October 1, 2026 · Professional Development · 8 min read
That sounds simple, but weak plans often become long documents full of contact lists and generic emergency instructions. A useful continuity plan starts with business impact, identifies the services that cannot tolerate long disruption, defines realistic recovery targets, maps the dependencies those services rely on, assigns decision authority and then tests the plan before a real incident does it for you.

ISO 22301:2019 remains the published international standard for business continuity management systems. It sets requirements for organisations to plan, implement, operate, monitor, review, maintain and continually improve a system for preparing for, responding to and recovering from disruptions. A third edition is under development in 2026, while the 2019 edition remains the published standard.
Source: ISO 22301:2019
Source: ISO/CD 22301, third edition under development
Ready.gov’s business continuity planning material places the business impact analysis before recovery strategies. Its planning template asks organisations to identify recovery time objectives for business processes and IT and recovery point objectives for data restoration.
Which product, service or obligation must continue or be restored first?
How long can the activity be unavailable before the impact becomes unacceptable?
How quickly should the process or service be restored after disruption?
For data-dependent services, how much data loss can the organisation tolerate?
Which people, systems, suppliers, facilities, data, approvals and external services are required?
What reduced level of service is acceptable while full recovery continues?
Source: Ready.gov, Emergency Plans
If every function is labelled “critical”, prioritisation becomes impossible. The purpose of the impact analysis is to establish sequence and trade-offs. During a real disruption, resources are constrained. The organisation needs to know what must recover first, what can operate manually, what can pause and what can be restored later.
| Impact area | Questions to ask | Evidence |
|---|---|---|
| Customer/service impact | What happens to customers or beneficiaries if the service stops? | Service commitments, SLAs, customer dependency |
| Financial impact | How does downtime affect revenue, cash flow, penalties or recovery cost? | Finance data, contractual penalties, cost estimates |
| Legal/regulatory impact | Which obligations have fixed deadlines or mandatory reporting? | Contracts, law, regulatory requirements |
| Safety impact | Could interruption endanger employees, customers or the public? | Safety analysis, incident history |
| Reputation/trust | Which failures would materially damage confidence? | Stakeholder analysis, past incidents, communications risk |
| Dependency impact | Which other services fail if this process is unavailable? | Process maps, systems architecture, supplier maps |
A critical process is only as resilient as the things it depends on. Those dependencies are often wider than the process owner initially expects.
Who has the knowledge, access, licences or authority needed to perform the work? Is that capability concentrated in one person or one location?
Which applications, networks, devices, integrations and datasets are essential? Can the service function at reduced capacity if one system is unavailable?
Which vendors, cloud services, logistics partners, utilities or outsourced processes are genuine single points of failure?
Can the activity move elsewhere? Does the alternate site depend on the same power, transport, telecoms or local infrastructure?
Who can release money, approve customer commitments, activate emergency procurement or communicate externally when normal leadership is unavailable?
Continuity investment should follow the impact analysis. High-cost redundancy is sensible for some services and wasteful for others.
| Dependency | Possible continuity strategy | Important test |
|---|---|---|
| Key employee | Cross-training, documented procedures, delegated authority | Can another person actually perform the task without the role-holder present? |
| Critical application | Redundancy, failover, alternate platform or manual workaround | Has recovery been exercised within the required time? |
| Data | Backups, replication, offline copies and restore procedures | Can the data be restored, not merely backed up? |
| Supplier | Secondary supplier, substitute product, strategic inventory | Is the alternative independent of the same upstream risk? |
| Facility | Remote work, alternate site, reciprocal arrangement | Can the alternate arrangement support the required capacity? |
| Communications | Alternate channels and predefined stakeholder lists | Can the team communicate if the primary platform is unavailable? |
Continuity plans fail when authority is vague. The team needs a small, usable decision structure that distinguishes strategic crisis leadership from operational recovery work.
Owns overall priorities, escalation and major trade-offs.
Coordinates restoration of critical services and resources.
Owns IT recovery, cyber containment and technical dependencies where relevant.
Handles employee safety, staffing, welfare and workforce communication.
Coordinates internal, customer, media and stakeholder messaging.
Tracks notification duties, evidence preservation and legal exposure.
The people using the plan may be tired, frightened, overloaded and working with incomplete information. This is not the time for dense policy prose.
CISA’s service-continuity guidance says continuity plans should be validated and exercised before they are relied on during a real event. It describes a progressive approach ranging from plan review and tabletop exercises through partial-function, full-function and integrated exercises.
Source: CISA Tabletop Exercise Package documentation
09:00: The organisation loses access to its core customer-management platform. Staff initially assume it is a normal outage.
09:20: IT finds ransomware indicators and isolates affected systems. The main communications platform is still available, but shared files are not.
10:00: A logistics partner reports its own systems are unavailable and cannot confirm deliveries.
11:30: A major customer asks for an executive update and a journalist contacts the communications team.
The exercise should force decisions: who activates the continuity plan, which services switch to manual work, what data can be trusted, who can speak externally, when legal/regulatory teams are involved, which customers are prioritised and what happens if the outage continues for 24 or 72 hours.
New information introduced as the scenario evolves: supplier failure, social media claims, staff absence, regulator contact or failed backup.
Record what the team decided, who decided it and what information they relied on.
Missing contacts, unclear authority, inaccessible documentation, conflicting recovery targets or untested assumptions.
Every finding needs an owner, due date and proof of closure. Otherwise the exercise becomes theatre.
Continuity plans age quickly. New systems, suppliers, offices, contracts, leadership structures and regulatory obligations can make an old plan inaccurate even if it was once well designed. Review after meaningful organisational changes, after exercises and after real incidents. CISA also recommends creating, maintaining and exercising incident-response and continuity plans rather than treating planning as a one-time activity.
| Time | Exercise activity | What to observe |
|---|---|---|
| 0–10 min | Brief the scenario, roles and rules | Does everyone understand who has decision authority? |
| 10–25 min | Initial disruption and first decisions | Can the team identify critical services and immediate priorities? |
| 25–45 min | Add a second failure or conflicting information | How does the team handle uncertainty and competing priorities? |
| 45–60 min | Customer, regulator or media pressure | Are messages consistent and approval routes clear? |
| 60–75 min | Extended-outage scenario | Are recovery assumptions realistic beyond the first few hours? |
| 75–90 min | Debrief and action assignment | Which gaps need owners, deadlines and evidence of closure? |
The exercise should not reward participants for “winning” the scenario. Its value comes from surfacing assumptions while the consequences are cheap: missing contacts, unclear authority, impossible recovery times, supplier dependencies, inaccessible documentation and communication conflicts.
MATSH’s Crisis Management and Business Continuity Course combines business impact analysis, continuity planning, crisis leadership, communications and scenario testing so teams can practise before disruption makes the decisions urgent.
We run all our courses as private programmes for organisations across the GCC and Africa.
Request In-House →