Introduction
In the first post of this series, I introduced the Assume Breach principle. I also highlighted three areas that often need more attention: Business Continuity Planning, Data Loss Prevention and Cryptography.
This post focuses on Business Continuity Planning (BCP).
Many organisations have a continuity plan on paper. They may have a policy, a list of key systems and a recovery plan. But documents alone do not keep a business running. The plan must work during a real crisis.
Executive summary
- A continuity plan must work during a cyberattack, not only after a power cut or office closure.
- Fast recovery is not enough. Recovery must also be secure.
- Leaders must set priorities and decision-making authority before a crisis.
- Technical teams must know which systems, accounts, suppliers and data each service needs.
- Plans and backups must be tested under realistic conditions.
From “if” disruption happens to “when” disruption happens
Traditional plans often cover office closures, power cuts, natural disasters and supplier failure. These risks still matter. But modern plans must also cover cyberattacks.
Ransomware may lock key systems. A cloud service may fail. An attacker may take control of an administrator account. Data may be damaged or stolen. Even the identity service used to sign in may be unavailable.
Assume Breach starts from the possibility that systems are already compromised. The organisation must recover quickly without bringing the attacker back. The goal is not only availability. The goal is resilience.
What business leaders need to decide
Leaders must decide what matters most before an incident occurs. Not every service needs to recover at the same time.
For each key service, decide:
- How long can the business operate without it?
- What is the minimum service the business must provide?
- Can staff run it manually for a short time?
- Which services must recover first?
- Who can make urgent decisions?
- How will the organisation communicate if normal channels fail?
These choices guide both management and technical teams. They also reduce delays when pressure is high.
What technical teams need to prepare
Recovery Time Objectives and Recovery Point Objectives are still important. They define how soon a service must return and how much data the business can lose.
However, speed is only part of recovery. Teams must understand what each service needs. This may include accounts, networks, certificates, data, suppliers and cloud platforms.
Before restoring a service, verify:
- Which systems were affected.
- Whether backups are intact.
- Whether accounts can still be trusted.
- Whether data was changed.
- Whether the original weakness has been fixed.
- Whether the recovery environment is clean and isolated.
Restoring an infected system may restart the attack. Recovery must therefore be secure as well as fast.
How BCP supports ISO 27001
Information security still matters during a crisis. ISO 27001 reinforces this through two Annex A controls:
- A.5.29: Information security during disruption.
- A.5.30: ICT readiness for business continuity.
These controls connect continuity planning with information security. The organisation must protect the confidentiality, integrity and availability of information, even during disruption.
BCP therefore belongs in the Information Security Management System. It must link to risk, incident response, suppliers, access control, backups, crisis communication and management review.
Five common weaknesses
1. Plans are too vague
Broad instructions do not help people make urgent decisions. Plans need clear actions, owners and contact details.
2. Tests are too limited
A tabletop exercise every few years is not enough for a key service. Tests should include cyberattacks, unavailable systems, missing staff and recovery from isolated backups.
3. Dependencies are unclear
A key application may depend on an identity service, network, supplier or certificate. Missing one of these links can block recovery.
4. Backups are trusted without proof
Backups help only when they are protected and tested. Keep them separate, monitor them and protect them from deletion or change.
5. Nobody knows who decides
Business owners, technical teams, legal advisers and management must work together. Clear roles and authority save time.
Connect continuity and incident response
Incident response teams find, contain and remove the threat. BCP keeps key services running or restores them. The two teams must work together.
Prepare fallback processes that do not rely on affected systems. Set up a separate communication channel and emergency access process. Keep the recovery environment away from the compromised network.
This joined approach prevents two bad outcomes: recovering too slowly and recovering into another attack.
The business value
A mature BCP does more than meet an audit requirement. It limits downtime and financial loss. It protects customer trust and helps the organisation meet legal, regulatory and contractual duties.
Cyber incidents quickly become business incidents. They can affect customer service, cash flow, operations and reputation. BCP gives leaders and technical teams a shared plan for managing that impact.
Conclusion
Business Continuity Planning is not just documentation. It is the ability to keep key services running during a crisis and restore them safely.
The strength of a plan is not proven during an audit. It is proven during disruption. Organisations that prepare for that moment recover faster, make better decisions and reduce the total impact of an incident.
