We help you build a Business Continuity Management System in line with ISO 22301, so your critical processes keep running during outages, cyber attacks and disasters.

// Why it matters

Why ISO 22301 Consulting matters

The cost of a disruption often comes less from the incident itself than from how unprepared you were. ISO 22301 helps you decide how long each process can be down and design recovery strategies that meet those limits.

// Scope

What does it cover?

Business impact analysis (BIA)

We determine the criticality, dependencies and acceptable downtime of your processes.

Risk assessment

We assess the threats and scenarios that could cause disruption.

Recovery strategies

We define strategies that fit targets such as recovery time (RTO) and data-loss tolerance (RPO).

Business continuity plans

We prepare plans covering roles, communication and step-by-step recovery.

IT disaster recovery

We support planning for restoring your information systems.

Test and exercise programme

We design the exercise calendar and scenarios that prove your plans work.

// Method

How do we proceed?

  1. Scope and policyWe define the scope of the system, objectives and responsibilities.
  2. Impact analysis and risk assessmentWe identify critical processes and disruption scenarios.
  3. Strategies and plansWe write the recovery strategies and continuity plans.
  4. Exercises and testsWe test the plans with scenarios and fix the weak points.
  5. Review and improvementWe review the system at regular intervals and keep it current.
// Deliverables

What do we deliver?

  • Business impact analysis report
  • Risk assessment report
  • Recovery strategy document
  • Business continuity and IT disaster recovery plans
  • Exercise scenarios and reports
  • Internal audit and management review records
// Who is it for?

Who is this service for?

Organisations that must provide uninterrupted serviceCompanies offering payment, data and infrastructure servicesOrganisations that commit to continuity in customer contractsPublic institutionsThose who want an integrated system with ISO 27001
// FAQ

Frequently asked questions

How is it different from ISO 27001?

ISO 27001 focuses on the confidentiality, integrity and availability of information assets; ISO 22301 focuses on service continuity during disruption. They complement each other and can be built as an integrated system.

Is disaster recovery the same as business continuity?

No. Disaster recovery focuses on restoring IT systems; business continuity covers the whole way you work, including people, processes, suppliers and facilities.

Is an exercise mandatory?

The standard expects plans to be tested. We design a programme suited to your organisation, from tabletop exercises to technical tests.

// Related services

Services you can combine

// Information request

Get information about ISO 22301 Consulting

Fill in the short form and we will get back to you as soon as possible. For a more detailed preliminary assessment you can also use the needs-analysis form below.

    Open the detailed needs-analysis form

    If you share your current situation in a few questions, we can give you a clearer preliminary assessment and scope proposal.

      Let’s talk about ISO 22301 Consulting

      Share your needs and current situation, and we will define the right scope and roadmap together.