the facility


 An explosion in the facility
 An occurrence of natural calamities such as earthquake, flood, etc.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

1) All employees shall be trained on the likely happening of such events, the precautionary measures
to be taken, handling of actual threat, reaction needed etc.

2) All employees shall be trained in the evacuation procedure. Evacuation map and procedure shall
also be posted in the facility.

3) An emergency assembly point shall be marked in the premises for easy identification.

4) A list of emergency contact numbers shall be displayed in the facility.

5) A regular inspection of fire-fighting equipment, fire alarms shall be performed to ensure that they
help when most needed.

6) The emergency lights with battery back-up shall be provided to assist in case of any blackout due
to power cut or any emergency such as fire etc.

7) The names of fire-fighting trained employees shall be displayed in the facility.

8) All the employees shall be trained to inform police/fire service department/ ambulance in case of
any occurrence of above listed incidents.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


18
D. DANGEROUS DEVICES & SUBSTANCES

Definition:

 Substances such as explosives, crackers, liquors, illegal drugs or other contraband are termed
as dangerous substances. Devices such as bomb, Improvised Explosive Devices (IEDs), other
arms & ammunitions are termed as dangerous devices. Any devices, which are not used for the
company’s finished goods production purpose or official purpose, are termed as suspicious
devices.
 There are chances for smuggling of the dangerous devices and substances using the company’s
supply chain as well as chances for use of the company’s premises for temporary storage of
these items.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

1) If any employee finds any of the above substances or devices inside the facility, he/ she should
immediately bring to the attention of the Factory Manager/ HR Manager about the presence of such
items. He/ she should not handle the substances or devices on his/ her own. The factory
management shall seek the help of Police department immediately upon identification of such
devices/substances.

2) All arriving packages, mails and parcels shall be screened before entry into the facility to protect
entry of any dangerous substances or devices into the premises.

3) All employees and visitors shall be screened before entry into the facility to protect entry of any
dangerous substances or devices into the factory premises.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


19
E. COMPROMISED INFRASTRUCTURE

Definition:

 Any damages or tampering of the facility infrastructure such as Gates, Doors, Windows,
Perimeter Fence, Building walls etc.,
 Broken or inoperable Locks, Lights, CCTV, Alarm system and Computer terminals,
 Presence of virus and malware in the computer terminals.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

1) If any employee notices any damage or compromises in the infrastructure such as Gates, Doors,
Windows, or any broken or Locks, Lights, CCTV, Alarm system, Computer terminals, they should
bring to the attention of the Factory Manager/ HR Manager about the location and nature of such
damages or compromises.

2) The compromised infrastructure shall be repaired and restored to its original condition on a priority
basis.

3) The factory management shall investigate root causes of the above incidents and if they are
intentionally done, the factory management shall initiate suitable punitive action against the
perpetrators.

4) If a computer user or operator finds any virus in the system, he should bring to the attention of
the IT administrator about the existence of such virus in their system. The IT administrator should
immediately take steps to eliminate the virus from the system. All the systems shall have to be
checked for virus and malware presence on a regular basis by computer users.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


20
F. CONTRABAND SMUGGLING

Definition:

 Contraband means goods that have been imported or exported illegally,


 There are chances for smuggling of the contrabands using the company’s supply chain as well
as chances for use of the company’s premises for temporary storage of these items.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

1) All employees shall be instructed not to bring any personal items into the production or packing
area. All their personal items shall be kept in the isolated area away from production or packing
sections. The personal items shall be stored in the designated storage locations only.

2) There are chances of smuggling of any non-manifested items such as drugs, explosives, lethal
weapons etc. to the foreign nations through the shipment cargo. Hence, all employees particularly
packers should keep strict vigil over their department to ensure that no such items are introduced
into the packed cartons.

3) If any employee or visitor tries to bring any non-manifested items into the facility, he/ she shall
be handed over to the Police department immediately.

4) All employees shall be notified of any incident of smuggling or smuggling trends through notice
board displays.

5) All drivers of the trucks/containers shall be informed/ trained about the smuggling practices, and
they should be alert to prevent any attempt to smuggle through the finished goods during transit.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


21
G. HUMAN TRAFFICKING

Definition:

 Human trafficking means the action or practice of illegally transporting people from one
country or area to another, typically for the purposes of forced labour or sexual exploitation.
 Human trafficking is an organized crime. It is the world’s second most profitable criminal
enterprise.
 There are possibilities for human trafficking through the cargo/ container shipped from the
company’s premises to the foreign locations.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

1) The company shall not engage prison or bonded or indentured or slave labour. The company shall
maintain copies of valid national identity papers for all the regular and contract employees.

2) The company shall not hire child or young labour.

3) The company shall not allow unidentified or unauthorized persons into the packing areas, finished
goods warehouses and loading bays.

