Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Business Continuity Management Consulting, ISO 22301 | Resilience Guard
Business continuity consulting

A good plan today beats a perfect plan tomorrow.

IT failure, cyberattack, fire, flood or supplier collapse: whether operations grind to a halt or continue running depends on the effectiveness of your BCM programme. We design, build and validate programmes that hold, aligned to ISO 22301.

The service

What is business continuity consulting?

Business continuity consulting designs and implements the management programme that keeps an organisation's critical activities running through disruption: business impact analysis, continuity strategy, plans and structures, and the exercising and audit that prove they work, aligned to ISO 22301.

The foundation of any credible programme is the Business Impact Analysis: methodically identifying critical activities, assessing the impact of their disruption, setting Recovery Time Objectives, Recovery Point Objectives and the Maximum Tolerable Period of Disruption, and exposing the interdependencies across IT, supply chain and outsourcing partners that a disruption will find first.

From that foundation we build to your objective, whether that is ISO 22301 certification, reassuring regulators, satisfying client auditors or simply the confidence that the organisation can take a hit. Recognising that every client is unique, engagements are bespoke: as much or as little help as you need, from a single BIA to a complete programme built, embedded and certified.

Anchor
ISO 22301, ISO 22313
Foundation
BIA: RTO, RPO, MTPD
Objective
Certification or capability
Validation
Exercise and audit
THE PROGRAMME CYCLE, ISO 22301 ALIGNEDUnderstandBIA and risk assessmentStrategiseOptions and solutionsImplementPlans and structuresValidateExercise and auditImproveReview and matureLeadership and policyClause 5 at the centre
The continuity programme cycle: understand, strategise, implement, validate and improve, with leadership commitment at the centre, as ISO 22301 requires.
What we deliver

The programme, stage by stage

Business Impact Analysis. Critical activities identified, disruption impacts assessed, RTO, RPO and MTPD set, and interdependencies across systems, suppliers and partners exposed.
Risk assessment. The threats most likely to interrupt critical activities, evaluated for likelihood and consequence and connected to the wider risk management picture.
Continuity strategy. Recovery options selected and resourced: people, premises, technology, information and suppliers, sized to the recovery objectives the BIA established.
Plans and structures. The business continuity plan set, response structures and activation logic, written for the person using them mid incident. See our guidance on the business continuity plan.
Validation and improvement. Exercising through our exercise formats and independent review through business continuity audit, closing the loop into continual improvement and, where wanted, ISO 22301 certification.
Questions

Frequently asked questions

What is a Business Impact Analysis?+

A BIA methodically identifies your critical activities, assesses the impact of their disruption over time, sets recovery objectives such as RTO, RPO and the Maximum Tolerable Period of Disruption, and exposes interdependencies across IT, supply chain and partners. It is the foundation every credible continuity plan is built on.

Do we need ISO 22301 certification?+

Not always, but you need the capability it describes. Certification is valuable where regulators, clients or tenders demand demonstrable continuity; elsewhere an ISO 22301 aligned programme without the certificate can be the proportionate choice. We help you decide, then build to that objective.

How long does a BCM programme take to build?+

A focused BIA takes weeks; a complete programme from analysis to exercised plans typically runs a few months depending on size and complexity. We scope engagements so value lands early: critical activities protected first, refinement after.

How does business continuity relate to NIS2, DORA and the Swiss ISG?+

All three treat continuity as a legal expectation: NIS2 Article 21 names business continuity among its mandatory measures, DORA requires tested ICT continuity and recovery plans, and Swiss critical infrastructure operators need continuity capability behind the ISG's reporting duties.

How is the programme kept alive after delivery?+

Through the validation cycle: planned exercises, audit at intervals, and review after significant change. Our exercise programmes and BCLE 2000 training keep the capability in your people, not on a shelf.

Explore further

Related services

Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Find out whether your operations would hold.

Start with a Business Impact Analysis or a programme review; we will show you exactly where you stand against ISO 22301.

Book a consultation
All consultations are treated with strict confidentiality.