Home › Blog › Business Continuity Plan: A Practical Guide to BIA, Recovery and Tabletop Testing
Professional Development

Business Continuity Plan: A Practical Guide to BIA, Recovery and Tabletop Testing

October 1, 2026 · Professional Development · 8 min read

Business Continuity Plan: A Practical Guide to BIA, Recovery and Tabletop Testing

A business continuity plan should answer one question: how will the organisation keep delivering what matters when normal operations stop?

That sounds simple, but weak plans often become long documents full of contact lists and generic emergency instructions. A useful continuity plan starts with business impact, identifies the services that cannot tolerate long disruption, defines realistic recovery targets, maps the dependencies those services rely on, assigns decision authority and then tests the plan before a real incident does it for you.

Business team planning crisis response and business continuity
Photo by Memento Media on Unsplash.

ISO 22301:2019 remains the published international standard for business continuity management systems. It sets requirements for organisations to plan, implement, operate, monitor, review, maintain and continually improve a system for preparing for, responding to and recovering from disruptions. A third edition is under development in 2026, while the 2019 edition remains the published standard.

Source: ISO 22301:2019
Source: ISO/CD 22301, third edition under development

A continuity plan is not a prediction of the next crisis. It is a tested operating model for preserving critical outcomes when the cause of disruption is uncertain.

Start with a business impact analysis

Ready.gov’s business continuity planning material places the business impact analysis before recovery strategies. Its planning template asks organisations to identify recovery time objectives for business processes and IT and recovery point objectives for data restoration.

Critical service

Which product, service or obligation must continue or be restored first?

Maximum tolerable disruption

How long can the activity be unavailable before the impact becomes unacceptable?

Recovery time objective

How quickly should the process or service be restored after disruption?

Recovery point objective

For data-dependent services, how much data loss can the organisation tolerate?

Dependencies

Which people, systems, suppliers, facilities, data, approvals and external services are required?

Minimum operating level

What reduced level of service is acceptable while full recovery continues?

Source: Ready.gov, Emergency Plans

Do not treat every process as equally critical

If every function is labelled “critical”, prioritisation becomes impossible. The purpose of the impact analysis is to establish sequence and trade-offs. During a real disruption, resources are constrained. The organisation needs to know what must recover first, what can operate manually, what can pause and what can be restored later.

Impact area Questions to ask Evidence
Customer/service impact What happens to customers or beneficiaries if the service stops? Service commitments, SLAs, customer dependency
Financial impact How does downtime affect revenue, cash flow, penalties or recovery cost? Finance data, contractual penalties, cost estimates
Legal/regulatory impact Which obligations have fixed deadlines or mandatory reporting? Contracts, law, regulatory requirements
Safety impact Could interruption endanger employees, customers or the public? Safety analysis, incident history
Reputation/trust Which failures would materially damage confidence? Stakeholder analysis, past incidents, communications risk
Dependency impact Which other services fail if this process is unavailable? Process maps, systems architecture, supplier maps

Map dependencies before choosing recovery strategies

A critical process is only as resilient as the things it depends on. Those dependencies are often wider than the process owner initially expects.

1

People

Who has the knowledge, access, licences or authority needed to perform the work? Is that capability concentrated in one person or one location?

2

Technology and data

Which applications, networks, devices, integrations and datasets are essential? Can the service function at reduced capacity if one system is unavailable?

3

Suppliers and third parties

Which vendors, cloud services, logistics partners, utilities or outsourced processes are genuine single points of failure?

4

Facilities and physical access

Can the activity move elsewhere? Does the alternate site depend on the same power, transport, telecoms or local infrastructure?

5

Authority and approvals

Who can release money, approve customer commitments, activate emergency procurement or communicate externally when normal leadership is unavailable?

Choose recovery strategies that match the impact

Continuity investment should follow the impact analysis. High-cost redundancy is sensible for some services and wasteful for others.

Dependency Possible continuity strategy Important test
Key employee Cross-training, documented procedures, delegated authority Can another person actually perform the task without the role-holder present?
Critical application Redundancy, failover, alternate platform or manual workaround Has recovery been exercised within the required time?
Data Backups, replication, offline copies and restore procedures Can the data be restored, not merely backed up?
Supplier Secondary supplier, substitute product, strategic inventory Is the alternative independent of the same upstream risk?
Facility Remote work, alternate site, reciprocal arrangement Can the alternate arrangement support the required capacity?
Communications Alternate channels and predefined stakeholder lists Can the team communicate if the primary platform is unavailable?

Build the crisis command structure before the crisis

Continuity plans fail when authority is vague. The team needs a small, usable decision structure that distinguishes strategic crisis leadership from operational recovery work.

Crisis lead

Owns overall priorities, escalation and major trade-offs.

Operations/recovery lead

Coordinates restoration of critical services and resources.

Technology lead

Owns IT recovery, cyber containment and technical dependencies where relevant.

People lead

Handles employee safety, staffing, welfare and workforce communication.

