Business continuity management (BCM) is the management discipline that prepares a company for disruptions: which processes are vital, how long may they fail, with which workarounds do they continue — and who decides what when it happens? The result are contingency plans that secure the ability to act in an emergency.
With NIS2, BCM has turned from good practice into duty: the directive explicitly requires business continuity, backup management, recovery and crisis management as part of risk management — including leadership accountability.
From risk to contingency plan
It starts with the business impact analysis (BIA): it identifies critical business processes, their dependencies — systems, staff, providers, sites — and quantifies what downtime costs. From this derive recovery targets (RTO/RPO) and continuity strategies: workarounds, redundant resources, emergency operation.
The contingency plans make this operational: alerting and escalation paths, a crisis team with clear roles, immediate measures per scenario, communication templates for customers, authorities and staff — and the restart order. Proven frameworks are ISO 22301 and BSI standard 200-4; exercises turn paper into responsiveness.
Typical emergency scenarios a BCM covers
- Cyberattack with complete IT outage — including communication without compromised systems.
- Failure of site, data center or power supply.
- Failure of critical providers and suppliers (including cloud and network providers).
- Staff outage in key functions — deputy rules and documented knowledge.