Skip to content
Emergency Response & Crisis Management

Business Continuity and Disaster Recovery Planning

ISO 22301 and ISO 22361 BCM engineered for a post pandemic, cyber physical, and supply chain fragile operating environment

What this study delivers

Business Continuity and Disaster
Recovery Planning

Business Continuity Management has become a board level concern in the wake of COVID 19, Colonial Pipeline in May 2021 with its 4.4 million dollar ransom and six day East Coast fuel disruption, Suez in 2021, the Texas freeze in 2021, Norsk Hydro in 2019, and the steady rhythm of cyber physical, climate driven, and geopolitical disruptions. ISO 22301 from 2019 codifies the management system, ISO 22361 from 2022 adds the crisis management discipline, ISO 27031 covers ICT business continuity, ISO 31000 anchors risk management, and NIST SP 800 34 and 800 184 cover IT disaster recovery. Modern BCM execution rests on a Business Impact Analysis that quantifies financial, regulatory, contractual, reputational, and human safety impact at 1 hour, 4 hour, 24 hour, 72 hour, 7 day, and 30 day disruption durations, on Recovery Time Objective and Recovery Point Objective definition for each critical process, on recovery strategy selection covering hot, warm, and cold site, geographic diversification, supplier redundancy, manual workaround, and cloud failover, and on quarterly exercise programmes that genuinely test the plan rather than merely rehearse it. The cyber resilience overlay of the 2020s through CISA, NIST CSF 2.0, the EU NIS2 Directive of 2023, and the India CERT In Rules has made ICT BCM integration mandatory rather than optional, and our team builds it into your programme from the start.

Business Continuity and Disaster Recovery Planning Overview
Study execution

How the study is executed

A structured, facilitated process that runs from scope definition through close out and produces defensible, actionable outputs.

Business Impact Analysis (BIA)

Conduct BIA per ISO 22301, identify critical business functions, dependencies (people, technology, supply chain, facilities), Maximum Tolerable Period of Disruption (MTPD), Recovery Time Objective (RTO), Recovery Point Objective (RPO).

Risk Assessment & Threat Profile

Conduct BCP risk assessment per ISO 22301 / 22317, natural hazards (earthquake, flood, storm), technological (cyber, infrastructure failure), human (pandemic, labour action), regulatory (sanctions, certification loss), align with corporate ERM.

Recovery Strategy Design

Design recovery strategies, alternate site (hot / warm / cold), workforce relocation, supply chain backup, IT failover, telecommunications, specify per critical function with RTO / RPO targets, align with corporate IT DR plan.

BCP Documentation & Plan Authoring

Author BCP documentation per ISO 22301, policy, scope, recovery strategy, plan activation, communications, recovery procedures, return to normal, integrate with corporate ERM, crisis management, and emergency response.

BCP Exercise & Testing Programme

Design exercise programme, desktop walkthrough (quarterly), tabletop (annual), simulation (biennial), full recovery (triennial), specify independent observer team and after action review, align with ISO 22301 testing requirement.

BCP Certification & Continuous Improvement

Achieve ISO 22301 certification through third party audit, specify continuous improvement cycle, exercise findings, post incident review, environmental change, integrate with corporate management review.

Business Continuity and Disaster Recovery Planning Scope
Study scope

What the study covers in full

Business Impact Analysis with quantified financial, regulatory, and reputational impact
Critical process inventory with a Maximum Tolerable Period of Disruption definition
RTO and RPO definition for each critical process that feeds recovery strategy selection
Recovery strategy selection across hot, warm, and cold site, geographic diversification, and supplier redundancy
ICT BCM integration per ISO 27031 with a cyber resilience overlay from NIST CSF 2.0
Supply chain continuity per the BCI GPG with Tier 1 and Tier 2 supplier dependency mapping
BCP and DR plan documentation with role based playbooks
Crisis management integration per ISO 22361 from 2022
Quarterly exercise programme across tabletop, functional, and full scale with after action review discipline
Continuous improvement cycle per ISO 22301 Clause 10 with management review
Why it matters

Outcomes of Business Continuity and Disaster Recovery Planning

Business Resilience and Recovery Assurance
  • We maintain critical safety services and HSE response during disruption
  • We strengthen crisis management coordination
  • We protect workforce and community wellbeing through a structured response
  • We reduce cascading failure risk across interdependent systems
ISO 22301 BCP Certification Defence
  • We deliver a BCM management system ready for ISO 22301 (2019) certification
  • We integrate ISO 22361 crisis management
  • We align you with EU NIS2, India CERT In, and US CISA expectations
  • We support your ESG disclosure on resilience and operational continuity
BCP Testing and Activation Discipline
  • We reduce downtime duration through a structured response
  • We strengthen supplier and customer dialogue on continuity
  • We improve IT and OT recovery capability through documented playbooks
  • We support M&A resilience integration
Downtime and Continuity Cost Reduction
  • We minimise business interruption loss, typically a 30 to 50 percent recovery time reduction
  • We trim insurer loadings on business interruption risk
  • We reduce customer credit, SLA penalty, and lost sale exposure
  • We support premium pricing on resilient supply commitments
Standards & references

Codes & standards we work to

ISO 22301 (2019) BCMISO 22361 (2022) Crisis ManagementISO 27031 (2011) ICT BCISO 22320 (2018) Emergency ManagementNFPA 1600 (2024)NIST SP 800 34 Rev.1 and 800 184BCI Good Practice Guidelines (GPG 2018)EU NIS2 Directive (2023)CISA CRR and Zero TrustDisaster Management Act 2005 (India)NDMA Guidelines (India)MSIHC Rules 13 and 14 (On Site and Off Site Emergency Plan, India)OSHA HAZWOPER 29 CFR 1910.120(q)
When to engage

Triggers that signal the need

ISO 22301 certification targetPost disruption programme reset following COVID, cyber, climate, or supply chain eventsM&A continuity integrationCustomer or regulator BCP requestPeriodic plan revalidation, typically annualMajor IT or OT transitionEU NIS2, India CERT In, or SEC cyber disclosure compliance
Industries served

Where Business Continuity and Disaster Recovery Planning applies

Oil & Gas, Upstream

Wellheads, separators, gas compression, FPSO topsides, produced water systems.

UpstreamOffshoreFPSO
Refineries & Petrochemicals

Distillation columns, reactors, heat exchangers, storage spheres, LPG handling.

RefiningPetrochemical
LNG & Gas Processing

Cryogenic exchangers, liquefaction trains, BOG compressors, storage and sendout.

LNGCryogenic
Specialty Chemicals

Reactive systems, batch reactors, solvent handling, runaway reaction scenarios.

ReactiveBatch
Power Generation

Boilers, HRSGs, steam headers, hydrogen systems, ammonia SCR units.

PowerHydrogen
Pharma & Food

Sterile vessels, CIP/SIP, pressure fermenters, solvent recovery, spray dryers.

PharmaFood & Bev
What we deliver

Tangible deliverables

  • BIA report with criticality ranking and MTPD
  • RTO and RPO matrix for each critical process
  • BCP and DR plan suite with role based playbooks
  • ICT BCM and cyber resilience integration plan
  • Supply chain dependency map and continuity strategy
  • Crisis management integration framework
  • Exercise programme across tabletop, functional, and full scale
  • Continuous improvement governance per ISO 22301 Clause 10
  • Management review pack template
Get Started

Ready to start your project?

Speak with our team to scope an engagement tailored to your facility, regulatory context, and lifecycle stage.