BT 2015 Annual Report Download - page 45

Download and view the complete annual report

Please find page 45 of the 2015 BT annual report below. You can navigate through the pages in the report by either clicking on the pages listed below, or by using the keyword search tool below to find specific information within the annual report.

Page out of 236

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236

43
Overview
The Strategic Report
Purpose and strategy
Delivering our strategy
0ur lines of business
Group performance
Governance
Financial statements
Additional information
Changes over the last year Risk mitigation
n the past ear we have had to deal with an unprecedented increase in
the volue and intensit of cber attacs. e recorded ore top priorit
incidents in the last three onths of 01 than were eperienced in the
previous two ears. he attacs were aied not ust at  but also at our
custoers with the potential to disrupt others and cause collateral daae
to  services.
ollowin a coprehensive review of the resilience and disaster recover
capabilit of our critical sstes databases and echanes we have
invested in enhancin site resilience based on our taret levels of acceptable
ris. e have also invested sinificantl in eo-resilience ie cross-site
recover for our critical sstes where this did not previousl eist and
have alread seen a return on this investent throuh sealess failover and
continuit of service durin planned and occasionall unplanned outaes.
e anae the ris of service interruption throuh a robust control
fraewor that focuses first and foreost on prevention supported b
tried-and-tested recover capabilities. e have also undertaen a lare-
scale estate resilience prorae durin the ear throuh which we have
continued to invest in developin our resilience and recover capabilities in
instances where the ris has been shown to eceed acceptable levels for us.
e have a rollin prorae of aor incident siulations to test and refine
our crisis anaeent procedures. n intensive focus on controllin the
volue of networ chanes has also reduced the nuber of incidents.
he replaceent of euipent that is approachin the end of its service life
has provided opportunities to invest in new ore resilient facilities. e also
benefit fro havin eoraphicall-distributed locations that support cross-
site recover avoidin the need to invest in new sites ust for this purpose.
ur securit strate ais to prevent deter and iniise the conseuences
of attacs. ur defences include phsical protection of our assets
encrption of data control of access rihts real-tie analsis and sharin
of intellience and continuous onitorin for intrusion odifications
and anoalies. e can rapidl adust firewalls to autoaticall bloc ost
alicious data trac. hese easures cobine to reduce the lielihood
of a aor incident and help ensure that interruption or daae can be
contained and dealt with proptl and eectivel.
n response to the increased cber threat we have strenthened our
defences invested in new tools techniues and sills to onitor threats
and increased our capacit to deal with attacs. e have also started a aor
prorae to restructure our  estate to ae it uicer and easier to
anae the incidents when the occur.
ouh aret conditions and copetitive pressures continue in an
lobal reions while in soe we are eperiencin hiher rowth in volue
of business due to previous investents we have ade. he ris landscape
chanes accordinl as does our focus of ris support and review.
f particular note this ear has been the nuber of broadband contracts
with local authorities throuh the UK prorae now enterin the
deliver phase of the contract lifeccle. hile these contracts carr a
dierent ris profile we appl our established ris overnance and reportin
processes to ensure that riss and itiation activities are identified and
reported to anaeent.
ur roup-wide ris overnance and reportin alon with line of business
local overnance and ris anaeent processes provide the visibilit of
e ris and itiation activities. ssurance is provided via independent
audits and at an individual contract level throuh an independent
review prorae based on ultiple selection criteria or b senior
anaeent reuest. roress on riss and itiation actions areed at
these independent reviews are onitored and reported to relevant senior
anaers to ensure proress can be traced.  separate dedicated tea
provides assurance over our UK prorae.
e have sills developent proraes to enhance the abilit of our
people to identif and anae ris and to ae sure learnin fro previous
eperience is included in trainin aterials. he scope and availabilit of
trainin opportunities continue to row in line with -wide learnin and
developent initiatives.