Most organisations that have “done” business continuity have a document: a Business Continuity Plan, often produced once, during a compliance push, and rarely opened again until the next audit. ISO 22301, the international standard for Business Continuity Management Systems, is built around a different premise — that a plan is only as good as the evidence that it works.
The core building blocks of ISO 22301:
Why the exercise programme is the part that matters. A tabletop exercise reveals whether the plan’s assumptions hold — whether the named recovery team members are actually reachable, whether the “alternate” data centre has been kept in sync, whether a supplier’s own continuity commitments were ever verified rather than assumed. A plan that has only ever existed on paper reliably fails on details that seem trivial until the moment they matter: an outdated contact list, a recovery site that was quietly decommissioned, a dependency on a system that itself has no continuity plan.
What “certifiable” business continuity looks like in practice:
The connection to the rest of governance. Business continuity doesn’t operate in isolation from information security — a ransomware incident is both a security event and a continuity event, and organisations whose ISMS and BCMS are managed as separate, disconnected programmes routinely discover the gap between them during the incident they were both supposed to prepare for.