The 35 terms that carry the discipline, defined in plain language, from BIA and RTO to NIS2, DORA and the Swiss ISG.
Precision of language is precision of thought. These are the terms Resilience Guard uses with clients, boards and auditors, defined the way we mean them: short, exact and free of vendor mystique.
The capability of an organisation to continue delivering its critical products and services at acceptable predefined levels following a disruption.
The management discipline of identifying threats to an organisation, understanding their impact on critical activities, and building a rehearsed capability to keep those activities running and recover quickly. See the full guide on our business continuity management page.
The formal, auditable framework that establishes, operates, monitors, reviews, maintains and continually improves business continuity across an organisation. A BCMS can be certified against ISO 22301.
The documented, rehearsed set of procedures that keeps an organisation's critical activities running during a disruption and recovers them within defined timeframes. See our BCP guide.
The process of identifying an organisation's critical activities, the resources they depend on, and the impact of their interruption over time, producing recovery priorities and objectives.
Directive (EU) 2022/2557 on the resilience of critical entities, applying since 18 October 2024, and Germany's related KRITIS regime: all hazards resilience duties for critical entities across eleven sectors.
A structured rehearsal of an organisation's response to a realistic scenario, producing a recorded timeline, findings and corrective actions. See crisis exercising.
The leadership discipline of directing an organisation through a disruptive event: assessment, decision making, communication and coordination under pressure, with clear authority and one log.
An ICT service provider designated as critical to the EU financial sector under DORA and placed under the direct oversight of a Lead Overseer from the European Supervisory Authorities; financial entities must manage the concentration risk such providers represent.
Assets, systems and services whose disruption would have significant impact on society, the economy or public safety, and which regulation increasingly names and obliges directly.
An organisation's ability to keep operating and to lead through a cyber attack: technical response, business continuity and crisis management working as one rehearsed system. See cyber resilience.
The restoration of IT systems, applications and data after disruption, usually to defined recovery time and recovery point objectives; one component of business continuity, not a synonym for it.
The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, applying since 17 January 2025: ICT risk management, incident reporting, resilience testing and oversight of critical ICT providers for financial entities.
The two classes of organisation regulated by NIS2 across its annex sectors, set chiefly by size and sector: essential entities face proactive supervision, important entities ex post supervision, with broadly the same duty set applying to both.
The documented framework DORA requires of financial entities: strategies, policies, protocols and tools covering identification, protection, detection, response, recovery, learning and communication for ICT risk, approved and owned by the management body.
The maximum level of disruption to an important service an organisation is prepared to accept, expressed as a defined limit such as duration or volume, set consciously by leadership.
The organised approach to detecting, containing and resolving a disruptive event in its earliest phase, before or alongside invocation of continuity and crisis arrangements.
The Swiss federal Information Security Act (SR 128), in force since 1 January 2024, with a 24 hour duty to report significant cyber attacks on critical infrastructure to BACS since 1 April 2025 and sanctions since 1 October 2025. See our German language guide.
The international standard for business continuity management systems: the certifiable framework covering leadership, business impact analysis, plans, exercising, audit and continual improvement.
The international standard for information security management systems, covering the governance, risk treatment and controls that protect information assets; increasingly integrated with ISO 22301 in one management system.
An ICT incident meeting DORA's classification thresholds, triggering the regulation's reporting sequence to the competent authority: initial notification, intermediate report and final report within the deadlines set by the technical standards.
NIS2's explicit placement of cybersecurity duty on management bodies: they must approve and oversee risk management measures, undergo training, and can be held personally liable for infringements.
The time after which the viability of an organisation would be irreparably threatened if delivery of a product, service or activity is not resumed.
The minimum level of a product, service or activity that an organisation commits to deliver during a disruption, agreed in advance rather than improvised.
Directive (EU) 2022/2555 on cybersecurity across the Union, with national transposition due by 17 October 2024: risk management, continuity, incident reporting and management accountability for essential and important entities.
The ability of an organisation to anticipate, prevent, withstand, respond to, recover from and adapt to disruption so its critical services continue within set tolerances. See our definition page.
The EU aviation information security regime: Delegated Regulation (EU) 2022/1645 applying from 16 October 2025 and Implementing Regulation (EU) 2023/203 from 22 February 2026, requiring information security management across aviation organisations and authorities.
The maximum tolerable amount of data loss measured in time: the point to which data must be restored after an incident.
The target time within which a product, service, activity or system must be resumed after a disruption.
The register DORA requires financial entities to maintain of all contractual arrangements with ICT third party providers, at entity, sub consolidated and consolidated level, available to the competent authority on request.
The systematic identification, analysis and evaluation of risks to an organisation's critical activities, informing which threats are reduced, transferred, accepted or planned against.
An incident meeting NIS2's significance criteria, starting the directive's reporting clock: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month to the CSIRT or competent authority.
Any resource, person, system, site or supplier, whose failure alone would interrupt a critical activity because no alternative exists; the honest output of a good dependency analysis.
The exposure an organisation inherits from suppliers and service providers whose failure or compromise would disrupt its own critical activities; a named focus of DORA, NIS2 and supervisory regimes.
Advanced testing under DORA for designated financial entities: intelligence led attacks on live production systems, based on the TIBER-EU framework, at least every three years, with findings feeding the ICT risk framework.
No term matches that filter. Try a shorter fragment, or ask us directly.
Definitions are the start; capability is the point. Talk to a practitioner about where you are. We respond within 24 hours.
Book a consultation