4) The security guards shall inspect the empty containers before loading process, the security guards
shall monitor the loading process and screen the contents of the container before closing the door
and sealing.

5) The company shall maintain proper documentation for all exports and imports made.

6) The company shall not import goods from illegal suppliers or sources. The company shall perform
risk assessment of all material suppliers. The company shall maintain proper documentation for all
imports made, if any. The company shall screen the contents of the import container before
unloading into the facility.

7) The company shall ensure that humans are not trafficked through import of any raw materials or
export of the company’s products.

8) All the employees employed in the company and its facility shall be of Indian nationals only. No
foreign or illegal immigrants shall be employed intentionally or unintentionally.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


22

TI Cycles of India’s policy on human trafficking:

 The company will not indulge in any human trafficking activities.


 The company will not employ any prison/ bonded/ indentured/ slave/ forced labour.
 The company will not force workers to work in the facility. All workers are employed on voluntary
basis only.
 The company will not engage any child labour.
 No international migrant labour will be engaged by the company.
 All employees engaged in the company and its facilities shall be Indian nationals with valid
identity papers.
 The company will not allow its supply chain to be used for any human trafficking attempts
through constant monitoring of the supply chain process.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


23
H. CYBER THREAT / ATTACK

Definition:

 A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or
disrupt digital life in general. Cyber threats include computer viruses, data breaches, Denial
of Service (DoS) attacks and other attack vectors.
 Cyber threats also refer to the possibility of a successful cyber-attack that aims to gain
unauthorized access, damage, disrupt, or steal an information technology asset, computer
network, intellectual property or any other form of sensitive data. Cyber threats can come
from within an organization by trusted users or from remote locations by unknown parties.

Origins of Cyber threats:

Hostile nation-states: National cyber warfare programs provide emerging cyber threats ranging
from propaganda, website defacement, espionage, disruption of key infrastructure to loss of life.
Government-sponsored programs are increasingly sophisticated and pose advanced threats when
compared to other threat actors. Their developing capabilities could cause widespread, long-term
damages to the national security of many countries including the Facilityed States. Hostile nation-
states pose the highest risk due to their ability to effectively employ technology and tools against
the most difficult targets like classified networks and critical infrastructure like electricity grids and
gas control valves.

Terrorist groups: Terrorist groups are increasingly using cyberattack to damage national
interests. They are less developed in cyberattack and have a lower propensity to pursue cyber
means than nation-states. It is likely that terrorist groups will present substantial cyber threats as
more technically competent generations join their ranks.

Corporate spies and organized crime organizations: Corporate spies and organized crime
organizations pose a risk due to their ability to conduct industrial espionage to steal trade secrets
or large-scale monetary theft. Generally, these parties are interested in profit-based activities,
either making a profit or disrupting a business's ability to make a profit by attacking key
infrastructure of competitors, stealing trade secrets, or gaining access and blackmail material.

Hacktivists: Hacktivists activities range across political ideals and issues. Most hacktivist groups
are concerned with spreading propaganda rather than damaging infrastructure or disrupting
services. Their goal is to support their political agenda rather than cause maximum damage to an
organization.

Disgruntled insiders: Disgruntled insiders are a common source of cybercrime. Insiders often
don't need a high degree of computer knowledge to expose sensitive data because they may be
authorized to access the data. Insider threats also include third-party vendors and employees who
may accidentally introduce malware into systems or may log into a secure S3 bucket, download its
contents and share it online resulting in a data breach. We need to check our S3 permissions or
someone else will.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


24
Hackers: Malicious intruders could take advantage of a zero-day exploit to gain unauthorized
access to data. Hackers may break into information systems for a challenge or bragging rights. In
the past, this required a high level of skill. Today, automated attack scripts and protocols can be
downloaded from the Internet, making sophisticated attacks simple.

Natural disasters: Natural disasters represent a cyber threat because they can disrupt our key
infrastructure just like a cyberattack could.

Accidental actions of authorized users: An authorized user may forget to correctly configure
S3 security, causing a potential data leak. Some of the biggest data breaches have been caused by
poor configuration rather than hackers or disgruntled insiders.

Common cyber threats:

Malware: Malware is software that does malicious tasks on a device or network such as
corrupting data or taking control of a system.

Spyware: Spyware is a form of malware that hides on a device providing real-time information
sharing to its host, enabling them to steal data like bank details and passwords.

Phishing attacks: Phishing is when a cybercriminal attempts to lure individuals into providing
sensitive data such as personally identifiable information (PII), banking and credit card details and
passwords.

Distributed denial of service (DDoS) attacks: Distributed denial of service attacks aim to
disrupt a computer network by flooding the network with superfluous requests to overload the
system and prevent legitimate requests being fulfilled.

Ransomware: Ransomware is a type of malware that denies access to a computer system or


data until a ransom is paid.

