COVID-19—Mitigating Risks to Critical IT Projects and Services

March 26, 2020

Written By Stephen Burns, Sébastien Gittens, Michael Whitt, Ruth Promislow, and Matt Flynn

Given the disruptions arising from COVID-19, organizations are well advised to consider how such disruptions will impact their key information technology (IT) projects and services. In particular, starting with those projects and services with the highest priority, we recommend that organizations:

  • review and prioritize their in-flight projects and services (current and in procurement process);
  • review their existing compliance, reporting, governance, risk identification and mitigation processes for the in-flight critical IT projects and services; such as:
    • licensing compliance (especially, given remote work);
    • service levels: specific service levels and related reporting;
    • key personnel;
    • confidentiality and cybersecurity;
    • change management;
    • business continuity and disaster recovery plans and processes; and
    • contractual relief, such as notice of disruption, excusable failure, and force majeure provisions;
  • seek details from the relevant IT vendors and service suppliers as to:
    • how they are currently mitigating COVID-19;
    • how they plan to manage in the coming months, including:
      • supporting remote work;
      • using alternative communication and collaboration solutions;
      • restricting in-person meetings and maintaining social distancing; and
      • restricting travel, especially, international travel; and
      • compliance with any applicable recommended courses of action by the applicable public health authorities;
    • how they plan to prepare and manage the recovery from COVID-19;
    • how these plans will impact the critical projects and services, including their planned approach to resourcing (including key personnel), timelines, deliverables and governance; and
    • how these plans will continue to evolve as the world responds to COVID-19; and
  • review (and, if needed, update) the organization's existing: (i) IT governance processes and resource availability to mitigate the potential COVID-19 disruptions; and (ii) applicable policies.

Organizations are well advised to adopt a pro-active approach to obtaining the information needed from their critical vendors with respect to their response to COVID-19 and to be clear about their expectations around the responsible mitigation, response and recovery activities which may be required.

If you have any questions regarding the information in this article, please contact a member of the Bennett Jones Technology Law group. In addition, please visit our COVID-19 Resource Centre for other COVID-19-related materials.

Authors

Stephen D. Burns
403.298.3050
burnss@bennettjones.com

J. Sébastien A. Gittens
403.298.3409
gittenss@bennettjones.com

Ruth E. Promislow
416.777.4688
promislowr@bennettjones.com

Matthew Flynn
416.777.7488
flynnm@bennettjones.com



Please note that this publication presents an overview of notable legal trends and related updates. It is intended for informational purposes and not as a replacement for detailed legal advice. If you need guidance tailored to your specific circumstances, please contact one of the authors to explore how we can help you navigate your legal needs.

For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.