Infographic titled “Business Continuity Plan (BCP)” with the subtitle “Prepare. Continue. Recover.” It explains why BCP matters: minimising impact, staying resilient, protecting trust and meeting ISO 27001 requirements. The infographic shows a five-step BCP lifecycle: understand, plan, prepare, respond and recover. It also highlights key BCP elements such as business impact analysis, roles and responsibilities, dependencies and resources, data and backup strategy, communication planning, and testing and training. The final section connects BCP to an Assume Breach approach, focusing on compromised systems, immutable backups, verified recovery and secure recovery environments, leading to stronger resilience, lower impact, faster detection, secure recovery and reduced costs.

Assume Breach: Why Business Continuity Planning Must Be Than a Document

Introduction In the first post of this series, I introduced the Assume Breach principle. I also highlighted three areas that often need more attention: Business Continuity Planning, Data Loss Prevention and Cryptography. This post focuses on Business Continuity Planning (BCP). Many organisations have a continuity plan on paper. They may have a policy, a list of key systems and a recovery plan. But documents alone do not keep a business running. The plan must work during a real crisis. ...

25 July 2026 · 4 min · 845 words · Arnold
Image depicting the flow from BCP, DLP & Cryptography through the ISO 27001 alignment into the result: Reduced impact, faster detection & response and greater operational resilience

Assume Breach: Strengthening Security with BCP and DLP

Introduction In the past year, I have performed numerous internal audits. Across many of these audits, I observed a recurring pattern: three important security domains are often either limited in scope or insufficiently implemented: Business Continuity Planning Data Loss Prevention Cryptography In most cases, an initial effort has been made. However, the actual coverage, maturity and operational effectiveness of these implementations are often lacking. In my view, these controls do not always receive the level of attention and organisational weight they deserve. ...

25 May 2026 · 4 min · 823 words · Arnold