Zero-day exploits: A zero-day exploit is a flaw in software, hardware or firmware that is


unknown to the party or parties responsible for patching the flaw.

Advanced persistent threats: An advanced persistent threat is when an unauthorized user


gains access to a system or network and remains there without being detected for an extended
period of time.

Trojans: A trojan creates a backdoor in your system, allowing the attacker to gain control of your
computer or access confidential information.

Wiper attacks: A wiper attack is a form of malware whose intention is to wipe the hard drive of
the computer it infects.

Intellectual property theft: Intellectual property theft is stealing or using someone else's
intellectual property without permission.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


25
Theft of money: Cyberattack may gain access to credit card numbers or bank accounts to steal
money.

Data manipulation: Data manipulation is a form of cyberattack that doesn't steal data but aims
to change the data to make it harder for an organization to operate.

Data destruction: Data destruction is when a cyber attacker attempts to delete data.

Man-in-the-middle attack (MITM attack): A MITM attack is when an attack relays and
possibly alters the communication between two parties who believe they are communicating with
each other.

Drive-by downloads: A drive-by download attack is a download that happens without a person's
knowledge often installing a computer virus, spyware or malware.

Malvertising: Malvertising is the use of online advertising to spread malware.

Rogue software: Rogue software is malware that is disguised as real software.

Unpatched software: Unpatched software is software that has a known security weakness that
has been fixed in a later release but not yet updated.

Data centre disrupted by natural disaster: The data centre our software is housed on could
be disrupted by a natural disaster like flooding.

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL


26
Preventive Measures:

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

 Installation of a licensed anti-virus software in all the computer terminals


 Installation of a licensed fire wall program in the IT server
 Installation of a licensed malware, spyware, ransomware protection program in the IT
server
 Prohibition of use of personal devices on the office computers
 Strong and complex password to access systems
 Regular change of computer passwords
 Users lock out of computer terminals after 3 unsuccessful attempts to login
 Training to the users on cyber security measures
 Conducting Vulnerability Scan (VS) on periodical basis
 Performing Penetration Testing (Pen test) on periodical basis
 Engaging licensed and certified software and hardware vendors
 Engaging authorized maintenance service providers
 Installing licensed and certified software and operating systems
 Regular automated backup of the system data
 Storage of backup devices in an offsite location with password protection and/or in
encrypted format
 Use of secure technologies such as VPN or MFA for remote access to the system network
 Engaging certified/ approved Cyber threat intelligence agencies

I. FLASH STRIKE BY WORKERS

Definition:

 A sudden cessation of work by a body of persons employed in an industry without any prior
intimation or serving an advance notice forcing the company to halt its operations.

The company shall undertake following actions to ensure security recovery, business resumption
and business continuity while facing the above crisis situation in the facility:

 The management shall initiate a process of conciliation and reasonableness that can avert
any conflict situations with the workers, including sudden strikes.
 By acting expeditiously and firmly, the management can and should curb a sudden strike.
 The management shall resolve the crisis at the earliest and bring back the normalcy.
TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL
27
COMMUNICATION OF CRISIS SITUATIONS TO THE STAKEHOLDERS/ INTERESTED
PARTIES:

The company shall inform the above crisis situations to the following stakeholders/ interested parties
based on the need-to-know basis:

1) Customers and customer representatives


2) Business Partners including material suppliers, manufacturers, sub-contractors, service
providers and logistics companies
3) Local law enforcement agencies such as Police Department, Cyber Cell, NIA, CB-CID, etc.
4) Government authorities such as Fire & Rescue Services, Customs, Central Excise,
Enforcement Directorate, District Collector and Income-Tax department

USE OF O FF-SITE LOCATION:

The company has another facility in Rajpura, Punjab, India. The company shall use this facility in
case of the Ambattur premises is rendered unusable due to the crisis situation.

CRISIS MANAGEMENT TEAM:

CRISIS SITUATIONS PRIMARY CONTRIBUTING RESPONSIBLE


RESPONSIBLE PERSON PERSONS
Terrorism/ Bomb threat HR Manager Asst. Security Officer, Factory Manager
in the facility
Terrorism threat during Shipping Manager Shipping Executive
supply chain
Fire / Explosion/ Natural HR Manager Asst. Security Officer, Factory Manager
calamities
Dangerous Substances & HR Manager Asst. Security Officer, Factory Manager
Devices
Compromised HR Manager Asst. Security Officer, Factory Manager
infrastructure
Contraband Smuggling Shipping Manager Asst. Security Officer, Factory Manager

Human Trafficking Shipping Manager HR Manager, Asst. Security Officer

Cyber Threat/Attack IT Manager IT Executive

Flash Strike by Workers HR Manager HR Executive, Asst. Security Officer,


Factory Manager

TUBE INVESTMENTS OF INDIA LIMITED – TI CYLES OF INDIA SCS MANUAL

You might also like