Skip to content
Phishing for Trouble –
The IO Podcast returns for Series 2
Listen now

Business continuity is the capability to keep your critical activities running during disruption and to restore the rest within timeframes you agreed in advance. It covers the analysis that tells you which activities matter, the strategies that keep them available, the plans your people follow when something breaks, and the exercises that prove any of it works. In the UK it is most often built to ISO 22301, the international standard for business continuity management.

  • Know which activities are critical, and how long each one can be down before the damage is real.
  • Have a strategy for keeping those activities available, not just a document describing the ideal.
  • Give people procedures they can follow under pressure, with clear roles and communications.
  • Test the plans against realistic scenarios, then feed what you learn back into them.
  • Hold evidence that the whole cycle is running, so you can prove continuity rather than assert it.

What is business continuity?

Business continuity is the discipline of preparing an organisation to continue delivering its most important products and services when something disrupts normal operations. That disruption might be a cyber attack, a supplier failure, a power cut, a systems outage, an extreme weather event or the sudden loss of a site or a team. The point is not to predict which one happens. It is to know in advance which activities cannot stop, how quickly each must be back, and what you will actually do.

Two ideas do most of the work. The first is that not everything matters equally, so you rank activities by the impact of losing them. The second is that recovery has a clock on it, expressed as a recovery time objective for each activity and a maximum tolerable period of disruption beyond which the harm becomes unacceptable. Once those are agreed, continuity stops being a vague ambition and becomes a set of commitments you can design for, resource and test.

Business continuity sits inside the wider discipline of business resilience. Continuity keeps operations running through a specific disruption. Resilience is the broader capability to absorb change of any kind, including regulatory change and risks to security, privacy and AI, and to keep earning trust while you do it. Continuity is a component of resilience, not a substitute for it.

Business continuity, disaster recovery or resilience?

These three terms get used interchangeably and they are not the same thing. The distinction matters because it determines who owns the work and what good looks like.

  Business continuity Disaster recovery Business resilience
Focus Keeping critical activities running Restoring IT systems and data Absorbing change of any kind and keeping trust
Scope The whole organisation ICT systems and data Security, privacy, AI and operations together
Measures Recovery time objective, maximum tolerable period of disruption Recovery time objective, recovery point objective Posture, evidence and speed of response
Anchoring standard ISO 22301 ISO/IEC 27031 ISO 27001, ISO 27701, ISO 42001 and ISO 22301 together
Core question Can we keep operating? Can we get the systems back? Can we handle whatever comes next, and prove it?

Disaster recovery is a subset of continuity, concerned with the technology layer. Continuity is broader, covering people, premises, suppliers and processes as well as systems. For a fuller treatment of the last column, read how resilience differs from business continuity.




IO's compliance loop connects information security, privacy, and AI governance so you can manage risk holistically.

This page covers one part of business resilience. Real Resilience — IO’s framework for connecting security, privacy and AI governance — is where the full picture comes together.




How do you build a business continuity capability?

Business continuity management runs as a cycle rather than a project. You establish what matters, design how to protect it, write it down, test it, and use what you learn to improve. ISO 22301 structures this as a management system, which is what turns a one off planning exercise into something that stays current.

The business continuity lifecycle in six stages: policy, impact analysis, strategy, plans, exercise and improve

Each stage produces something the next one needs.

  • Policy and scope: agree your objectives, the activities in scope and who is accountable. Without a defined scope every later step expands without limit.
  • Business impact analysis: identify critical activities, the impact of losing each one over time, their dependencies, and the recovery timeframes you will commit to.
  • Continuity strategy: decide how each critical activity will keep running. Options include redundancy, alternative sites, manual workarounds, standby suppliers and prioritised recovery.
  • Plans and procedures: document what people do, in what order, with what authority, and how they communicate internally and externally.
  • Exercise and test: run the plans against realistic scenarios. An untested plan is an assumption, and exercises are where assumptions break cheaply.
  • Review and improve: feed findings, incidents and business changes back into the cycle so the plans reflect how the organisation works now.

Most organisations do not fail at writing plans. They fail at keeping them current and at proving they work. That is a management system problem rather than a documentation problem, which is why continuity is best run alongside your other governance rather than in a silo of its own. The guide on how to build business resilience sets out the wider sequence this fits into.

Which standard should you work to?

ISO 22301 is the international standard for business continuity management systems and it is certifiable, which matters if customers or regulators want independent assurance rather than your word. It specifies the requirements for the management system: leadership, planning, impact analysis, strategy, procedures, exercising, evaluation and improvement.

