Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Resilience Glossary: 35 Terms Defined | Resilience Guard
Home  ›  Insights  ›  Glossary
The language of the discipline

The resilience glossary

The 35 terms that carry the discipline, defined in plain language, from BIA and RTO to NIS2, DORA and the Swiss ISG.

Practitioner led since 2014 Led by John Zeppos, Founder and Group Managing Director DRI Accredited training provider Three BCI Global Awards 16+ EU Horizon research projects Trusted to train 3 of the Big Four

Precision of language is precision of thought. These are the terms Resilience Guard uses with clients, boards and auditors, defined the way we mean them: short, exact and free of vendor mystique.

Business continuity (BC)

The capability of an organisation to continue delivering its critical products and services at acceptable predefined levels following a disruption.

Business continuity management (BCM)

The management discipline of identifying threats to an organisation, understanding their impact on critical activities, and building a rehearsed capability to keep those activities running and recover quickly. See the full guide on our business continuity management page.

Business continuity management system (BCMS)

The formal, auditable framework that establishes, operates, monitors, reviews, maintains and continually improves business continuity across an organisation. A BCMS can be certified against ISO 22301.

Business continuity plan (BCP)

The documented, rehearsed set of procedures that keeps an organisation's critical activities running during a disruption and recovers them within defined timeframes. See our BCP guide.

Business impact analysis (BIA)

The process of identifying an organisation's critical activities, the resources they depend on, and the impact of their interruption over time, producing recovery priorities and objectives.

CER Directive and KRITIS

Directive (EU) 2022/2557 on the resilience of critical entities, applying since 18 October 2024, and Germany's related KRITIS regime: all hazards resilience duties for critical entities across eleven sectors.

Crisis exercise

A structured rehearsal of an organisation's response to a realistic scenario, producing a recorded timeline, findings and corrective actions. See crisis exercising.

Crisis management

The leadership discipline of directing an organisation through a disruptive event: assessment, decision making, communication and coordination under pressure, with clear authority and one log.

Critical ICT third party provider (CTPP)

An ICT service provider designated as critical to the EU financial sector under DORA and placed under the direct oversight of a Lead Overseer from the European Supervisory Authorities; financial entities must manage the concentration risk such providers represent.

Critical infrastructure

Assets, systems and services whose disruption would have significant impact on society, the economy or public safety, and which regulation increasingly names and obliges directly.

Cyber resilience

An organisation's ability to keep operating and to lead through a cyber attack: technical response, business continuity and crisis management working as one rehearsed system. See cyber resilience.

Disaster recovery (DR) and IT disaster recovery (ITDR)

The restoration of IT systems, applications and data after disruption, usually to defined recovery time and recovery point objectives; one component of business continuity, not a synonym for it.

DORA

The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, applying since 17 January 2025: ICT risk management, incident reporting, resilience testing and oversight of critical ICT providers for financial entities.

Essential and important entities

The two classes of organisation regulated by NIS2 across its annex sectors, set chiefly by size and sector: essential entities face proactive supervision, important entities ex post supervision, with broadly the same duty set applying to both.

ICT risk management framework

The documented framework DORA requires of financial entities: strategies, policies, protocols and tools covering identification, protection, detection, response, recovery, learning and communication for ICT risk, approved and owned by the management body.

Impact tolerance

The maximum level of disruption to an important service an organisation is prepared to accept, expressed as a defined limit such as duration or volume, set consciously by leadership.

Incident response

The organised approach to detecting, containing and resolving a disruptive event in its earliest phase, before or alongside invocation of continuity and crisis arrangements.

ISG (Swiss Information Security Act)

The Swiss federal Information Security Act (SR 128), in force since 1 January 2024, with a 24 hour duty to report significant cyber attacks on critical infrastructure to BACS since 1 April 2025 and sanctions since 1 October 2025. See our German language guide.

ISO 22301

The international standard for business continuity management systems: the certifiable framework covering leadership, business impact analysis, plans, exercising, audit and continual improvement.

ISO 27001

The international standard for information security management systems, covering the governance, risk treatment and controls that protect information assets; increasingly integrated with ISO 22301 in one management system.

Major ICT related incident (DORA)

An ICT incident meeting DORA's classification thresholds, triggering the regulation's reporting sequence to the competent authority: initial notification, intermediate report and final report within the deadlines set by the technical standards.

Management accountability (NIS2)

NIS2's explicit placement of cybersecurity duty on management bodies: they must approve and oversee risk management measures, undergo training, and can be held personally liable for infringements.

Maximum tolerable period of disruption (MTPD)

The time after which the viability of an organisation would be irreparably threatened if delivery of a product, service or activity is not resumed.

Minimum business continuity objective (MBCO)

The minimum level of a product, service or activity that an organisation commits to deliver during a disruption, agreed in advance rather than improvised.

NIS2

Directive (EU) 2022/2555 on cybersecurity across the Union, with national transposition due by 17 October 2024: risk management, continuity, incident reporting and management accountability for essential and important entities.

Operational resilience

The ability of an organisation to anticipate, prevent, withstand, respond to, recover from and adapt to disruption so its critical services continue within set tolerances. See our definition page.

Part-IS

The EU aviation information security regime: Delegated Regulation (EU) 2022/1645 applying from 16 October 2025 and Implementing Regulation (EU) 2023/203 from 22 February 2026, requiring information security management across aviation organisations and authorities.

Recovery point objective (RPO)

The maximum tolerable amount of data loss measured in time: the point to which data must be restored after an incident.

Recovery time objective (RTO)

The target time within which a product, service, activity or system must be resumed after a disruption.

Register of information (DORA)

The register DORA requires financial entities to maintain of all contractual arrangements with ICT third party providers, at entity, sub consolidated and consolidated level, available to the competent authority on request.

Risk assessment

The systematic identification, analysis and evaluation of risks to an organisation's critical activities, informing which threats are reduced, transferred, accepted or planned against.

Significant incident (NIS2)

An incident meeting NIS2's significance criteria, starting the directive's reporting clock: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month to the CSIRT or competent authority.

Single point of failure (SPOF)

Any resource, person, system, site or supplier, whose failure alone would interrupt a critical activity because no alternative exists; the honest output of a good dependency analysis.

Third party risk

The exposure an organisation inherits from suppliers and service providers whose failure or compromise would disrupt its own critical activities; a named focus of DORA, NIS2 and supervisory regimes.

Threat led penetration testing (TLPT)

Advanced testing under DORA for designated financial entities: intelligence led attacks on live production systems, based on the TIBER-EU framework, at least every three years, with findings feeding the ICT risk framework.

No term matches that filter. Try a shorter fragment, or ask us directly.

Start the conversation

When the vocabulary becomes a programme.

Definitions are the start; capability is the point. Talk to a practitioner about where you are. We respond within 24 hours.

Book a consultation
All consultations are treated with strict confidentiality.