The Cyber Academy take
BCM is the discipline that identifies threats to your critical operations, then designs the plans and procedures to keep them running through disruption. Not a one-off project. The BCM team that delivers under a real incident is the one that ran a tabletop exercise four months ago and wrote down what failed.
What business continuity management actually covers
Business continuity management is the management discipline that keeps an organisation's most important activities running, or running again quickly, when something goes wrong. The trigger can be a cyber incident, a supplier collapse, a flood, a power loss or a pandemic. The threat does not need to be predicted by name. What matters is that the activity it would knock out has been identified, prioritised and given a tested plan to recover within an acceptable window.
The scope is deliberately broad. BCM looks at people, premises, technology, suppliers and information, not just the IT estate. That is the first thing that distinguishes it from disaster recovery, which is the IT-focused subset concerned with restoring infrastructure, applications and data. A bank can restore every server and still fail to operate because the call centre has nowhere to sit and the third party that prices its trades is offline. BCM owns that whole picture.
It is also a continuous cycle, not a project with an end date. Plans drift out of date the moment an organisation reorganises, adopts a new system or onboards a new critical supplier. The teams that perform under a real incident are the ones that rehearsed a scenario recently and captured what broke, then fixed it before the next round.
The core BCM lifecycle
Most programmes follow a recognisable sequence, mirrored in the international standard ISO 22301:
- Business impact analysis. The structured study that ranks each activity by how badly disruption hurts over time and produces the recovery objectives.
- Risk assessment. Identifying the threats and vulnerabilities most likely to disrupt the prioritised activities.
- Strategy and solutions. Choosing how to keep activities running or recover them: alternate sites, workarounds, redundancy, supplier diversification.
- Plans and procedures. Writing the business continuity plan, incident response structure and recovery runbooks people will actually use under stress.
- Exercising and review. Tabletop and live tests, post-incident reviews and audits that feed corrections back into the cycle.
Where BCM sits in the regulatory landscape
Continuity has moved from good practice to supervised obligation in several sectors. ISO 22301 specifies the requirements for a certifiable business continuity management system and is the reference most organisations align to. In the European Union, the Digital Operational Resilience Act sets continuity and testing expectations for financial entities, and the NIS 2 Directive requires business continuity measures, including backup and crisis management, from operators in essential and important sectors.
Certification is not mandatory to do BCM well, but it gives auditors, regulators and large customers a recognised baseline. Whether or not a programme seeks a certificate, the same disciplines apply: know your critical activities, set defensible recovery objectives, write usable plans and prove they work by testing them.
Frequently asked questions
01What is the difference between business continuity and disaster recovery?
Disaster recovery is the IT-focused subset of business continuity that restores infrastructure, applications and data. Business continuity is broader: it covers people, premises, suppliers and processes as well as technology, so the whole organisation can keep operating.
02Is ISO 22301 certification required for business continuity management?
No. ISO 22301 is the international standard you can certify a business continuity management system against, but doing BCM well does not require a certificate. Certification gives regulators and customers a recognised baseline and is increasingly expected in regulated sectors.
03Where do RTO and RPO come from in a BCM programme?
They are outputs of the business impact analysis. The RTO is the longest a process can be down before unacceptable harm, and the RPO is the maximum tolerable data loss measured in time. Both should be validated by the business owners, not set by IT alone.
04How often should business continuity plans be tested?
Test regularly rather than annually. Tabletop exercises are cheap and fast and expose gaps that document reviews miss, so many programmes run them quarterly and supplement them with periodic live recovery tests.
05Who should own business continuity management in an organisation?
Accountability sits with senior management because continuity decisions are business decisions about acceptable downtime and investment. A coordinator or BCM lead runs the lifecycle, but each critical activity needs an owner who validates its recovery objectives and plan.