Glossary · simply explained

BCM & contingency planning

Business continuity management (BCM) is the management discipline that prepares a company for disruptions: which processes are vital, how long may they fail, with which workarounds do they continue — and who decides what when it happens? The result are contingency plans that secure the ability to act in an emergency.

With NIS2, BCM has turned from good practice into duty: the directive explicitly requires business continuity, backup management, recovery and crisis management as part of risk management — including leadership accountability.

From risk to contingency plan

It starts with the business impact analysis (BIA): it identifies critical business processes, their dependencies — systems, staff, providers, sites — and quantifies what downtime costs. From this derive recovery targets (RTO/RPO) and continuity strategies: workarounds, redundant resources, emergency operation.

The contingency plans make this operational: alerting and escalation paths, a crisis team with clear roles, immediate measures per scenario, communication templates for customers, authorities and staff — and the restart order. Proven frameworks are ISO 22301 and BSI standard 200-4; exercises turn paper into responsiveness.

Typical emergency scenarios a BCM covers

  • Cyberattack with complete IT outage — including communication without compromised systems.
  • Failure of site, data center or power supply.
  • Failure of critical providers and suppliers (including cloud and network providers).
  • Staff outage in key functions — deputy rules and documented knowledge.

Frequently asked questions about BCM & contingency planning

What is the difference between BCM, contingency plan and DR?

BCM is the overarching discipline, the contingency plan its documented result per scenario, disaster recovery the IT-specific part of restoration. BCM asks: how do we keep delivering? DR asks: how do the systems come back? Both share the targets from the BIA.

Does NIS2 really require a BCM?

Yes — Article 21 explicitly names business continuity, backup management, disaster recovery and crisis management as minimum risk management measures. For affected entities, a demonstrable BCM is thus part of compliance, not optional polish.

How do you start a BCM pragmatically?

With the business impact analysis for the five to ten most critical processes: dependencies, tolerable downtimes, existing gaps. From this emerge the first contingency plans including alerting and crisis team — better few rehearsed plans than a complete, unread manual.

How often must contingency plans be exercised?

At least annually, sensibly staggered: tabletop exercises for the crisis team, technical restart tests for IT, occasionally an overarching full simulation. Every exercise ends with documented findings — otherwise the plan stays at the state of its creation.

What belongs in the ransomware scenario of a contingency plan?

Decision paths for isolation and shutdown, communication via non-compromised channels, reporting deadlines (72 hours GDPR, 24/72 hours NIS2), forensic preservation, recovery into clean environments and the negotiation stance. Prepared contacts — forensics, counsel, insurer — save days in an emergency.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.