IT failure, cyberattack, fire, flood or supplier collapse: whether operations grind to a halt or continue running depends on the effectiveness of your BCM programme. We design, build and validate programmes that hold, aligned to ISO 22301.
Business continuity consulting designs and implements the management programme that keeps an organisation's critical activities running through disruption: business impact analysis, continuity strategy, plans and structures, and the exercising and audit that prove they work, aligned to ISO 22301.
The foundation of any credible programme is the Business Impact Analysis: methodically identifying critical activities, assessing the impact of their disruption, setting Recovery Time Objectives, Recovery Point Objectives and the Maximum Tolerable Period of Disruption, and exposing the interdependencies across IT, supply chain and outsourcing partners that a disruption will find first.
From that foundation we build to your objective, whether that is ISO 22301 certification, reassuring regulators, satisfying client auditors or simply the confidence that the organisation can take a hit. Recognising that every client is unique, engagements are bespoke: as much or as little help as you need, from a single BIA to a complete programme built, embedded and certified.
A BIA methodically identifies your critical activities, assesses the impact of their disruption over time, sets recovery objectives such as RTO, RPO and the Maximum Tolerable Period of Disruption, and exposes interdependencies across IT, supply chain and partners. It is the foundation every credible continuity plan is built on.
Not always, but you need the capability it describes. Certification is valuable where regulators, clients or tenders demand demonstrable continuity; elsewhere an ISO 22301 aligned programme without the certificate can be the proportionate choice. We help you decide, then build to that objective.
A focused BIA takes weeks; a complete programme from analysis to exercised plans typically runs a few months depending on size and complexity. We scope engagements so value lands early: critical activities protected first, refinement after.
All three treat continuity as a legal expectation: NIS2 Article 21 names business continuity among its mandatory measures, DORA requires tested ICT continuity and recovery plans, and Swiss critical infrastructure operators need continuity capability behind the ISG's reporting duties.
Through the validation cycle: planned exercises, audit at intervals, and review after significant change. Our exercise programmes and BCLE 2000 training keep the capability in your people, not on a shelf.
Esercitazioni da tavolo, funzionali, informatiche e su vasta scala che verificano i piani e le prove di conformità alle norme ISO 22301, NIS2 e DORA.
Dottrina, strutture e comunicazioni che contengono il picco e abbreviano i tempi di recupero, basate sulla norma ISO 22361.
La struttura sopra i piani: rischio, continuità, crisi, sicurezza informatica e persone su un'unica base di governance, secondo ISO 22316.
Dall'universo dei rischi al rischio gestito: identificazione, valutazione consapevole dello stress, trattamento personalizzato e monitoraggio in tempo reale.
Oltre la prevenzione: la capacità di resistere, reagire e riprendersi, garantendo al contempo la continuità dei servizi essenziali.
Dalla determinazione dell'ambito di applicazione alle misure previste dall'articolo 21 e alla prontezza di presentazione dei rapporti entro 24 ore ai sensi della direttiva (UE) 2022/2555.
I cinque pilastri del Regolamento (UE) 2022/2554 attuato per gli enti finanziari e i loro fornitori di infrastrutture ICT critiche.
Il nostro modello operativo proprietario incentrato sulle decisioni: esposizione e affidabilità delle decisioni misurate separatamente, per il consiglio di amministrazione.
Il rischio che ereditate dai fornitori e dalle piattaforme condivise: mappato, garantito, contrattualizzato ed esercitato, secondo le norme ISO 28000, NIS2 e DORA.
Riservatezza, integrità e disponibilità garantite da un ISMS dinamico e conforme alla norma ISO 27001.
Il Framework per la Resilienza Aeroportuale: cinque ambiti come un unico modello operativo per l'intero aeroporto, basato sul motore 7A, nelle edizioni per l'aviazione commerciale, cargo e business.
La governance ha avvolto ogni livello dei sistemi intelligenti, dal comportamento dei modelli alla responsabilità del consiglio di amministrazione e alla norma ISO 42001.
Start with a Business Impact Analysis or a programme review; we will show you exactly where you stand against ISO 22301.
Prenota una consulenza