• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

About Us | Articles | Free Resources | Podcast | YouTube Channel

Contact Us Subscribe

Bryghtpath

Business Continuity and Crisis Management Consultants

  • Start
        • Start your Resilience Journey

          Moving your organization – or your career – forward on your resilience journey can be a difficult and scary proposition.  Often, we find that prospective clients aren’t quite sure where to start.

          To help you along your journey, we’ve outlined below four curated collections geared towards momentum-building action and advice perfectly paired with your organization’s current stage of resilience.

        • I want to learn more about Resilience

        • We’re just getting started with our resilience program

        • We’re seeking to optimize & mature our resilience program

        • I’m a Resilience Professional seeking to further develop my skills

  • Company
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
  • Courses & Training
        • Courses & Training

          We’ve created a number of free and premium courses that have helped thousands improve their skills, build more resilient organizations, and lead through organizations through difficult critical moments successfully.

        • Coaching
          • 1-on-1 Coaching Call
          • Private Backchannel
          • Private Coaching Program
        • Free Intro Courses
          • Overview
          • Business Continuity 101
          • Crisis Communications 101
          • Crisis Management 101
        • Premium Courses
          • Overview
          • Custom Training
          • 5-Day Business Continuity Accelerator
          • Communicating in the Critical Moment
          • Crisis Management Academy®️
          • Preparing for Careers in Resilience
  • Expertise
        • Our Expertise
        • Here at Bryghtpath, in our core values, we state that we are humbly confident in our resiliency expertise.

          We write, publish, speak, and train others constantly – striving to share our thought leadership publicly to advance our industry and exercise our curiosity by interacting with other leaders in our practice domains.

        • Ultimate Guide to Business Continuity

        • Ultimate Guide to Crisis Management

        • Case Studies & Results

        • Free Resources & Frameworks
          • Overview - Free Resources
          • Bryghtpath Frameworks
            • Bryghtpath Business Continuity Lifecycle
            • Bryghtpath Crisis Management Framework
            • Bryghtpath Exercise Maturity Model
            • Bryghtpath Global Security Framework
            • Bryghtpath Long-Term Recovery Framework
            • Bryghtpath Professional Reading List
            • Bryghtpath Workplace Violence & Threat Management Toolkit
          • Resiliency Professionals Facebook Group
          • Resource Library
          • Webinars & Videos
          • Whitepapers & Reports
        • Our Thoughts & Insights
          • Articles
          • Lead Through Disruption. Stay Ahead with Bryghtpath.
          • Managing Uncertainty Podcast
          • Media & Professional Appearances
          • YouTube Channel
        • Whitepapers & Reports
          • Global Security Operations Centers & Resilience
          • Managing the Whole Crisis: The Ransomware Challenge
          • Mastering Uncertainty: Strengthening Organizational Resilience
          • Social Activism Campaigns
          • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
        • Our Industry Expertise

          Bryghtpath has extensive experience in a number of industries working with clients of all sizes, geographical locations, and business models. As a team, we possess, deep global operating experience on every continent around the world.

        • Industries Overview

        • Case Studies

        • Start your Journey

        • Education

          Education Icon
        • Finance

          Financial Services 800x800
        • Government

          Government Icon
        • Healthcare

          Healthcare Icon 800x800
        • Hospitality & Leisure

          Hospitality & Leisure Industry Icon 800x800
        • Life Sciences

          Life Sciences 800x800
        • Logistics

          Transportation & Logistics Industry Icon 800x800
        • Manufacturing

          Manufacturing Industry Icon 800x800
        • Non-Profits

          Non-Profit Industry Icon 800x800
        • Retail

          Retail Industry Icon 800x800
        • Tech & Media

          Communications Industry Icon 800x800
        • Utilities

          Power & Utilities Icon
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • Start
  • Company
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
  • Courses & Training
    • Coaching
      • 1-on-1 Coaching Call
      • Private Backchannel
      • Private Coaching Program
    • Free Intro Courses
      • Overview
      • Business Continuity 101
      • Crisis Communications 101
      • Crisis Management 101
    • Premium Courses
      • Overview
      • Custom Training
      • 5-Day Business Continuity Accelerator
      • Communicating in the Critical Moment
      • Crisis Management Academy®️
      • Preparing for Careers in Resilience
  • Expertise
    • Our Expertise
    • Our Thoughts & Insights
      • Articles
      • Lead Through Disruption. Stay Ahead with Bryghtpath.
      • Managing Uncertainty Podcast
      • Media & Professional Appearances
      • YouTube Channel
    • Free Resources & Frameworks
      • Overview – Free Resources
      • Bryghtpath Frameworks
        • Bryghtpath Business Continuity Lifecycle
        • Bryghtpath Crisis Management Framework
        • Bryghtpath Exercise Maturity Model
        • Bryghtpath Global Security Framework
        • Bryghtpath Long-Term Recovery Framework
        • Bryghtpath Professional Reading List
        • Bryghtpath Workplace Violence & Threat Management Toolkit
      • Resiliency Professionals Facebook Group
      • Resource Library
      • Webinars & Videos
      • Whitepapers & Reports
    • Whitepapers & Reports
      • Global Security Operations Centers & Resilience
      • Managing the Whole Crisis: The Ransomware Challenge
      • Mastering Uncertainty: Strengthening Organizational Resilience
      • Social Activism Campaigns
      • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

What is Business Continuity?

