Business continuity management is how an organisation keeps its important work running when something disrupts it. The disruption might be a cyber attack, a power failure, a supplier collapse, a flood or the loss of a site.
Business continuity management is a cycle, not a document. You work out what the business cannot afford to lose, how long it can survive without it, what you will do instead, and then rehearse that arrangement until it is believable.
The value shows in the decisions made before an event. Teams that agree recovery priorities in a calm meeting recover faster than teams arguing about them during an outage. Within an information security management system, continuity planning also protects availability, which is one of the three properties the standard asks you to preserve.
What Business Continuity Covers
Continuity covers the whole organisation, not only IT. A plan that restores servers while the customer service team has nowhere to sit is half a plan.
The scope should include people, premises, technology, information, suppliers and equipment. For each one, ask what happens if it becomes unavailable tomorrow morning.
Two disruption types are often underestimated. The first is loss of key people, where a small team holds knowledge nobody else has. The second is supplier failure, which is why continuity assessment belongs in your vendor management process rather than being treated as an internal-only exercise.
Continuity also sits next to, but apart from, emergency response. An emergency action plan protects people in the first minutes of an event. Continuity picks up afterwards and deals with keeping the organisation trading. Both are needed, and confusing the two leaves a gap in the hours between them.
Business Impact Analysis
The business impact analysis is the foundation. Skip it and every later decision becomes guesswork.

Identifying Critical Activities
List the activities the organisation performs, then judge the impact of losing each one over time: after an hour, a day, a week. Impact covers finance, legal and regulatory duties, customer commitments and reputation.
A useful discipline is to force ranking. When every department declares itself critical, the analysis has failed. Ask each owner which single activity they would restore first if only one could run, then build the priority list from those answers.
Setting Recovery Time and Recovery Point Objectives
The recovery time objective is how quickly an activity must be back. The recovery point objective is how much data loss is acceptable, measured in time.
Set both with the people who own the activity, then check them against what your technology can deliver. A four-hour recovery time objective on a system backed up nightly is a gap, not a target. Recording that gap honestly beats publishing a figure nobody can meet.
Mapping Dependencies
Every critical activity depends on something else. Record the systems, data, staff, premises and third parties each one needs, and link these to your asset identification and classification records.
Dependency mapping is where hidden single points of failure surface. One shared spreadsheet, one unpatched server or one supplier used by four teams shows up quickly once activities are traced back to what they rely on.
Want your impact analysis, risks and continuity actions in one connected system? Try Effivity for Free and set your priorities up in a few hours.
Choosing Continuity Strategies
For each critical activity, decide how it will keep running. Options usually fall into a few groups:

- Redundancy: duplicate systems, sites or connections
- Alternative working: remote access, another office, shared space
- Manual workaround: paper forms or offline processes for a defined period
- Third party arrangements: standby suppliers or contracted support
- Accept the outage: a documented decision where the cost of resilience outweighs the impact
The manual workaround deserves more respect than it gets. Many organisations can run for two days on paper if someone has thought about it in advance, printed the forms and trained the team. Nobody can invent that process during a live outage.
Strategy choice is also a cost decision. Full redundancy for every activity is rarely affordable, so match the level of investment to the impact figures from the analysis. Documenting why a lower-cost option was accepted is as important as the choice itself, since it shows the decision was deliberate.
What the Business Continuity Plan Contains
The plan converts the strategy into instructions. Keep it short and usable:
- Activation criteria and who can invoke the plan
- Continuity team roles with named deputies
- Priority activities with their recovery objectives
- Step-by-step actions for each strategy
- Contact lists for staff, customers, suppliers and authorities
- Communication templates and an internal reporting line
- Return to normal working and stand-down criteria
Hold the plan under version control with the same rigour you apply through document control, and keep an offline copy. A plan available only on the system that has failed is no plan at all.
Where the disruption is a security incident, the continuity plan and the incident response plan run together. One keeps the business trading while the other deals with the cause.
Exercising the Plan
Untested plans fail in predictable ways: wrong phone numbers, unavailable people, and recovery times nobody has ever measured.
Build up gradually. Start with a walkthrough of the document, move to a tabletop scenario with the continuity team, then run a live test of one component such as working from an alternative location or restoring a priority system within its stated recovery time.
Record every exercise: date, scenario, participants, what worked and what did not. Convert findings into dated actions with owners. An exercise producing observations but no corrective actions gives you comfort and no improvement.
One test is worth prioritising above the rest: measure an actual recovery against its stated objective. That single number tells you whether the plan is realistic.
Roles, Governance and Review
Continuity needs an owner at senior level, a coordinator who maintains the programme, and activity owners who keep their sections current.
Review triggers matter more than calendar dates. Refresh the analysis and plan after any disruption or exercise, after organisational or system changes, when a critical supplier changes, and at least annually. Feeding results into management review keeps continuity visible to leadership rather than sitting with one coordinator.
ISO Standards and Continuity
ISO 22301 is the dedicated standard for business continuity management systems, covering the full cycle from analysis through to exercising and improvement.
ISO 27001 approaches continuity from the information security angle. Within the Annex A controls, it addresses information security during disruption and information and communication technology readiness for business continuity, alongside redundancy of processing facilities. In practice the two align well: the impact analysis, recovery objectives and exercise records satisfy both.
Auditors typically want the impact analysis, defined recovery objectives, the plan, evidence it has been communicated, and records from the most recent exercise. Continuity risks should also appear in your risk management plan rather than living in a separate silo.
Measuring Continuity Performance
- Percentage of critical activities with a current impact analysis
- Actual recovery time against the stated objective
- Exercises completed against those planned
- Overdue continuity actions
- Critical suppliers with continuity arrangements confirmed
Track the gap between stated and actual recovery time over several exercises. A closing gap is the clearest evidence that continuity management is working.
How Effivity Supports Business Continuity
Effivity's Information Security Continuity Management module holds continuity requirements, plans and related records in one place, linked to the risks and assets they protect. Workflows assign tasks to owners with due dates and reminders, so reviews and exercises do not slip.
Document Control keeps plans and procedures under version history with approval records. Corrective actions from exercises and real disruptions are tracked to verified closure, and dashboards show open actions, ageing and completion rates in real time. Because information security management software links these records, the evidence an auditor asks for is already assembled. Effivity supports 3,000+ organisations across 120+ countries.
Get a Free Personalized Demo to see continuity planning mapped to your own critical activities.
Frequently Asked Questions
It is the process of preparing an organisation to keep critical activities running during a disruption. It covers analysis, strategy, planning, exercising and review.
It identifies critical activities and measures the effect of losing them over time. The results set recovery priorities and objectives.
The recovery time objective is how fast an activity must be restored. The recovery point objective is how much data loss is acceptable.
At least once a year, and after major changes or real disruptions. Record the scenario, participants and actions raised each time.
ISO 22301 is the dedicated business continuity management standard. ISO 27001 covers continuity from the information security side.
Senior management owns the programme, a coordinator maintains it, and activity owners keep their own plans current. Every employee follows it during a disruption.