Case study
Case Study - Northgate Information Solutions
6 slides · 3 min read · Domain 3
Case Study: Site and Facility Security Controls
Overview
Northgate Information Solutions (NIS) is a major supplier of software applications and outsourcing solutions to the public sector. Located in Hemel Hempstead, UK, it was located adjacent to the Buncefield oil storage depot.
In the early morning of December 11, 2005, a fire and subsequent explosion at the storage depot wreaked havoc on the NIS site. The blast caused the collapse of NIS's application and management system, disabled 212 production systems and destroyed voice, data and email services. Finally, the blast blew the main water tank from the roof of the building. Unfortunately, this was the supply for the fire sprinkler system, so the building then caught fire.
Paper, IT systems, filing cabinets, etc., were all blown into the parking lot. There was no loss of life or serious injuries as a result of the incident. The image shows how the site looked after the incident. We can safely assume that NIS had multiple layers of security protecting the IT systems, the building (site) and the customer data. In fact, NIS had excellent business continuity planning in place and was operational again very quickly. But here, we're considering only the facility's security.
Instructions
1. What additional security concerns
Please write a brief response did this incident present?
considering some key elements of this case. Once you 2. This was an extreme incident.
How would an organization deal are done, review the following with such an event?
summary lecture.
3. What external factors would have affected security?
4. Clearly an incident of this magnitude was never considered, and while NIS probably had security guards, were there enough for protecting the scene after what happened?
Feedback
This case is a prime example of the importance of business continuity and site security. In fact, it is why business continuity is such a big field unto itself.
Let's look at the picture of the NIS disaster site while we think of the following.
Almost certainly there were not sufficient personnel to secure the scene, and temporary staff would have been quickly engaged. Papers and confidential information were physically blown out of the facility, which is perhaps a difficult scenario for business continuity process and progress. So, it would be important to be nimble and responsive to continue operations. So personnel were needed, but then what about vetting the new staff? Given the nature of the event and factoring in that a fire was raging (and more explosions may have occurred), the emergency services would probably not have allowed site access to civilians. It is also highly unlikely that the emergency services would have cared about the sensitive nature of the material that was blown away.
There is a lot to consider with site and facility controls, and preparation and foresight can be essential.
What would have helped this situation was having enough staff pre-vetted for an extreme event, and ensuring coordination with local emergency response authorities, as well as other local organizations, so security professionals could easily gain access to the property to help secure NIS data.
