Business continuity
Business continuity risk assessment
What stops the business, how likely it is and for how long.
What this work consists of
This is the risk assessment from the continuity discipline, and it answers a different question than an IT risk assessment: not what can be breached, but what makes the operation stop, how likely that is, and for how long. We map the scenarios that interrupt each critical process, the single points of failure, and the dependencies on vendors and on individual people.
The work starts by closing the scope in writing and mapping the processes, then moves into interviews: documents say what should happen, the conversation says what actually happens and where the single-person dependency lives. The result is a matrix prioritized by likelihood and impact, along with an action plan with owners and sequence, pointing to the mitigations that actually move the risk.
On your side, we need time on the calendar with the people accountable for the processes and access to whoever knows the vendors and contracts. The cycle format adds treatment tracking and periodic reassessment, because the matrix ages fast: a new vendor or a migration changes the whole picture. It is the input that makes the BIA and the recovery plans start out pointing at the right risk.
How we conduct it, stage by stage
The stages and deliverables below describe the Assessment with treatment follow up modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Process mapping
We map which processes exist, who answers for each one and what it depends on to work: systems, people, suppliers and other processes. That picture defines where to go deeper and what can stay out.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Remediation follow-through
We chase the queue until each item closes, with a date and an owner. Finding things is the easy part.
Periodic reassessment
The critical ones come back to the table on a calendar, and a new supplier arrives assessed instead of arriving and being assessed after the incident.
What is not included
- The BIA itself, which is a separate service and usually comes next
- Writing the continuity and recovery plans, which belongs to the continuity service
- Tests and simulations, which are a separate service and come after the plans
- Contracting an alternate site or a recovery provider, which is your investment
- Executing the mitigations in the action plan, which belongs to the named owners; in the tracking option we chase progress, we do not do it for them
- Information security risk assessment, which covers the breach question and has its own service
- Auditing or due diligence on the mapped vendors: here we name the dependency; assessing the vendor is separate work
- Financial quantification of the risk for insurance purposes, which is actuarial work for the broker or the insurer
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.