Communications lead

Coordinates internal, customer, media and stakeholder messaging.

Legal/regulatory adviser

Tracks notification duties, evidence preservation and legal exposure.

Write plans for use under pressure

The people using the plan may be tired, frightened, overloaded and working with incomplete information. This is not the time for dense policy prose.

A usable continuity-plan structure

  • Activation criteria and who can activate the plan
  • Critical services in priority order
  • Named roles, deputies and decision authority
  • Immediate actions for the first 15 minutes, first hour and first day
  • Recovery targets and minimum operating levels
  • Dependencies and recovery strategies
  • Primary and alternate communication channels
  • Supplier and partner contacts
  • Escalation and regulatory-notification triggers
  • Manual workarounds and alternate-site instructions
  • Return-to-normal criteria
  • Exercise history, findings and plan changes

Tabletop exercises are where the plan becomes real

CISA’s service-continuity guidance says continuity plans should be validated and exercised before they are relied on during a real event. It describes a progressive approach ranging from plan review and tabletop exercises through partial-function, full-function and integrated exercises.

Source: CISA Tabletop Exercise Package documentation

Illustrative exercise

Scenario: ransomware plus supplier outage

09:00: The organisation loses access to its core customer-management platform. Staff initially assume it is a normal outage.

09:20: IT finds ransomware indicators and isolates affected systems. The main communications platform is still available, but shared files are not.

10:00: A logistics partner reports its own systems are unavailable and cannot confirm deliveries.

11:30: A major customer asks for an executive update and a journalist contacts the communications team.

The exercise should force decisions: who activates the continuity plan, which services switch to manual work, what data can be trusted, who can speak externally, when legal/regulatory teams are involved, which customers are prioritised and what happens if the outage continues for 24 or 72 hours.

A tabletop exercise needs injects, decisions and evidence

Injects

New information introduced as the scenario evolves: supplier failure, social media claims, staff absence, regulator contact or failed backup.

Decision log

Record what the team decided, who decided it and what information they relied on.

Observed gaps

Missing contacts, unclear authority, inaccessible documentation, conflicting recovery targets or untested assumptions.

Improvement owner

Every finding needs an owner, due date and proof of closure. Otherwise the exercise becomes theatre.

Common continuity-plan failures

Failure: the plan assumes the primary communications channel still works. Include alternate channels and offline access to essential contact information.
Failure: backups are treated as recovery. A backup is useful only if it can be restored within the required time and dependency chain.
Failure: every department sets its own recovery target. Targets need to reflect cross-functional business priorities and technical reality.
Failure: the alternate supplier depends on the same infrastructure or upstream source. Apparent redundancy may still contain one common point of failure.
Failure: leaders have never practised making decisions together. The plan cannot compensate for unclear authority and conflicting priorities during a real incident.

Maintain the plan as the organisation changes

Continuity plans age quickly. New systems, suppliers, offices, contracts, leadership structures and regulatory obligations can make an old plan inaccurate even if it was once well designed. Review after meaningful organisational changes, after exercises and after real incidents. CISA also recommends creating, maintaining and exercising incident-response and continuity plans rather than treating planning as a one-time activity.

A 90-minute tabletop exercise can expose more than a 90-page plan

Time Exercise activity What to observe
0–10 min Brief the scenario, roles and rules Does everyone understand who has decision authority?
10–25 min Initial disruption and first decisions Can the team identify critical services and immediate priorities?
25–45 min Add a second failure or conflicting information How does the team handle uncertainty and competing priorities?
45–60 min Customer, regulator or media pressure Are messages consistent and approval routes clear?
60–75 min Extended-outage scenario Are recovery assumptions realistic beyond the first few hours?
75–90 min Debrief and action assignment Which gaps need owners, deadlines and evidence of closure?

The exercise should not reward participants for “winning” the scenario. Its value comes from surfacing assumptions while the consequences are cheap: missing contacts, unclear authority, impossible recovery times, supplier dependencies, inaccessible documentation and communication conflicts.

Build a plan that can survive a real test

MATSH’s Crisis Management and Business Continuity Course combines business impact analysis, continuity planning, crisis leadership, communications and scenario testing so teams can practise before disruption makes the decisions urgent.

Explore the Crisis Management course
Register

Sources

⏱
8 min read 1,537 words · practical and to the point
Upcoming Dates
Employee Engagement Training Program 12 Oct 2026 · USD 2,850
View all upcoming dates →
More on This Topic
Brainstorming vs Design Thinking vs SCAMPER: Which Creativity Method Should You Use? 8 min read Creativity and Innovation at Work: From Problem Framing to Tested Ideas 7 min read Business Continuity Statistics 2026: Cyber, Disruption and Resilience Risk 7 min read Lean vs Six Sigma vs Kaizen vs Root Cause Analysis: Which Method Should You Use? 8 min read

Need In-House Training?

We run all our courses as private programmes for organisations across the GCC and Africa.

Request In-House →