LOADING…
Platform  /  Datasheets  /  Business Continuity & Resilience
BIA · continuity · recovery

Prove you can recover,do not just hope to.

Business impact analysis, an interactive dependency graph and tested continuity plans - blended into a live Prevent, Absorb, Recover readiness score, with supplier risk linked to the services that depend on it.

All datasheets
3 lifecycle phasesRTO/RPO per serviceTested recovery
3

lifecycle phases - Prevent, Absorb and Recover - blended into one live resilience readiness number, so you can prove operational resilience to a regulator and a board, not just file a binder that ages on a shelf.

The challenge

An untested recovery plan is a wish with a cover page.

Most organisations can produce a continuity plan on demand - but very few can prove it works, because the business impact analysis is a stale spreadsheet, the dependencies are undocumented and the plans have never been exercised. The two columns below set the usual paper-only reality against a live, tested resilience model.

The problem
BIA in a spreadsheet, last touched two years ago
RTO and RPO guessed, never tested against reality
Supplier and system dependencies undocumented
Recovery plans untested until a real incident hits
No link between resilience and supplier risk
The approach
A live BIA with RTO, RPO and MTPD per service
Dependencies mapped as an interactive graph
Continuity plans owned, approved and exercised
Exercises from tabletop to full failover, with achieved RTO
Resilience scored across Prevent, Absorb and Recover
What it does

The whole lifecycle, on one platform.

This is not a document store. It is a live model of how your services fail and how fast you recover - business impact, dependencies, tested plans and a resilience score that all move together as things change.

Business impact analysis

Score services by impact over time - RTO, RPO and maximum tolerable disruption.

Dependency graph

An interactive map of the suppliers, systems and assets each service relies on, with an auto-derived dependency-risk score.

Continuity plans

Owned plans per service - activation criteria, recovery steps, comms plan and an approval workflow, exportable to PDF.

Exercises & failover

Run and record exercises from tabletop to full failover, capturing achieved RTO against target.

Resilience posture score

A live Prevent, Absorb, Recover readiness number that moves as controls, dependencies and tests change.

Review & assurance

Review dates tracked, owners reminded, and every decision logged for the auditor.

At a glance

The numbers that matter.

Resilience here is not a binder you file once a year - it is a handful of live measures that move as your services and dependencies change. RTO and RPO are held per critical service, exercises run from tabletop to full failover, and the whole picture rolls up into one Prevent, Absorb, Recover posture score aligned to ISO 22301 and NCSC CAF v4.0 Objective D.

RTO/RPO
per critical service
Full failover
to tabletop exercises
P·A·R
live posture score
ISO 22301
+ NCSC CAF Objective D
How it works

From impact analysis to tested recovery.

Resilience runs as one continuous loop, not a once-a-year project. The six phases below carry a service from identifying what is critical, through a quantified business impact analysis and dependency map, into owned and exercised continuity plans - and finally into a live posture score that is reviewed whenever something changes.

01
Identify
Critical services
Owners assigned
02
BIA
RTO / RPO / MTPD
Impact over time
03
Map
Dependency graph
Risk score derived
04
Plan
Continuity playbook
Approved & owned
05
Test
Tabletop to failover
Achieved RTO logged
06
Score
Prevent-Absorb-Recover
Reviewed on change
Where it fits

Resilience, evidenced.

The same continuity work feeds straight into the regimes a UK organisation is held to, so you evidence once and report everywhere. The frameworks below - from ISO 22301 and NCSC CAF v4.0 Objective D through to NIS continuity duties and operational-resilience impact tolerances - all draw on the one live model rather than a separate paper exercise per regulator.

ISO 22301Business continuity management systems
NCSC CAF v4.0Objective D - response and recovery planning (D1, D2)
Operational resilienceImportant business services and impact tolerances
NIS RegulationsContinuity duties for operators of essential services
NIST CSF 2.0The Recover function
ISO 31000Risk management principles
What you get

Proof you can recover.

You leave with the artefacts a board and an auditor actually ask for, not a shelf of documents. A live BIA register with RTO, RPO and MTPD per service, an interactive dependency map that makes concentration visible, and approved continuity plans with exercise history and achieved RTO - all exportable to PDF.

Live BIA register

RTO, RPO and MTPD per service, with criticality derived from impact.

Dependency map

Every supplier and system a service relies on, with concentration made visible.

Continuity plans + log

Approved plans, exercise history and achieved RTO - exportable to PDF.

Next step

See your resilience posture.

A 30-minute walkthrough on your critical services - the live posture score, not slides.

All datasheets →