You are here: Home / Business Continuity / What is Business Continuity?

November 8, 2022 By //  by Bryan Strawser

As your company’s newly assigned head of global security, you’ve just been informed that running your organization’s business continuity program falls squarely within your role. But what is business continuity?

Sure, you’re a battle-tested veteran in managing security for large-scale enterprises. Business continuity? Not so much. The revelation leaves you feeling a lot like that time you signed your kid up for pee-wee soccer and somehow ended up as the team coach. But now the stakes are astronomically higher.

You need to quickly move on from “how did we get here” to “now what?”

If you’re a newly minted business continuity program owner who doesn’t know the first thing about business continuity and is wondering, “where should I start,” you’re far from alone in your experience. Here, we unpack the basics so you can take the reins of your organization’s business continuity program with clarity and confidence.

What is Business Continuity, and Why Does it Matter?

There are many misconceptions out there about what makes up business continuity—a software subscription, an IT disaster recovery plan, checking the boxes on an off-the-shelf template. While these are all inarguably important parts of a business continuity program, these exercises will do little to build your organization’s resilience in isolation.

That’s because organizational resilience is the sum of many pieces, parts, people, and processes that are continually evolving and changing. Those pieces and parts require coordination, refinement, and improvement over time. That’s why we like to think of business continuity as the discipline of making your organization more resilient or able to solve big problems—and your business continuity program as the means by which you embed this discipline into your organization to build your capacity to prevent, withstand, and recover from unplanned disasters and adverse events.

Your business continuity program ensures that in the face of today’s inevitable disruptions, you can continue operations and protect your most important assets, especially your people. Importantly, organizational resilience isn’t just about surviving but building a competitive advantage in the ability to quickly pivot and respond to the unplanned.

These strategies are part of the approach that we use in our 5-Day Business Continuity Accelerator course where we aim to improve the perception of your business continuity program within your organization.

We’ll help you answer the key question: “What is Business Continuity?” and more.

We offer our 5-Day Business Continuity Accelerator quarterly.

Learn more and get on the waiting list >>

The Key Pillars of Business Continuity

While resilience means something different for every organization—every business has different experiences, threats, and resources—there are a few key pillars that we consider essential to every business continuity program. We take each in turn below.

1.   Business Continuity

A strong business continuity program is the backbone of every organization’s resilience efforts.

We think of business continuity as the process of planning for a disruption to a critical business team or capability, such as human resources, contact centers, manufacturing facilities, or the like.

As part of this process, your business needs to assess the most likely potential disruptions and their impacts, create business continuity plans to guide your response to those specific disruptions, and then train, exercise, and improve upon those plans over time. Potential disruptions can range from cyberattacks, fires, natural disasters, or power outages to terrorism and active shooter threats.

2.   Crisis Management

Where business continuity is the discipline of planning for disruptions, crisis management is devoted to developing the processes for actually managing those disruptions when they occur—who does what, at what time, and in what order.  It includes a diverse range of pre-planned strategies that help an organization deal with an unexpected adverse event that might otherwise cause significant damage.

Sometimes because of the way companies have structured things, they might think of crisis management as a component of their business continuity program, while others think of business continuity as a component of a crisis management program. It doesn’t really matter so long as the capabilities for both planning (what we call business continuity) and actually managing a disruption (what we call crisis management) are in place.

3.   IT Disaster Recovery

The last key pillar of business continuity is IT disaster recovery—the plans, strategies, and solutions that ensure your critical technology platforms are available to your business teams. This includes having an understanding of critical system requirements, such as availability, maximum acceptable downtime or recovery time objectives (RTO), and recovery point objectives (RPO), and ensuring that you have a plan to meet those objectives in the event of an IT disaster incident.  Ideally, IT will own the IT disaster recovery process, but with coordination and input from the organization’s business continuity and crisis management program.

Bryghtpath-Organizational-Resilience What is Business Continuity?

Business Continuity Roles and Responsibilities

Good business continuity governance—i.e., having the right people, policies, and practices in place to direct and control your business continuity and crisis management program—is critical to business continuity program success on many fronts. Not only is it an ISO 22301 compliance requirement, but it also helps build visibility and awareness for your program, builds accountability, and assists in identifying and closing program gaps.

Good governance starts with carefully defining program roles and responsibilities and ensuring you have the right people in each role. These are some of the fundamental roles and responsibilities typical in most organizations.

