LOADING…
Platform  /  Business Resilience  ·  Module
BIA · continuity · recovery

When a supplier goes down,you don't.

Business impact analysis, dependency mapping and tested recovery - with supplier risk linked directly to the services that keep you running.

BIA drivenRTO · RPO trackedTested recovery
The challenge

An untested plan is a hypothesis, not a capability.

A continuity plan you have never tested is a hypothesis, not a capability.

Most organisations can produce a business-continuity document. Far fewer can show, for a given critical service, exactly which suppliers and systems it depends on, how long it can be down before real harm, and the date they last proved they could recover. That gap is precisely what regulators and boards now probe - and where a supplier outage quietly becomes a service failure.

E2ERisk connects business impact analysis, dependency mapping and tested recovery into one live picture. Each important service carries its RTO, RPO and dependencies - including the suppliers behind it - and every exercise and failover test is tracked to closure, rolling up into a Prevent, Absorb, Recover posture you can defend rather than a binder nobody has opened.

Why it's different

Supplier risk is business continuity.

Most of the outages that take a service down start outside your own estate, with a supplier you depend on. When they go down, you go down - yet that dependency rarely appears in the continuity plan. E2ERisk maps it before the incident, and makes the link between supplier risk and business continuity visible all the way up to your board.

Business impact analysis

Score services by impact over time - RTO, RPO and maximum tolerable disruption.

Dependency mapping

An interactive dependency graph links each service to the suppliers, systems and assets it relies on - and auto-derives a per-service dependency-risk score from the map.

Continuity plans

Owned continuity plans per critical service - activation criteria, recovery steps, comms plan and an approval workflow, exportable to PDF.

Exercises & failover tests

Run and record exercises from tabletop to full failover - capturing achieved RTO against target, with findings tracked to closure.

Supplier-linked continuity

Supplier compromise maps straight to service impact - exposure known before the event.

Continuous review

Plans re-validated on change; gaps tracked to closure.

See it work

One screen. Every critical service. Live recovery.

The FCA, the PRA, DORA and the NCSC CAF all expect the same thing: proven recovery of important business services within a defined impact tolerance. A regulator wants that position current, not reconstructed from a binder on a shelf. The view below shows it live - every critical service, its recovery posture and the gaps that still need closing.

 E2ERisk · Business Resilience postureLive
42
CRITICAL SVCS
7
OVER TOLERANCE
18
PLANS APPROVED
61%
TESTED 12M
DEPENDENCY RISK
Critical · 6High · 14Medium · 12Low · 10
SERVICES AT RISK
Citizen Portal · RTO 4h, no tested continuity planno planPayments · recovery time outside impact toleranceover toleranceCasework · single point of failuredep risk 82
Resilience posture

Prevent. Absorb. Recover.

Resilience is not a single number; it is a posture across the whole lifecycle - what you do to prevent disruption, absorb it when it lands, and recover within tolerance. E2ERisk scores all three and keeps the score live, moving as your controls, dependencies and tested recovery plans change rather than freezing on the day the document was written.

 resilience lifecycle · live postureLive
81
Resilience readinessBlended across Prevent, Absorb and Recover · recalculated as evidence changes
Prevent
84
Controls upstream of disruption
Supplier assurance88
Patching cadence76
Absorb
72
Redundancy & dependency risk
Dependency risk68
Concentration74
Recover
90
Tested, owned continuity
Plans approved12/14
Exercised (12mo)86%
The problem

An untested recovery plan is a plan that fails.

The gap is rarely the plan itself; it is whether anyone has proved it works. A BIA frozen two years ago, recovery targets nobody has tested and undocumented dependencies mean the first real test of your continuity capability is the incident itself - which is exactly when you cannot afford to be wrong.

