Business impact analysis, an interactive dependency graph and tested continuity plans - blended into a live Prevent, Absorb, Recover readiness score, with supplier risk linked to the services that depend on it.
lifecycle phases - Prevent, Absorb and Recover - blended into one live resilience readiness number, so you can prove operational resilience to a regulator and a board, not just file a binder that ages on a shelf.
Most organisations can produce a continuity plan on demand - but very few can prove it works, because the business impact analysis is a stale spreadsheet, the dependencies are undocumented and the plans have never been exercised. The two columns below set the usual paper-only reality against a live, tested resilience model.
This is not a document store. It is a live model of how your services fail and how fast you recover - business impact, dependencies, tested plans and a resilience score that all move together as things change.
Score services by impact over time - RTO, RPO and maximum tolerable disruption.
An interactive map of the suppliers, systems and assets each service relies on, with an auto-derived dependency-risk score.
Owned plans per service - activation criteria, recovery steps, comms plan and an approval workflow, exportable to PDF.
Run and record exercises from tabletop to full failover, capturing achieved RTO against target.
A live Prevent, Absorb, Recover readiness number that moves as controls, dependencies and tests change.
Review dates tracked, owners reminded, and every decision logged for the auditor.
Resilience here is not a binder you file once a year - it is a handful of live measures that move as your services and dependencies change. RTO and RPO are held per critical service, exercises run from tabletop to full failover, and the whole picture rolls up into one Prevent, Absorb, Recover posture score aligned to ISO 22301 and NCSC CAF v4.0 Objective D.
Resilience runs as one continuous loop, not a once-a-year project. The six phases below carry a service from identifying what is critical, through a quantified business impact analysis and dependency map, into owned and exercised continuity plans - and finally into a live posture score that is reviewed whenever something changes.
The same continuity work feeds straight into the regimes a UK organisation is held to, so you evidence once and report everywhere. The frameworks below - from ISO 22301 and NCSC CAF v4.0 Objective D through to NIS continuity duties and operational-resilience impact tolerances - all draw on the one live model rather than a separate paper exercise per regulator.
You leave with the artefacts a board and an auditor actually ask for, not a shelf of documents. A live BIA register with RTO, RPO and MTPD per service, an interactive dependency map that makes concentration visible, and approved continuity plans with exercise history and achieved RTO - all exportable to PDF.
RTO, RPO and MTPD per service, with criticality derived from impact.
Every supplier and system a service relies on, with concentration made visible.
Approved plans, exercise history and achieved RTO - exportable to PDF.
A 30-minute walkthrough on your critical services - the live posture score, not slides.