IT failure, cyberattack, fire, flood or supplier collapse: whether operations grind to a halt or continue running depends on the effectiveness of your BCM programme. We design, build and validate programmes that hold, aligned to ISO 22301.
Business continuity consulting designs and implements the management programme that keeps an organisation's critical activities running through disruption: business impact analysis, continuity strategy, plans and structures, and the exercising and audit that prove they work, aligned to ISO 22301.
The foundation of any credible programme is the Business Impact Analysis: methodically identifying critical activities, assessing the impact of their disruption, setting Recovery Time Objectives, Recovery Point Objectives and the Maximum Tolerable Period of Disruption, and exposing the interdependencies across IT, supply chain and outsourcing partners that a disruption will find first.
From that foundation we build to your objective, whether that is ISO 22301 certification, reassuring regulators, satisfying client auditors or simply the confidence that the organisation can take a hit. Recognising that every client is unique, engagements are bespoke: as much or as little help as you need, from a single BIA to a complete programme built, embedded and certified.
A BIA methodically identifies your critical activities, assesses the impact of their disruption over time, sets recovery objectives such as RTO, RPO and the Maximum Tolerable Period of Disruption, and exposes interdependencies across IT, supply chain and partners. It is the foundation every credible continuity plan is built on.
Not always, but you need the capability it describes. Certification is valuable where regulators, clients or tenders demand demonstrable continuity; elsewhere an ISO 22301 aligned programme without the certificate can be the proportionate choice. We help you decide, then build to that objective.
A focused BIA takes weeks; a complete programme from analysis to exercised plans typically runs a few months depending on size and complexity. We scope engagements so value lands early: critical activities protected first, refinement after.
All three treat continuity as a legal expectation: NIS2 Article 21 names business continuity among its mandatory measures, DORA requires tested ICT continuity and recovery plans, and Swiss critical infrastructure operators need continuity capability behind the ISG's reporting duties.
Through the validation cycle: planned exercises, audit at intervals, and review after significant change. Our exercise programmes and BCLE 2000 training keep the capability in your people, not on a shelf.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Start with a Business Impact Analysis or a programme review; we will show you exactly where you stand against ISO 22301.
Book a consultation