{"id":10437,"date":"2026-10-01T09:00:00","date_gmt":"2026-10-01T05:00:00","guid":{"rendered":"https:\/\/matsh.co\/en\/?p=10437"},"modified":"2026-09-27T17:31:33","modified_gmt":"2026-09-27T13:31:33","slug":"business-continuity-plan-guide","status":"publish","type":"post","link":"https:\/\/matsh.co\/en\/business-continuity-plan-guide\/","title":{"rendered":"Business Continuity Plan: A Practical Guide to BIA, Recovery and Tabletop Testing"},"content":{"rendered":"<style>\n.mh-section{border-left:4px solid #c0561b;padding-left:14px;margin:42px 0 18px;font-size:1.35rem;color:#3d2408}\n.mh-hook{background:#fdf5ee;border:1.5px solid #ecd0a8;border-radius:16px;padding:30px 32px;margin-bottom:28px}.mh-hook h2{margin:0 0 12px;color:#3d2408;font-size:1.38rem}.mh-hook p{margin:0;color:#4a3a2e;line-height:1.8}\n.mh-pull{border-left:4px solid #c0561b;background:#fdf5ee;padding:20px 26px;margin:28px 0;font-size:1.04rem;font-weight:600;color:#3d2408;line-height:1.7}\n.mh-grid{display:grid;grid-template-columns:repeat(auto-fit,minmax(220px,1fr));gap:14px;margin:22px 0 30px}.mh-card{border:1.5px solid #ecd0a8;border-radius:13px;padding:20px;background:#fff}.mh-card strong{display:block;color:#3d2408;margin-bottom:7px}.mh-card p{margin:0;color:#4a5568;font-size:.9rem;line-height:1.7}\n.mh-table{width:100%;border-collapse:collapse;margin:20px 0 30px;font-size:.91rem}.mh-table th{background:#3d2408;color:#fff;text-align:left;padding:13px 14px}.mh-table td{border:1px solid #ead8c4;padding:13px 14px;vertical-align:top;line-height:1.58}.mh-table tr:nth-child(even) td{background:#fffaf6}\n.mh-step{border:1.5px solid #ecd0a8;border-radius:14px;padding:20px 24px;margin:14px 0;display:flex;gap:16px}.mh-step .n{background:#c0561b;color:#fff;width:34px;height:34px;border-radius:50%;display:flex;align-items:center;justify-content:center;font-weight:800;flex-shrink:0}.mh-step h4{margin:0 0 6px;color:#3d2408}.mh-step p{margin:0;color:#4a5568;font-size:.9rem;line-height:1.72}\n.mh-worked{background:#f8fafc;border:1.5px solid #dde3ec;border-radius:12px;padding:26px 28px;margin:24px 0}.mh-worked .label{font-weight:800;color:#c0561b;text-transform:uppercase;font-size:.78rem}.mh-worked h4{margin:6px 0 10px;color:#122f42}.mh-worked p{margin:0 0 12px;color:#3a4a5e;line-height:1.8}\n.mh-fail{background:#fdf3f8;border-radius:10px;padding:16px 20px;margin:10px 0;color:#4a1030;line-height:1.65}\n.mh-artifact{border:2px dashed #ecd0a8;border-radius:12px;padding:22px 26px;margin:24px 0}.mh-artifact h4{margin:0 0 10px;color:#3d2408}.mh-artifact ul{margin:0;padding-left:20px;color:#3a4a5e;line-height:1.9}\n.mh-related{background:#f8fafc;border:1.5px solid #dde3ec;border-radius:14px;padding:28px 30px;margin:34px 0}.mh-related h3{margin:0 0 16px;color:#122f42}.mh-related-grid{display:grid;grid-template-columns:repeat(auto-fit,minmax(230px,1fr));gap:12px}.mh-related a{background:#fff;border:1px solid #dde3ec;border-radius:10px;padding:14px 16px;text-decoration:none;color:#122f42;display:block}.mh-related span{display:block;color:#6b7a99;font-size:.8rem;margin-top:4px}\n.mh-cta{background:linear-gradient(135deg,#c0561b,#3d2408);border-radius:16px;padding:36px 38px;margin:36px 0;color:#fff}.mh-cta h3{color:#fff;margin:0 0 10px}.mh-cta p{margin:0 0 20px;opacity:.92;line-height:1.7}.mh-cta a{display:inline-block;background:rgba(255,255,255,.16);border:1px solid rgba(255,255,255,.35);border-radius:8px;padding:10px 16px;margin:5px 7px 0 0;color:#fff;text-decoration:none;font-weight:700;font-size:.86rem}\n<\/style>\n<div class=\"mh-hook\">\n<h2>A business continuity plan should answer one question: how will the organisation keep delivering what matters when normal operations stop?