Business Continuity Plans
What is a business continuity plan?
Most organisations have some form of business continuity plan. Fewer have one that would actually work under the pressure of a real outage.
We help Australian organisations build BCPs grounded in reality — based on what your business actually does, what would genuinely cause harm if it stopped, and what your staff can realistically do during a disruption.
What’s included
Policy and Statement of Work
We supply a template so you can quickly develop a policy documenting the scope, governance and operation of your program, reflecting your organisation's current and future resilience requirements. In this initial phase, we also develop a Statement of Work covering the activities, deliverables, work schedule and project plan.
Business Impact Analysis
This is the foundation of any effective BCP. We work with your leadership team to identify your Prioritised Activities (the activities most time-critical to your organisation) and rank them by Maximum Allowable Outage: how long you can manage without them before suffering unacceptable harm. This is where most BCPs fail: plans that try to recover everything at once recover nothing effectively.
Review of business continuity risks
Based on the BIA findings, we identify the threats most likely to affect your organisation (cyber incidents, utility outages, supply chain failures, extreme weather, loss of key staff) assess their likelihood and impact, and recommend mitigation strategies.
Most organisations know less than they think about the recoverability of their critical IT applications and data, particularly cloud-based ones. Most SaaS vendors won't warrant a Recovery Time Objective unless you've purchased a highly resilient service, so it's essential your third-party agreements reflect the disruption tolerance you've established in the BIA.
Plan and documentation development
We develop your full suite of BCP documentation: the overarching plan, Recovery Procedures for each Prioritised Activity, contact directories and supporting materials. Plans are written to be used under pressure, not stored in a drawer. Recovery Procedures are built around the actual current recoverability of your supporting resources.
IT disaster recovery
IT recovery is often the weakest link in a BCP. We assess whether your critical systems can actually be recovered within the timeframes your business requires, and work with your IT team to close the gaps when they can't. It's common for IT departments to lack current recovery plans, or have ones that haven't been tested in the past 12 months. The right time to update your IT DR Plan is straight after your BIA, once you know the recoverability targets your critical systems need to hit.
Implementation, training and exercising
Plans are only as good as the people who need to use them. We help embed the BCP through staff training and facilitated exercises that test the plan before a real disruption occurs; building your team's confidence and surfacing gaps while they're still cheap to fix.
Business continuity vs crisis management
A Business Continuity Plan and a Crisis Management Plan serve different purposes, and need to work together.
The Business Continuity Plan focuses on operational recovery: how you restore your time-critical activities and services after a disruption.
The Crisis Management Plan focuses on strategic leadership response: who's in charge, how decisions get made, and how you communicate with staff, customers, regulators and the media.
Both are necessary. We often develop them in parallel, so they're aligned from the start.
Regulated by APRA?
CPS 230 (Operational Risk Management) sets specific requirements for business continuity, Critical Operations and third-party risk management. We help regulated entities meet these obligations, from initial gap assessment through to full compliance.
Ready to talk?
Ready to build a plan that actually works? Contact us and we'll talk through where your organisation is starting from.
Get in touchBusiness continuity consulting
Most organisations have some form of business continuity plan. Fewer have one that would actually work under the pressure of a real outage.
We help Australian organisations build BCP’s that are grounded in reality; based on what your business actually does, what would genuinely cause harm if it stopped and what your staff can realistically do during a disruption.
A typical engagement will include the following:
We supply a template to enable you to quickly develop a Policy that documents the scope, governance and operation of the Program. This Policy should be developed to reflect the current and future resilience requirements of your organisation. During this initial phase, we also develop a Statement of Work that details the activities to be undertaken by us and your staff, deliverables, work schedule and project plan.
Business Impact Analysis (BIA)
This is the foundation of any effective BCP. We work with your leadership team to identify your Prioritised Activities (the activities in your organisation that are most time-critical) and the resources they depend on. They are ranked by their Maximum Allowable Outage time (how long your organisation can manage without them before suffering unacceptable harm) and identify the resources they depend on. This is where most BCP’s fail: plans that try to recover everything at once recover nothing effectively.
Review of Business Continuity Risks
In the context of the findings of the BIA, we identify the threats most likely to affect your organisation (cyber incidents, utility outages, supply chain failures, extreme weather, loss of key staff etc), assess their likelihood and potential impact and recommend possible mitigation strategies.
It is very common that we find that organisations have little knowledge regarding the recoverability of critical IT applications and data they use. This is particularly true for cloud based applications. Most Software as a Service vendors will not warrant a Recovery Time Objective for applications, unless a highly resilient service has been purchased. It is imperative that the agreement with your Third Party vendors reflects your tolerance for disruption you have established in the BIA.
Business Continuity Plan and documentation development
We develop the full suite of BCP documentation: the over-arching plan, Recovery Procedures for each of your Prioritised Activities, contact directories and supporting materials. Plans are written to be used under pressure, not stored in a drawer. Importantly, the Recovery Procedures will be developed based on the recoverability of your supporting resources in their current state.
IT Disaster Recovery review
IT recovery is often the weakest link. We assess whether your critical systems can actually be recovered within the timeframes your business requires and work with your IT team to close the gaps when they can't.
We have also found it is common for the IT Department to lack current IT Disaster Recovery Plans or they exist and have not been tested in the previous 12 months. The logical time to update your IT DR Plan is after the completion of a BIA, because you will then know the recoverability targets for your critical IT systems.
Implementation, training and exercising
Plans are only as good as the people who need to use them. We help embed the BCP through staff training and facilitated exercises that exercise the plan before a real disruption occurs.
APRA-regulated entities
If your organisation is regulated by APRA (including ADIs, general insurers, superannuation funds, and life insurers) CPS 230 (Operational Risk Management) sets specific requirements for business continuity, critical operations and third-party risk management.
We have considerable experience helping regulated entities meet these obligations, from initial gap assessment through to full CPS 230 compliance.
What our customers say
“Our five year old business continuity plan was in need of a refresh … the guys at Continuity Matters sorted us out with a set of plans with recovery procedures for when things go wrong. We’re ready to face any challenge! Thank you Continuity Matters.”
Manufacturing company
“The Business Continuity risk assessment report was an eye opener for us. We had no idea that our suppliers posed such risks to our business. Thanks to the team at Continuity Matters we are in a position now to address those risks.”
Medical manufacturing organisation