Without E2ERisk
BIA in a spreadsheet, last updated two years ago
RTO and RPO guessed, never tested against reality
Supplier and system dependencies undocumented
Recovery plans untested until a real incident hits
No link between resilience and supplier risk
With E2ERisk
A live BIA with RTO, RPO and MTPD per service
Recovery targets set, owned and tested on a schedule
Supplier and asset dependencies mapped end to end
Scenario and tabletop tests with actions tracked to closure
Resilience tied directly to the supplier risk register
How it works

From impact analysis to tested recovery.

Resilience is built service by service: identify the critical services and their owners, run a BIA for RTO, RPO and tolerance, map the suppliers and systems each one depends on, write the recovery plan, then test it from tabletop to full failover and feed the lessons back in. The position stays current because the cycle keeps running.

01
Identify
Critical services
Owners assigned
02
BIA
RTO / RPO / MTPD
Impact over time
03
Map
Supplier dependencies
System dependencies
04
Plan
Recovery strategy
Roles & runbooks
05
Test
Tabletop to failover
Achieved RTO logged
06
Review
Post-test learning
Re-baseline
Why it's better

Four ways to do resilience. Three capture a fragment.

A BIA spreadsheet, a folder of BCP documents and a CMDB each hold one piece - impact, plan or wiring - and none of them connects to the supplier risk that actually triggers an outage. The comparison below shows what changes when all three live on one model alongside your assurance data.

CapabilityBIA spreadsheetBCP documentsCMDBBusiness Resilience
BIA with RTO / RPOFrozen snapshotNot reallyAsset data onlyLive, criticality-scored
Dependency graphNoneFree textWiring, not impactInteractive, FK-linked
Cascade / blast radiusNoneNonePartialMapped before the incident
Tested continuity + logNoneFiled, never testedNoneTabletop to full failover
Recovery-readiness scoreNoneNoneNonePrevent / Absorb / Recover
Connected to your platformRe-keyedRe-keyedSeparate toolReuses services, assets, risk & CAF

The result is recovery you can evidence rather than assert: every critical service carries a tested plan, an achieved RTO and the dependency map behind it - and the resilience score moves as the evidence does.

Framework depth

One critical service, resilience evidenced.

Recovering an important business service inside its tolerance is what ISO 22301, the CAF's Objective D, the operational-resilience regime and NIST's recover function all ask for, in different words. Evidence the recovery once and it answers all of them.

Critical service
Recovery of a citizen-facing payments service within its agreed recovery-time objective.
This maps to
ISO 22301Business continuity management
NCSC CAF D1 / D2Response & recovery planning
Operational resilienceImportant business services
NIST CSF 2.0RC - recover
Outcomes

Recovery you can actually evidence.

The point of the module is what it lets you prove: a Prevent-Absorb-Recover readiness score, exercises from tabletop to full failover, an achieved RTO logged against target for each service, and alignment to ISO 22301 and CAF Objective D - all from the dependency and supplier data you already hold.

3-phase
Prevent, Absorb, Recover score
Full failover
to tabletop exercises
Achieved RTO
logged against target
ISO 22301
+ NCSC CAF Objective D
What you get

Proof you can recover, not just hope to.

Three things come out of the module, each in a form a regulator or a board accepts: the BIA with recovery targets, the dependency map that exposes concentration risk, and the tested recovery plans with their exercise findings tracked to closure.

BIA & recovery targets

RTO, RPO and MTPD per critical service, with impact modelled over time.

Dependency map

Every supplier and system a service relies on - concentration risk made visible.

Tested recovery plans

Tabletop and scenario exercises with findings tracked through to closure.

Native to your frameworks

Map once. Report against everything.

One body of resilience evidence, mapped to every continuity and operational-resilience regime a UK organisation answers to - so a recovery proven once is reported against ISO 22301, the CAF, DORA and the rest without being rebuilt.

ISO 22301NCSCNIS RegulationsNIST SP 800-34DORABCI Good Practice
Business Resilience

Know the blast radius before the breach.

Pre-map supplier dependencies to critical services, so ‘are we exposed?’ is answered in minutes.

See Supplier Assurance