<\/h2>\n<p>That sounds simple, but weak plans often become long documents full of contact lists and generic emergency instructions. A useful continuity plan starts with business impact, identifies the services that cannot tolerate long disruption, defines realistic recovery targets, maps the dependencies those services rely on, assigns decision authority and then tests the plan before a real incident does it for you.<\/p>\n<\/div>\n<figure class=\"wp-block-image size-full\" style=\"margin:26px 0 34px\"><img decoding=\"async\" src=\"https:\/\/matsh.co\/en\/wp-content\/uploads\/2026\/09\/Business-continuity-planning-meeting-photo-by-Memento-Media-on-Unsplash.jpg\" alt=\"Business team planning crisis response and business continuity\"\/><figcaption style=\"font-size:.75rem;color:#6b7a99\">Photo by <a href=\"https:\/\/unsplash.com\/@heymemento?utm_source=wpvibe&#038;utm_medium=referral\" target=\"_blank\" rel=\"noopener\">Memento Media<\/a> on Unsplash.<\/figcaption><\/figure>\n<p>ISO 22301:2019 remains the published international standard for business continuity management systems. It sets requirements for organisations to plan, implement, operate, monitor, review, maintain and continually improve a system for preparing for, responding to and recovering from disruptions. A third edition is under development in 2026, while the 2019 edition remains the published standard.<\/p>\n<p><a href=\"https:\/\/www.iso.org\/standard\/75106.html\" target=\"_blank\" rel=\"noopener\">Source: ISO 22301:2019<\/a><br \/>\n<a href=\"https:\/\/www.iso.org\/standard\/93606.html\" target=\"_blank\" rel=\"noopener\">Source: ISO\/CD 22301, third edition under development<\/a><\/p>\n<div class=\"mh-pull\">A continuity plan is not a prediction of the next crisis. It is a tested operating model for preserving critical outcomes when the cause of disruption is uncertain.<\/div>\n<h2 class=\"mh-section\">Start with a business impact analysis<\/h2>\n<p>Ready.gov&#8217;s business continuity planning material places the business impact analysis before recovery strategies. Its planning template asks organisations to identify recovery time objectives for business processes and IT and recovery point objectives for data restoration.<\/p>\n<div class=\"mh-grid\">\n<div class=\"mh-card\"><strong>Critical service<\/strong><\/p>\n<p>Which product, service or obligation must continue or be restored first?<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Maximum tolerable disruption<\/strong><\/p>\n<p>How long can the activity be unavailable before the impact becomes unacceptable?<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Recovery time objective<\/strong><\/p>\n<p>How quickly should the process or service be restored after disruption?<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Recovery point objective<\/strong><\/p>\n<p>For data-dependent services, how much data loss can the organisation tolerate?<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Dependencies<\/strong><\/p>\n<p>Which people, systems, suppliers, facilities, data, approvals and external services are required?<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Minimum operating level<\/strong><\/p>\n<p>What reduced level of service is acceptable while full recovery continues?<\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/www.ready.gov\/business\/emergency-plans\" target=\"_blank\" rel=\"noopener\">Source: Ready.gov, Emergency Plans<\/a><\/p>\n<h2 class=\"mh-section\">Do not treat every process as equally critical<\/h2>\n<p>If every function is labelled \u201ccritical\u201d, prioritisation becomes impossible. The purpose of the impact analysis is to establish sequence and trade-offs. During a real disruption, resources are constrained. The organisation needs to know what must recover first, what can operate manually, what can pause and what can be restored later.