Straight answers on business continuity, resilience, regulation and how we work. If your question is not here, we are glad to talk it through.
Business continuity management is the discipline of identifying the threats that could disrupt an organisation and the impact those disruptions would have on its operations, then building the capability to keep critical activities running and to recover quickly. It gives an organisation a tested, repeatable response that protects its people, stakeholders, reputation and value creating activities. The internationally recognised standard is ISO 22301.
Effective business continuity reaches beyond your own walls to your supply chain, so that the failure of a key supplier does not become a failure of your own service.
Risk management and business continuity are complementary, and they overlap, but they answer different questions. Risk management maps threats onto a risk matrix and sets out how each one will be mitigated. Business continuity goes a step further: it identifies your critical activities, plans for them and tests them, so that when a risk actually materialises the organisation already knows exactly what to do.
In short, business continuity builds on the foundation of risk management and turns preparation into a rehearsed response.
A business continuity plan is a document. On its own it is only as good as the people and processes behind it. A business continuity management system is the living framework that establishes, operates, monitors, reviews, maintains and continually improves that capability.
A plan is the first step towards resilience. A certified management system is an ongoing commitment that touches every part of the organisation and requires visible support from senior management.
Not necessarily. Disaster recovery is how you resume operations after a disruptive event, whether that is a major incident or something localised such as a software failure or power outage. Sound disaster recovery helps you get back to business without losing too many customers or too much reputation.
Resilience is different. It is the ability to withstand disruption with little or no interruption to service in the first place. Disaster recovery is one component of resilience, not a substitute for it.
Organisational resilience is the ability of an organisation to anticipate, prepare for, respond to and adapt to incremental change and sudden disruption in order to survive and prosper. It draws together business continuity, crisis management, risk management, information and cyber security and a strong risk culture into a single coordinated capability rather than a set of isolated plans.
Yes. ISO 22301 is the internationally recognised standard for business continuity management systems. It helps organisations identify the threats relevant to their business and the critical functions those threats could affect, and to put plans in place ahead of time so the business does not come to a standstill. It applies to disruption of every kind, from extreme weather, fire and flood to IT outage, supplier failure and cyber attack.
Yes. ISO 22301 allows an organisation to gain independent, third party certification of its business continuity management system. Certification signals to customers, suppliers, employees, investors and regulators that you can manage incidents and minimise disruption.
Commercially it can also be a differentiator, giving assurance that the products and services your clients rely on will be available when they need them, and it is increasingly requested in tenders.
The two standards address different, complementary concerns. ISO 27001 is the standard for information security management, focused on protecting the confidentiality, integrity and availability of information. ISO 22301 is the standard for business continuity, focused on keeping critical operations running through disruption and recovering them quickly.
Many organisations implement both, so that information is protected and operations are able to continue. We advise on and support certification for each.
NIS2 is the European Union directive on network and information security. It significantly widens the scope of the earlier NIS directive, covering more sectors classed as essential or important, and it raises the bar on risk management, incident reporting and management accountability, backed by meaningful penalties.
If your organisation operates in a covered sector or supplies one, NIS2 is likely to be relevant, including for companies established outside the EU that provide services within it. We help organisations scope their obligations and close the gap through our consulting services.
DORA, the Digital Operational Resilience Act, is the EU regulation on operational resilience for the financial sector. It sets requirements across ICT risk management, incident reporting, resilience testing including threat led penetration testing, and the oversight of critical third party ICT providers.
It applies to a broad range of financial entities and to certain ICT service providers that support them. We help firms and their suppliers prepare.
They can. Although these are EU instruments, Swiss organisations are frequently caught through their activities in the EU, through EU based clients and group companies, or through contractual flow down from customers who are themselves in scope. Swiss financial institutions also work within FINMA expectations on operational resilience that run in parallel.
The practical answer depends on your footprint and your client base. We assess where you stand and what, if anything, you need to do.
No. The sooner recommendations are implemented the sooner you are protected, but budget and resource rarely allow everything in one step. We take a phased approach, prioritising the work by urgency and by the budget available, so that the most important gaps are closed first.
It depends on the size and complexity of the organisation. A small or medium enterprise without a dedicated internal team, working with professional support, is typically in a position to apply for certification within around 12 to 18 months. For larger, international organisations with visible senior commitment this may extend to 18 to 24 months.
No. The need to stay available matters to organisations of every size and sector. Smaller organisations may have less time, money and resource to prepare, yet the cost of an unmanaged disruption can be severe. It is far easier to build in resilience as an organisation grows than to retrofit it later. We regularly help smaller organisations raise their resilience, and an initial exploratory conversation carries no obligation.
We work with clients across Switzerland, the wider European Union and the United Arab Emirates. Our sector experience spans banking and financial services, technology and telecoms, healthcare, government, energy and critical infrastructure, manufacturing, transport and logistics, maritime, retail and hospitality, among others. See the industries we serve.
It starts with a short, confidential conversation about where you are and what you are trying to achieve, at no cost and with no obligation. From there we agree a scope, a phased plan and clear outcomes. You can book a consultation or contact us to begin.
We deliver accredited and bespoke training across business continuity, crisis management and cyber resilience, from executive briefings through to professional certification. Programmes include DRI International accredited courses, our Critical Incident Response Professional certification, crisis management masterclasses and top team exercises, and training on the 7A Risk Management Framework.
See our training programmes for the full catalogue.
Yes. Our accredited programmes are recognised by DRI International, and training is delivered by senior practitioners who advise organisations on the same disciplines in practice, including work delivered for major institutions and at large scale events. This keeps the material grounded in real engagements rather than theory alone.
A short, confidential conversation is the quickest way to understand where you stand and what a sensible next step looks like.
Book a consultation