Skip to content

Home Expertise / Response & resilience

RES / RES-03

Business impact analysis, continuity and disaster recovery planning

Determine which activities must recover first and prepare continuity or restoration. Business continuity planning covers business operations; disaster recovery planning describes restoration of the supporting information systems.

WHEN IT HELPS

A focused response
to a defined need.

Leadership uncertain about recovery priorities, customer requirements, new critical services or dependence on a few applications without documented alternatives.

AT A GLANCE

Family
Response & resilience

Engagement
Project or assistance

Reference
RES-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Business workshops
  • interruption impacts
  • dependencies
  • RTO/RPO objectives
  • degraded operations
  • resources
  • recovery sequence
  • procedures
  • responsibilities
  • testing strategy

Deliverables

  • BIA
  • dependency map
  • approved objectives
  • continuity/DR plans
  • recovery guides
  • capability-gap analysis
  • exercise and investment plan

Acceptance evidence

Business priorities are approved; RTO/RPO are defined as targets; dependencies are identified; procedures have owners; gaps between targets and tested capability are explicit.

DELIVERY

How the work is structured.

Approach

Define objectives and ownership; prepare scenarios and resources; perform authorised response or exercise; document evidence; improve and revise.

Prerequisites & responsibilities

Customer: decision-makers, operations, business owners, legal/insurer where required, permissions and recovery resources. Provider: contracted expertise with evidence preservation.

Scope factors

Criticality, scope, investigation depth, data volume, dependencies, scenarios and mobilisation terms. Preparation, response, rebuilding and licensing are separate.

Questions to clarify

How long can each activity be interrupted? What data loss is acceptable? Can current resources actually meet those objectives?

IMPORTANT BOUNDARIES

An untested document does not prove recovery capability. Objectives require resources, available dependencies and business validation during exercises.

Recovery and investigation have limits; no total recovery or absolute resolution-time promise. Exercise results remain specific to the tested scenario.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company wants everything restored first. Project: link applications, sales and production to establish priorities. Target outcome: leadership-approved recovery order and degraded operations for lower-priority activities.

Scenario 02

An organisation demands a very short RPO without suitable backups. Project: measure the gap and propose architecture options. Target outcome: a documented investment-versus-risk decision rather than presenting the target as already achieved.

Technology and reference context

References: NIST risk and recovery practices; backup and continuity architectures tailored to selected applications.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.