<\/p>\n<table class=\"mh-table\">\n<thead>\n<tr>\n<th>Impact area<\/th>\n<th>Questions to ask<\/th>\n<th>Evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Customer\/service impact<\/td>\n<td>What happens to customers or beneficiaries if the service stops?<\/td>\n<td>Service commitments, SLAs, customer dependency<\/td>\n<\/tr>\n<tr>\n<td>Financial impact<\/td>\n<td>How does downtime affect revenue, cash flow, penalties or recovery cost?<\/td>\n<td>Finance data, contractual penalties, cost estimates<\/td>\n<\/tr>\n<tr>\n<td>Legal\/regulatory impact<\/td>\n<td>Which obligations have fixed deadlines or mandatory reporting?<\/td>\n<td>Contracts, law, regulatory requirements<\/td>\n<\/tr>\n<tr>\n<td>Safety impact<\/td>\n<td>Could interruption endanger employees, customers or the public?<\/td>\n<td>Safety analysis, incident history<\/td>\n<\/tr>\n<tr>\n<td>Reputation\/trust<\/td>\n<td>Which failures would materially damage confidence?<\/td>\n<td>Stakeholder analysis, past incidents, communications risk<\/td>\n<\/tr>\n<tr>\n<td>Dependency impact<\/td>\n<td>Which other services fail if this process is unavailable?<\/td>\n<td>Process maps, systems architecture, supplier maps<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"mh-section\">Map dependencies before choosing recovery strategies<\/h2>\n<p>A critical process is only as resilient as the things it depends on. Those dependencies are often wider than the process owner initially expects.<\/p>\n<div class=\"mh-step\">\n<div class=\"n\">1<\/div>\n<div>\n<h4>People<\/h4>\n<p>Who has the knowledge, access, licences or authority needed to perform the work? Is that capability concentrated in one person or one location?<\/p>\n<\/div>\n<\/div>\n<div class=\"mh-step\">\n<div class=\"n\">2<\/div>\n<div>\n<h4>Technology and data<\/h4>\n<p>Which applications, networks, devices, integrations and datasets are essential? Can the service function at reduced capacity if one system is unavailable?<\/p>\n<\/div>\n<\/div>\n<div class=\"mh-step\">\n<div class=\"n\">3<\/div>\n<div>\n<h4>Suppliers and third parties<\/h4>\n<p>Which vendors, cloud services, logistics partners, utilities or outsourced processes are genuine single points of failure?<\/p>\n<\/div>\n<\/div>\n<div class=\"mh-step\">\n<div class=\"n\">4<\/div>\n<div>\n<h4>Facilities and physical access<\/h4>\n<p>Can the activity move elsewhere? Does the alternate site depend on the same power, transport, telecoms or local infrastructure?<\/p>\n<\/div>\n<\/div>\n<div class=\"mh-step\">\n<div class=\"n\">5<\/div>\n<div>\n<h4>Authority and approvals<\/h4>\n<p>Who can release money, approve customer commitments, activate emergency procurement or communicate externally when normal leadership is unavailable?<\/p>\n<\/div>\n<\/div>\n<h2 class=\"mh-section\">Choose recovery strategies that match the impact<\/h2>\n<p>Continuity investment should follow the impact analysis. High-cost redundancy is sensible for some services and wasteful for others.<\/p>\n<table class=\"mh-table\">\n<thead>\n<tr>\n<th>Dependency<\/th>\n<th>Possible continuity strategy<\/th>\n<th>Important test<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Key employee<\/td>\n<td>Cross-training, documented procedures, delegated authority<\/td>\n<td>Can another person actually perform the task without the role-holder present?<\/td>\n<\/tr>\n<tr>\n<td>Critical application<\/td>\n<td>Redundancy, failover, alternate platform or manual workaround<\/td>\n<td>Has recovery been exercised within the required time?<\/td>\n<\/tr>\n<tr>\n<td>Data<\/td>\n<td>Backups, replication, offline copies and restore procedures<\/td>\n<td>Can the data be restored, not merely backed up?<\/td>\n<\/tr>\n<tr>\n<td>Supplier<\/td>\n<td>Secondary supplier, substitute product, strategic inventory<\/td>\n<td>Is the alternative independent of the same upstream risk?