The Person Who Knows What Happens on the Second Day
Most organizations can describe what they would do in the first hour of a serious disruption. Far fewer can say what the accounts payable team will be doing on day three with no core system, who is authorized to release payments manually, or how long the business can run that way before a supplier stops shipping. The business continuity manager owns that second question. The role is not writing a plan document. It is establishing which activities the organization cannot be without, for how long, and proving through exercises that the arrangements to restore them actually work. This guide is written for the whole function: business continuity and resilience managers, risk and compliance officers, crisis and emergency coordinators, information technology disaster recovery leads, operations and facilities managers who own the recovery site, and the executives who sign the recovery targets.
Why the Business Continuity Mandate Has Changed
From Binder to Tested Capability
The older version of this job produced a document. Collect department inputs, assemble a plan, circulate it for signature, and file it until the following year's review.
What is asked for now is evidence: named recovery targets per activity, arrangements that have been tried, and a record of what failed the last time they were tested. A plan that has never been exercised is a hypothesis.
The Gap Is Wider Than Most Boards Assume
UK national cyber security guidance notes that 36 percent of medium and large organizations have no incident response plan in place at all. Among those that do, many have never run the plan against a scenario.
The same guidance draws a distinction worth repeating internally: an incident response plan covers the immediate response, a business continuity plan covers how the organization keeps operating, and a disaster recovery plan covers getting systems back. Three documents, three owners, one timeline.
Regulators Now Set Clocks
Continuity used to be judged after the fact. Increasingly it is scheduled in advance. Under the US CIRCIA framework, covered entities are to report covered cyber incidents within 72 hours and ransom payments within 24, though the duty takes effect only through the final implementing rule and is not yet in force.
A recovery plan that cannot also produce a regulatory notification inside the window is incomplete, which is why incident response and cyber crisis management now sits inside the continuity brief rather than beside it.
The Risk Picture Keeps Moving
The 2026 global risks assessment, drawn from a survey of more than 1,300 leaders, found half of respondents expecting the next two years to be turbulent or stormy, with geoeconomic confrontation among the top short-term concerns.
For a continuity function that means the scenario set has to be refreshed deliberately. A plan built around fire and flood, in an organization whose real exposure is a single supplier in a contested trade lane, is tested against the wrong thing.
Dependencies Now Run Outside the Building
Most critical activities now depend on a cloud platform, a logistics partner, or a single specialist supplier. The recovery time the organization can achieve is capped by the slowest of those, whatever the internal plan claims.
Mapping and contracting for that exposure is the practical content of risk management in supply chain and business continuity.
What a Modern Business Continuity Manager Owns
The Business Impact Analysis
Everything starts here: which activities the organization performs, what breaks if each stops, and how quickly the consequences become severe. Done properly it is an interview and evidence exercise, not a survey emailed to department heads.
The output is a ranked list with timescales attached. Without it, every later decision about investment or priority is a matter of who argues hardest.
Recovery Targets That Mean Something
Two numbers per activity: how long it can be down before the damage is unacceptable, and how much recent data or work can be lost. Both are business decisions, signed by the activity owner, not technical settings chosen by an infrastructure team.
Aligning those targets with a management system rather than leaving them scattered across documents is what ISO 22301 business continuity management systems structures.
Strategies, Chosen and Costed
For each critical activity there is a choice: a standby site, a manual workaround, an alternative supplier, reciprocal capacity, or accepting the outage. Each has a price and each has a limit on how long it can hold.
Presenting those options with their cost and their ceiling, so executives choose rather than approve, is the discipline behind strategic risk planning and business continuity.
Technology Recovery, Jointly Owned
The continuity manager does not run the restore, but does own whether the restore meets the agreed target. That means witnessing tests rather than accepting a status report, and checking that backups are recoverable rather than merely taken.
Keeping that relationship honest is where digital risk management and business continuity earns its place in the function.
The Exercise Program
Exercises range from a discussion around a table to a live failover with systems switched off. The purpose is not to pass. An exercise where nothing went wrong was set too easy, and it taught the organization nothing.
Every exercise should end with findings, owners, and dates, handled the same way an audit finding is handled, and the next exercise should retest the ones that mattered.
Six Capabilities a Continuity Function Must Build
A bigger plan document is not the answer. The capabilities leaders now expect are analytical, technical, and political, held across the function rather than by one person who wrote the last version.
Impact analysis
Establish which activities matter, on what timescale, from evidence rather than from opinion.
Dependency mapping
Trace each critical activity to the systems, sites, people, and suppliers it actually needs.
Strategy and costing
Put real options in front of executives with their price and their time limit attached.
Exercise design
Build scenarios hard enough to fail, and run them often enough for the failures to be fixed.
Incident coordination
Run the response structure on the day, including notification clocks and stakeholder updates.
Assurance and reporting
Show the board which activities are covered, which are not, and what has actually been tested.
Sequencing matters. Impact analysis and dependency mapping come first, because a strategy chosen for the wrong activity is expense without protection, however well it is executed.
Exercise design, coordination, and assurance then convert a set of documents into a capability the organization can rely on and a regulator can inspect.
Where Continuity Teams Train: Amsterdam and Kuala Lumpur
Host city matters here because the room decides the scenarios. The method is the same everywhere; the disruptions people go home to are not.
