COVID-19—Mitigating Risks to Critical IT Projects and Services
March 26, 2020
Written By Stephen Burns, Sébastien Gittens, Michael Whitt, Ruth Promislow, and Matt Flynn
Given the disruptions arising from COVID-19, organizations are well advised to consider how such disruptions will impact their key information technology (IT) projects and services. In particular, starting with those projects and services with the highest priority, we recommend that organizations:
- review and prioritize their in-flight projects and services (current and in procurement process);
- review their existing compliance, reporting, governance, risk identification and mitigation processes for the in-flight critical IT projects and services; such as:
- licensing compliance (especially, given remote work);
- service levels: specific service levels and related reporting;
- key personnel;
- confidentiality and cybersecurity;
- change management;
- business continuity and disaster recovery plans and processes; and
- contractual relief, such as notice of disruption, excusable failure, and force majeure provisions;
- seek details from the relevant IT vendors and service suppliers as to:
- how they are currently mitigating COVID-19;
- how they plan to manage in the coming months, including:
- supporting remote work;
- using alternative communication and collaboration solutions;
- restricting in-person meetings and maintaining social distancing; and
- restricting travel, especially, international travel; and
- compliance with any applicable recommended courses of action by the applicable public health authorities;
- how they plan to prepare and manage the recovery from COVID-19;
- how these plans will impact the critical projects and services, including their planned approach to resourcing (including key personnel), timelines, deliverables and governance; and
- how these plans will continue to evolve as the world responds to COVID-19; and
- review (and, if needed, update) the organization's existing: (i) IT governance processes and resource availability to mitigate the potential COVID-19 disruptions; and (ii) applicable policies.
Organizations are well advised to adopt a pro-active approach to obtaining the information needed from their critical vendors with respect to their response to COVID-19 and to be clear about their expectations around the responsible mitigation, response and recovery activities which may be required.
If you have any questions regarding the information in this article, please contact a member of the Bennett Jones Technology Law group. In addition, please visit our COVID-19 Resource Centre for other COVID-19-related materials.
Authors
Stephen D. Burns 403.298.3050 burnss@bennettjones.com
| J. Sébastien A. Gittens 403.298.3409 gittenss@bennettjones.com
| Ruth E. Promislow 416.777.4688 promislowr@bennettjones.com
| Matthew Flynn 416.777.7488 flynnm@bennettjones.com
|
Please note that this publication presents an overview of notable legal trends and related updates. It is intended for informational purposes and not as a replacement for detailed legal advice. If you need guidance tailored to your specific circumstances, please contact one of the authors to explore how we can help you navigate your legal needs.
For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.
|