<\/td>\n<\/tr>\n<tr>\n<td>Facility<\/td>\n<td>Remote work, alternate site, reciprocal arrangement<\/td>\n<td>Can the alternate arrangement support the required capacity?<\/td>\n<\/tr>\n<tr>\n<td>Communications<\/td>\n<td>Alternate channels and predefined stakeholder lists<\/td>\n<td>Can the team communicate if the primary platform is unavailable?<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"mh-section\">Build the crisis command structure before the crisis<\/h2>\n<p>Continuity plans fail when authority is vague. The team needs a small, usable decision structure that distinguishes strategic crisis leadership from operational recovery work.<\/p>\n<div class=\"mh-grid\">\n<div class=\"mh-card\"><strong>Crisis lead<\/strong><\/p>\n<p>Owns overall priorities, escalation and major trade-offs.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Operations\/recovery lead<\/strong><\/p>\n<p>Coordinates restoration of critical services and resources.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Technology lead<\/strong><\/p>\n<p>Owns IT recovery, cyber containment and technical dependencies where relevant.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>People lead<\/strong><\/p>\n<p>Handles employee safety, staffing, welfare and workforce communication.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Communications lead<\/strong><\/p>\n<p>Coordinates internal, customer, media and stakeholder messaging.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Legal\/regulatory adviser<\/strong><\/p>\n<p>Tracks notification duties, evidence preservation and legal exposure.<\/p>\n<\/div>\n<\/div>\n<h2 class=\"mh-section\">Write plans for use under pressure<\/h2>\n<p>The people using the plan may be tired, frightened, overloaded and working with incomplete information. This is not the time for dense policy prose.<\/p>\n<div class=\"mh-artifact\">\n<h4>A usable continuity-plan structure<\/h4>\n<ul>\n<li>Activation criteria and who can activate the plan<\/li>\n<li>Critical services in priority order<\/li>\n<li>Named roles, deputies and decision authority<\/li>\n<li>Immediate actions for the first 15 minutes, first hour and first day<\/li>\n<li>Recovery targets and minimum operating levels<\/li>\n<li>Dependencies and recovery strategies<\/li>\n<li>Primary and alternate communication channels<\/li>\n<li>Supplier and partner contacts<\/li>\n<li>Escalation and regulatory-notification triggers<\/li>\n<li>Manual workarounds and alternate-site instructions<\/li>\n<li>Return-to-normal criteria<\/li>\n<li>Exercise history, findings and plan changes<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"mh-section\">Tabletop exercises are where the plan becomes real<\/h2>\n<p>CISA&#8217;s service-continuity guidance says continuity plans should be validated and exercised before they are relied on during a real event. It describes a progressive approach ranging from plan review and tabletop exercises through partial-function, full-function and integrated exercises.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/ctep-package-documents\" target=\"_blank\" rel=\"noopener\">Source: CISA Tabletop Exercise Package documentation<\/a><\/p>\n<div class=\"mh-worked\">\n<span class=\"label\">Illustrative exercise<\/span><\/p>\n<h4>Scenario: ransomware plus supplier outage<\/h4>\n<p><strong>09:00:<\/strong> The organisation loses access to its core customer-management platform. Staff initially assume it is a normal outage.<\/p>\n<p><strong>09:20:<\/strong> IT finds ransomware indicators and isolates affected systems. The main communications platform is still available, but shared files are not.<\/p>\n<p><strong>10:00:<\/strong> A logistics partner reports its own systems are unavailable and cannot confirm deliveries.<\/p>\n<p><strong>11:30:<\/strong> A major customer asks for an executive update and a journalist contacts the communications team.