Amsterdam and Kuala Lumpur sit at two useful poles. Amsterdam draws financial services, logistics, and data infrastructure organizations working under detailed European regulatory expectations, so the discussion tends toward important business services, impact tolerances, and evidence for supervisors. Kuala Lumpur brings manufacturing, energy, and regional shared service operations, where the pressure is physical continuity, supplier concentration, and running an alternative site in practice.
| Dimension | Amsterdam | Kuala Lumpur |
|---|---|---|
| Typical cohort profile | Continuity, operational risk, and compliance leads from banks, insurers, logistics operators, and data infrastructure firms. | Continuity, HSE, and operations leads from manufacturers, energy operators, and regional shared service centers. |
| Dominant pressure | Supervisory expectations, important business services, and evidence of testing. | Physical disruption, supplier concentration, and keeping production running. |
| Conversation tone | Evidence led, focused on documentation, tolerances, and third-party oversight. | Operations led, focused on workarounds, alternative sites, and supply routes. |
| Useful for | Delegates who must defend their arrangements to a regulator or a major client. | Delegates whose recovery depends on plant, logistics, and people rather than on systems alone. |
| Network effect | Access to European financial and infrastructure resilience peers. | Reach into Asian manufacturing, energy, and shared service networks. |
Choosing Between the Two Hubs
Delegates whose hardest problem is proving their arrangements to an outside party usually gain more from an Amsterdam cohort. Delegates whose hardest problem is keeping physical operations running often learn faster in Kuala Lumpur.
The analytical method is identical in both rooms. What differs is whether the expensive failure is an unsupportable claim or an idle production line.
Additional Hubs Beyond the Two
Beyond Amsterdam and Kuala Lumpur, EuroQuest runs risk and continuity programs in Vienna, Brussels, and Madrid. Vienna and Brussels suit teams working across European regulatory and public sector expectations.
Madrid adds a strong utilities, transport, and international services perspective for organizations whose continuity problem is geographic rather than regulatory.
The test of a continuity function is not whether it has a plan. It is whether anyone has ever tried to use the plan and written down what broke.
Building Continuity Evidence the Board Can Trust
Coverage Reported Honestly
The board needs three numbers: how many critical activities have agreed recovery targets, how many of those have tested arrangements, and how many have neither. A green status covering only the activities that were easy to plan for is worse than no status.
Reporting the gap explicitly is what converts continuity from a compliance chore into a funding conversation, and it is the reporting spine behind resilience and recovery planning for organizations.
Third Parties Inside the Scope
If a critical activity depends on an outside provider, the provider's recovery capability is the organization's recovery capability. Contract clauses requiring continuity arrangements are common; evidence that they were tested is rare.
Asking for test results, and joining an exercise where the dependency is material, is slower to establish and far cheaper than discovering the gap during an outage.
Recovery in an Industrial Setting
In plants, terminals, and utilities, continuity is physical: spare capacity, critical spares, safe shutdown and restart, and people qualified to run a degraded process. The information technology plan is a component rather than the whole answer.
That operating reality is the subject of operational resilience in industrial sectors, and it is where generic continuity templates fail most visibly.
After the Event, Before the Next One
Post-incident review is the cheapest source of improvement a continuity function will ever have, and it is routinely skipped because everyone is relieved and busy. Two weeks later the detail is gone.
Capturing what actually happened, against what the plan said would happen, is the recovery loop taught in resilience planning and disaster recovery frameworks.
Emerging Themes
Concentration in cloud and logistics providers, tighter notification clocks, client-driven resilience audits, and scenarios that combine cyber with physical disruption have all widened the mandate over the past few years.
The direction is consistent across regions and sectors. More proof is asked for, in more detail, and the business continuity manager is the person who has to produce it while the disruption is still running.
Frequently Asked Questions
Who should attend business continuity manager training?
Business continuity, resilience, and crisis managers; risk and compliance officers who own the continuity policy; information technology disaster recovery leads; operations, facilities, and supply chain managers whose activities appear in the plan; emergency and security coordinators; and the executives who have to approve recovery targets and fund the arrangements behind them.
What does a business continuity manager do?
A business continuity manager establishes which activities the organization cannot be without and for how long, maps what each one depends on, puts costed recovery options in front of executives, coordinates the response when a disruption happens, and runs an exercise program that tests whether the arrangements work. The output is tested capability, not a plan document.
What is the difference between business continuity and disaster recovery?
Business continuity covers how the organization keeps delivering its critical activities during a disruption, including manual workarounds, alternative sites, and people. Disaster recovery is the narrower technical task of restoring systems and data. A third document, the incident response plan, covers the immediate reaction in the first hours. All three should share one timeline and one set of agreed targets.
What qualifications does a business continuity manager need?
Routes in vary. Risk, operations, information technology, and emergency management backgrounds are all common, and the closest official occupation, emergency management director, typically requires a bachelor's degree plus several years of related experience. What matters most is the ability to run a credible impact analysis, design an exercise that finds real weaknesses, and report coverage honestly to a board.
How long does a business continuity program typically run?
EuroQuest risk and continuity programs usually run five to ten working days. Compressed five-day formats concentrate on one theme such as business impact analysis, management system requirements, or exercise design. Ten-day formats cover an integrated cycle from impact analysis through strategy selection, technology recovery, exercising, and board reporting.
Prove the Plan Before You Need It
EuroQuest International delivers business continuity, resilience, risk, and compliance programs across Amsterdam, Kuala Lumpur, Vienna, Brussels, and Madrid. Programs are built for continuity and risk teams, operations and technology leads, and the executives who approve recovery targets.
Explore Risk Management and Compliance Programs