Board of Directors: Your board has a fiduciary duty to exercise strategic-level visibility and oversight over business continuity and crisis management. They can also be instrumental in helping to promote a culture of resilience. Specific board oversight and strategic level visibility are typically delegated to the board’s Risk or Audit Committee.

Executive Management: Each member of the executive team retains ultimate oversight and responsibility for crisis management & business continuity planning in their specific area of operations. One or two people at this level should also act as an Executive Sponsor, with direct oversight of and advocacy on behalf of the crisis management & business continuity program.

Steering Committee Members: The steering committee—usually an interdisciplinary team of six to eight people—meets quarterly or annually to ensure the program is aligned with corporate strategy and objectives and is maturing and making forward progress towards annual goals.

Business Continuity & Crisis Management Program Manager: The program manager has direct oversight and responsibility for business continuity & crisis management program operations, reporting, and execution. The program manager exercises direct oversight over.

Business Continuity Team Members who conduct the day-to-day business continuity and crisis management activities.

Business Continuity Plan Owners: Each business unit is responsible for creating and exercising responsibility over their respective business continuity plan under the guidance of the program manager.

The roles and responsibilities in your program will vary somewhat depending on your size and organizational structure. At the very least, having competent executive sponsorship, a facile program manager, and engaged business continuity team members are non-negotiables.

The Business Continuity Lifecycle

One of the biggest mistakes we see businesses make with their business continuity program is thinking that it is just a one-and-done event. They put in a lot of work conducting their initial business impact analysis, identifying resilience gaps, creating plans, policies, lists, and procedures, and distributing these throughout the organization. Then they consider their “business continuity” box “checked” and move on.

In the meantime, data becomes stale. Technology evolves. Vendors and other third-party relationships come and go.  Business objectives change. Consequently, business continuity plans become outdated and leave you ill-prepared to handle the evolving threats that will inevitably occur and disrupt your business.=

Every business continuity program should have a lifecycle that is designed to grow and mature your program over time. The key steps of the business continuity lifecycle include:

  1. Assessing your business environment and potential disruptions with a Business Impact Analysis.
  2. Creating Business Continuity Plans that detail the procedural tasks and guidance for preserving and recovering critical business processes in response to a disruption.
  3. Exercising your plans with exercises and simulations to build confidence, muscle memory, and validate and diagnose gaps in your existing plans.
  4. Maturing and improving your program continuously over time with the insights gained from exercises and real-life implementation of your business continuity and crisis management plans.

We’ve illustrated each part of the business continuity lifecycle in more detail below.

Bryghtpath-Business-Continuity-Annual-Lifecycle What is Business Continuity?

Building a Culture of Resilience by Raising Awareness

Along with embracing a lifecycle approach to building resilience, one of the single most determining factors for the success of your business continuity and crisis management program is instilling a culture of resilience within your organization.

We think of a resilience culture as a way of thinking, acting, and planning within your organization that helps your organization better respond to change, disruption, and crisis.

One of the best ways to develop a resilience culture is to take the time to listen and understand the needs of all of your organization’s stakeholders.

  • What are their strategic objectives?
  • What initiatives are important to them right now?
  • What external drivers influence their respective areas of operations?
  • How will a disruption impact their specific function?

Armed with this input, you can better align your business continuity program against the needs of your stakeholders and develop effective messaging that communicates the value of business continuity in terms that they will understand. National events like National Cybersecurity Awareness Month and National Preparedness Month are also great ways to start driving engagement and awareness around resilience topics.

Want to work with us or learn more about Business Continuity?

  • Our proprietary Resiliency Diagnosis process is the perfect way to advance your business continuity program. Our thorough standards-based review culminates in a full report, maturity model scoring, and a clear set of recommendations for improvement.
  • Our Business Continuity services help you rapidly grow and mature your program to ensure your organization is prepared for the storms that lie ahead.
  • Our Ultimate Guide to Business Continuity contains everything you need to know about Business Continuity.
  • Our free Business Continuity 101 Introductory Course may help you with an introduction to the world of business continuity – and help prepare your organization for your next disruption.
  • Learn about our Free Resources, including articles, a resource library, white papers, reports, free introductory courses, webinars, and more.
  • Set up an initial call with us to chat further about how we might be able to work together.

Category: Business ContinuityTag: Bryan Strawser, bryghtpath, bryghtpath llc, Business Continuity, business continuity consultant, business continuity lifecycle, business continuity management, business continuity plan, business continuity program, business continuity roles and responsibilities, crisis management, pillars of business continuity

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: «Project Management Leader How to Gain Traction for your Business Continuity Program
Next Post: How to Successfully Grow in Year Two of Your Crisis Management Program »

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Premium Courses

5-Day Business Continuity Accelerator

Communicating in the Critical Moment

Crisis Management Academy®️

Preparing for Careers in Resilience

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model™
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.