<\/p>\n<p>The exercise should force decisions: who activates the continuity plan, which services switch to manual work, what data can be trusted, who can speak externally, when legal\/regulatory teams are involved, which customers are prioritised and what happens if the outage continues for 24 or 72 hours.<\/p>\n<\/div>\n<h2 class=\"mh-section\">A tabletop exercise needs injects, decisions and evidence<\/h2>\n<div class=\"mh-grid\">\n<div class=\"mh-card\"><strong>Injects<\/strong><\/p>\n<p>New information introduced as the scenario evolves: supplier failure, social media claims, staff absence, regulator contact or failed backup.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Decision log<\/strong><\/p>\n<p>Record what the team decided, who decided it and what information they relied on.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Observed gaps<\/strong><\/p>\n<p>Missing contacts, unclear authority, inaccessible documentation, conflicting recovery targets or untested assumptions.<\/p>\n<\/div>\n<div class=\"mh-card\"><strong>Improvement owner<\/strong><\/p>\n<p>Every finding needs an owner, due date and proof of closure. Otherwise the exercise becomes theatre.<\/p>\n<\/div>\n<\/div>\n<h2 class=\"mh-section\">Common continuity-plan failures<\/h2>\n<div class=\"mh-fail\"><strong>Failure: the plan assumes the primary communications channel still works.<\/strong> Include alternate channels and offline access to essential contact information.<\/div>\n<div class=\"mh-fail\"><strong>Failure: backups are treated as recovery.<\/strong> A backup is useful only if it can be restored within the required time and dependency chain.<\/div>\n<div class=\"mh-fail\"><strong>Failure: every department sets its own recovery target.<\/strong> Targets need to reflect cross-functional business priorities and technical reality.<\/div>\n<div class=\"mh-fail\"><strong>Failure: the alternate supplier depends on the same infrastructure or upstream source.<\/strong> Apparent redundancy may still contain one common point of failure.<\/div>\n<div class=\"mh-fail\"><strong>Failure: leaders have never practised making decisions together.<\/strong> The plan cannot compensate for unclear authority and conflicting priorities during a real incident.<\/div>\n<h2 class=\"mh-section\">Maintain the plan as the organisation changes<\/h2>\n<p>Continuity plans age quickly. New systems, suppliers, offices, contracts, leadership structures and regulatory obligations can make an old plan inaccurate even if it was once well designed. Review after meaningful organisational changes, after exercises and after real incidents. CISA also recommends creating, maintaining and exercising incident-response and continuity plans rather than treating planning as a one-time activity.<\/p>\n<h2 class=\"mh-section\">A 90-minute tabletop exercise can expose more than a 90-page plan<\/h2>\n<table class=\"mh-table\">\n<thead>\n<tr>\n<th>Time<\/th>\n<th>Exercise activity<\/th>\n<th>What to observe<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>0\u201310 min<\/td>\n<td>Brief the scenario, roles and rules<\/td>\n<td>Does everyone understand who has decision authority?<\/td>\n<\/tr>\n<tr>\n<td>10\u201325 min<\/td>\n<td>Initial disruption and first decisions<\/td>\n<td>Can the team identify critical services and immediate priorities?<\/td>\n<\/tr>\n<tr>\n<td>25\u201345 min<\/td>\n<td>Add a second failure or conflicting information<\/td>\n<td>How does the team handle uncertainty and competing priorities?<\/td>\n<\/tr>\n<tr>\n<td>45\u201360 min<\/td>\n<td>Customer, regulator or media pressure<\/td>\n<td>Are messages consistent and approval routes clear?<\/td>\n<\/tr>\n<tr>\n<td>60\u201375 min<\/td>\n<td>Extended-outage scenario<\/td>\n<td>Are recovery assumptions realistic beyond the first few hours?