Proposal
Business continuity (BCP, DRP and BCMS)
We define how each critical process gets back to work, write the business continuity plan and the disaster recovery plan, train the people who execute them and build the testing calendar. You choose how far to go: the plans alone, the full business continuity management system aligned to ISO 22301, or the continuous operation, where plan maintenance, testing and the annual review stay with us. A plan nobody maintains ages within six months.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Business continuity (BCP, DRP and BCMS)
From a plan on paper to a company that knows what to do when things stop.
How we run it
What this work consists of
We take the processes that cannot stop and define how each one gets back up and running. Recovery strategies are chosen with the alternatives and costs on the table, then turned into two documents, the business continuity plan and the disaster recovery plan, written to be followed under pressure, with steps and phone numbers.
How far to go is your call: stop at the plans and handle maintenance with your own team, build the full management system aligned with ISO 22301, with policy, defined roles, training, and a testing calendar, or contract ongoing operation, where we keep everything current, run the tests, and bring the results to your committee.
On your side, we need the BIA results, or to run the BIA first when there is none, plus access to the people who execute each critical process and to the technical team that will operate the recovery. In the end, the plans exist, have owners, and the people who will use them know it. In the options that include an exercise, the plans have already been put to the test once before the day they need to hold.
If the goal is ISO 22301 certification, the full management system is the path that supports the audit. We prepare and advise; certification is always issued by the independent body.
How we conduct it, stage by stage
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Recovery strategies
We define how each critical process gets back to work and at what cost, with the alternatives on the table before the choice.
Writing the plans
We write the plans in the format someone will use on the worst day of the year: direct, with steps and phone numbers.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Exercise
We put people in the situation and run it. What fails here is what would have failed for real.
What is not included
- Contracting and paying for the alternate recovery environment, whether cloud or a physical site, which is your investment with the provider
- Technical execution of the recovery during a real disaster, which belongs to your team or the contracted provider
- The ISO 22301 certification itself, which only an independent certification body can issue
- The BIA, when it does not exist yet: it is a separate service, comes first, and is what determines which processes these plans must cover
- Technical implementation of the chosen strategies, such as replication, backup, or redundancy, which stays with your IT team or the vendor
- Business continuity management software: the plans work as documents, and the license, if you want one, is your purchase
- Crisis management and incident communication, which answer a different question and have their own service
- The internal audit of the management system for certification purposes, which requires independence from whoever implemented it
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.