GRC & Compliance

Business continuity plan: the ultimate guide to organisational resilience

A business continuity plan is no longer a box to tick in an audit: it decides whether your organisation survives a major crisis or stops at it. What it covers, how to build it, govern it, test it and keep it alive.

Intervalle Technologies 8 min read

A business continuity plan (BCP) is the framework that lets an organisation keep its essential activities running — or restart them fast — after a major incident. Long treated as a regulatory obligation or a line in an audit report, it has become a genuine strategic advantage: among companies with a crisis-management organisation in place, 73% weathered recent turbulence with more resilience. This guide covers the essentials — definition, build, governance, tooling, testing — without detours.

What a business continuity plan is, and what it isn't

A BCP sets out the measures that keep an organisation's vital functions running, or bring them back quickly, when an interruption hits. Contrary to a common assumption, it is not confined to IT, even though that dimension is often decisive. A complete plan covers the identification of critical activities, the minimum acceptable service levels, the maximum tolerable interruption times, the human, technical and organisational resources to mobilise, crisis activation and communication procedures, and recovery strategies.

It should be distinguished from the disaster recovery plan (DRP), which focuses on restoring information systems after an incident. The DRP is in fact a component of the BCP, dedicated to the technical layer; the two are so closely linked that they are often cited together. Our consultants handle both within a single BCP and DRP engagement. As dependence on technology grows, IT continuity becomes a central pillar of the wider plan — without ever exhausting its scope.

Why continuity became a strategic issue

Four imperatives justify the investment. Economic first: a prolonged interruption can be costly — for 20% of companies, downtime exceeds €10 million. Regulatory next: the financial sector (Basel III, EU directives), operators of vital importance, organisations certified to ISO 22301 or ISO 27001, and essential-service providers under the NIS Directive are all required to hold a BCP. Then come the competitive edge — customer and partner trust, differentiation, access to markets that demand continuity guarantees, better ratings from rating agencies — and the protection of a reputation that a mishandled crisis can lastingly damage. Conversely, an organisation that keeps its essential services running in difficult conditions signals its professionalism and reliability.

The figures show the gap that remains: 86% of companies have a risk-management policy and 73% a crisis-management organisation, yet only 68% have formalised a business continuity plan. The issue sits within the organisation's broader governance, risk and compliance posture, of which the BCP is one marker of maturity.

A BCP is not an insurance policy filed away in a drawer: it is a competitive advantage that proves itself the day everything else stops.

Building the plan: from context to strategy

Building a BCP follows a methodical sequence. It starts with context and objectives: analysing the external environment (regulation, contractual requirements, geographic exposure, supplier dependencies) and the internal one (maturity, governance, resources, critical systems), then defining scope, objectives and allocated resources.

Next comes formalising continuity needs. For each essential activity, you set the minimum acceptable service level, the maximum tolerable downtime (MTD), the recovery time objective (RTO) and the recovery point objective (RPO) — the tolerable data loss. A Business Impact Analysis quantifies these thresholds and maps the critical dependencies: human, material, IT and external.

Third comes risk analysis. You inventory the threats — natural, technological, human, health-related, political — assess their likelihood and impact, and build realistic scenarios: a cyberattack paralysing the information system for 48 hours, a fire destroying head office, a pandemic keeping 40% of staff away. Finally, the continuity strategy chooses, for each activity, between degraded mode, workaround, transfer to another site, outsourcing and redundancy — options weighed by a cost-benefit analysis on three criteria: effectiveness, feasibility, cost.

Examples make it tangible. A European hotel group set its reservation system a minimum service level of 60%, a recovery time of 4 hours and a data loss under 10 minutes; a mining company operating in sub-Saharan Africa prioritised its strategic extraction sites and its main data centre, targeting recovery of critical operations within 4 hours. An African banking group, for its part, chose a blended strategy: a fallback site for critical teams, remote work for support functions, an IT backup contract, and manual procedures for essential operations.

Governing, tooling and documenting the plan

A plan without governance stays theoretical. Steering rests on a steering committee (executives and key operational leads), a BCP manager with cross-functional skills — risk management, crisis communication, business knowledge —, continuity correspondents in each critical function, and a crisis cell that can be activated at any time. A RACI matrix clarifies who executes, is accountable, is consulted or informed, while escalation procedures set alert thresholds and the decision chain. One industrial multinational structured its crisis cell across three levels — strategic, tactical, then operational at each site. Governance has its traps: over-centralisation, no named deputies, bloated and inaccessible documentation, or ownership handed to a purely technical profile.

On the technical side, the choice of solutions follows the recovery objectives. Recovery sites come as hot (permanent replication, near-instant failover), warm (preconfigured) and cold (premises still to be equipped). Data availability combines backups, synchronous or asynchronous replication and snapshots, often following the 3-2-1 rule: three copies, two media types, one off-site. Virtualisation and cloud add portability, elasticity and automated failover — an African telecom operator migrated its critical applications to a hybrid multi-cloud architecture to maximise resilience; these mechanisms connect to the backup and recovery capabilities already in place. Communications are doubled up too, since the usual channels can fail: satellite phones, radios, multiple mobile carriers, crisis messaging. Documentation, finally, is organised as a pyramid — framework document, operational procedures, role-based quick-reference sheets, technical annexes — and must stay accessible, including offline, clear, standardised and secure.

What to take away

  • A BCP is not a DRP: the first covers the whole organisation, the second the recovery of information systems, of which it is one component.
  • MTD, RTO, RPO and the minimum service level: the thresholds that turn a business need into a measurable continuity objective.
  • 43% of companies still have no formalised BCP; for 20%, downtime exceeds €10 million.
  • A BCP is only worth what it is tested to be: reviews, tabletop exercises, technical simulations and full-scale drills.

Testing, improving and keeping the plan alive

A BCP is only worth anything if it works for real; testing is the judge. Four levels complement each other: the document review — a European bank found its plan still listed systems decommissioned 18 months earlier —, tabletop exercises gathering stakeholders around a fictional scenario, technical simulations (failover to a recovery site, restoring backups) and full-scale drills that measure actual recovery times.

Each exercise feeds a Plan-Do-Check-Act improvement cycle: plan, do, check the gaps, act. Lessons learned, captured while fresh, turn every test into learning. An annual calendar — quarterly reviews, half-yearly tabletop exercises, at least one technical simulation a year, a full-scale drill every 12 to 24 months — keeps vigilance up without paralysing operations.

A plan only lives, finally, if the teams know it: general awareness sessions, targeted training for key actors, regular reminders. It must also reach the wider ecosystem — critical suppliers, partners, essential providers — whose involvement in some exercises exposes the vulnerabilities of the extended chain. A services company based in Senegal set up a quarterly review committee bringing together every department and an external consultant, keeping the plan continuously aligned with how the organisation evolves.

Digital transformation, finally, reshapes the exercise: growing interconnection and dependence on technology, cloud migration that shifts the model of who is responsible for what, remote work that challenges traditional fallback-site strategies, and accelerated development cycles that make the plan harder to keep current. Together they call for a BCP that is more agile, modular and wired into monitoring and alerting tools. Test automation, especially in cloud environments, raises its frequency and reliability. The lesson does not change: treat the plan as a living process, resourced and regularly exercised — because 43% of organisations still do not have one.

Rethinking your organisation's continuity and resilience?

We help regulated organisations build, test and continuously improve their business continuity plan. Tell us where you are and an expert will get back to you.