<\/td>\n<\/tr>\n<tr>\n<td>75\u201390 min<\/td>\n<td>Debrief and action assignment<\/td>\n<td>Which gaps need owners, deadlines and evidence of closure?<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The exercise should not reward participants for \u201cwinning\u201d the scenario. Its value comes from surfacing assumptions while the consequences are cheap: missing contacts, unclear authority, impossible recovery times, supplier dependencies, inaccessible documentation and communication conflicts.<\/p>\n<div class=\"mh-related\">\n<h3>Related MATSH reading<\/h3>\n<div class=\"mh-related-grid\">\n<a href=\"\/en\/business-continuity-statistics-2026\/\"><strong>Business Continuity Statistics 2026<\/strong><span>Current risk evidence on cyber incidents, business interruption, supply chains, regulation and natural catastrophes.<\/span><\/a><br \/>\n<a href=\"\/en\/strategies-for-effective-crisis-management-in-mena-family-businesses\/\"><strong>Crisis Management for MENA Family Businesses<\/strong><span>Governance and decision-making in family-enterprise disruption.<\/span><\/a><br \/>\n<a href=\"\/en\/strategies-for-managing-supply-chain-disruptions-in-african-logistics\/\"><strong>Supply Chain Resilience in Africa<\/strong><span>Continuity planning for logistics and supplier disruption.<\/span><\/a>\n<\/div>\n<\/div>\n<div class=\"mh-cta\">\n<h3>Build a plan that can survive a real test<\/h3>\n<p>MATSH&#8217;s Crisis Management and Business Continuity Course combines business impact analysis, continuity planning, crisis leadership, communications and scenario testing so teams can practise before disruption makes the decisions urgent.<\/p>\n<p><a href=\"\/en\/course\/crisis-management-business-continuity-course\/\">Explore the Crisis Management course<\/a><br \/>\n<a href=\"\/en\/register\/?course=Crisis+Management\">Register<\/a>\n<\/div>\n<h2 class=\"mh-section\">Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.iso.org\/standard\/75106.html\" target=\"_blank\" rel=\"noopener\">ISO 22301:2019, Business continuity management systems<\/a><\/li>\n<li><a href=\"https:\/\/www.iso.org\/standard\/93606.html\" target=\"_blank\" rel=\"noopener\">ISO\/CD 22301, third edition under development in 2026<\/a><\/li>\n<li><a href=\"https:\/\/www.ready.gov\/business\/emergency-plans\" target=\"_blank\" rel=\"noopener\">Ready.gov, Emergency Plans<\/a><\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/ctep-package-documents\" target=\"_blank\" rel=\"noopener\">CISA, Tabletop Exercise Package documentation<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A practical business continuity plan guide covering business impact analysis, recovery targets, dependencies, crisis roles, recovery strategies and tabletop exercises.<\/p>\n","protected":false},"author":1,"featured_media":10439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[404],"tags":[],"class_list":["post-10437","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-professional-development"],"_links":{"self":[{"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/posts\/10437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/comments?post=10437"}],"version-history":[{"count":2,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/posts\/10437\/revisions"}],"predecessor-version":[{"id":10453,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/posts\/10437\/revisions\/10453"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/media\/10439"}],"wp:attachment":[{"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/media?parent=10437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/categories?post=10437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/matsh.co\/en\/wp-json\/wp\/v2\/tags?post=10437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}