Read the detail on the ISO 22301 standard, or the practical view of business continuity under ISO 22301. If you are deciding how to run the management system itself, the overview of business continuity management systems covers what a BCMS has to do.

Sector rules often sit on top. UK financial services firms answer to operational resilience requirements from the FCA and the Bank of England, which ask for impact tolerances and severe but plausible scenario testing rather than continuity plans alone. Those obligations are covered under operational resilience.




ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.

ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.




How does business continuity fit into business resilience?

Continuity answers one question well: can we keep operating through this disruption? Resilience asks a bigger one: can we handle whatever comes next, including the things we have not thought of, and keep the trust of customers and regulators while we do it. Good governance, done well, is what produces that. Resilience is downstream of governance rather than a separate emergency capability.

The Resilience Loop: information security, data privacy and AI governance working as one system

The Resilience Loop connects three disciplines that most organisations run separately: information security under ISO 27001, data privacy under ISO 27701 and AI governance under ISO 42001. Continuity under ISO 22301 is the fourth lens over the same control set. An access control, a backup regime or a supplier assessment does not belong to one standard. It is one control, viewed through whichever lens is asking.

That is what makes continuity cheaper to run as part of a resilience programme than as a standalone project. Map a control once and reuse it. Capture its evidence once and surface it against every framework that asks. The business resilience framework explains how the common control set works in practice.

How do you prove business continuity works?

A plan on a shared drive proves nothing. What stands up to a customer’s due diligence questionnaire, an auditor’s sampling or a regulator’s request is evidence: a current business impact analysis, agreed recovery objectives, exercise records with dates and participants, incident logs, and demonstrable corrective actions from the last time something went wrong.

This is where most continuity programmes are weakest, because the evidence is generated once a year and scattered across inboxes and spreadsheets. Capturing it as a by-product of the work instead makes proof continuous rather than an annual scramble. The method is set out in how to evidence resilience, and you can benchmark where you stand today with the Resilience Score.

Related guides:

Related business continuity guides

Why choose ISMS.online for business continuity?

Most tools help you write a plan. ISMS.online helps you run the management system and prove it is working.

  • One control set, every framework: map a control once and reuse it across ISO 22301, ISO 27001, ISO 27701 and ISO 42001, so continuity is not a separate programme.
  • Impact analysis that stays current: hold critical activities, dependencies and recovery objectives in one place, linked to the controls that protect them.
  • Evidence on demand: exercise records, incident logs and corrective actions captured as you work, ready for auditors, customers and regulators.
  • Certifiable by design: everything maps to the standards, so your continuity capability is provable rather than asserted.
  • Informed by deep expertise: guided implementation from specialists who have run these management systems, not automation that hides the risk.
  • Continuous, not annual: a live view of continuity posture instead of a document refreshed the week before an audit.
  • Built for UK and regulated markets: designed for organisations where security, privacy and trust decide whether you win the contract.

See it in context on the business resilience platform, or book a demo.

FAQs

What is the difference between business continuity and disaster recovery?

Business continuity covers keeping the whole organisation’s critical activities running, including people, premises, suppliers and processes. Disaster recovery is narrower and concerns restoring IT systems and data after an outage. Disaster recovery is a component of continuity rather than an alternative to it, and it is measured with a recovery point objective as well as a recovery time objective.


Is business continuity a legal requirement in the UK?

There is no single law requiring every organisation to have a business continuity plan, but sector rules and contracts frequently do. UK financial services firms have operational resilience obligations from the FCA and the Bank of England. Suppliers to the public sector and to large enterprises are routinely asked to evidence continuity arrangements in tenders and due diligence. Certification to ISO 22301 is the usual way to answer those questions once rather than repeatedly.


What are RTO and MTPD?

The recovery time objective is the timeframe within which you commit to resuming an activity after disruption. The maximum tolerable period of disruption is the point beyond which the harm to the organisation becomes unacceptable. The recovery time objective is set inside the maximum tolerable period so there is margin, and both come out of the business impact analysis rather than being chosen arbitrarily.


How often should continuity plans be tested?

At least annually for critical activities, and again whenever something material changes: a new system, a new site, a significant supplier, a reorganisation or a merger. Exercises should vary in type, from a discussion based walkthrough to a full simulation, because each surfaces different weaknesses. What matters for evidence is that testing is scheduled, recorded and followed by corrective action.


Where does business continuity sit within business resilience?

Continuity is one component of resilience. It handles the question of operating through disruption. Resilience is the wider capability to absorb change of any kind, including new regulation and risks to security, privacy and AI, while keeping the trust of customers and regulators. Running continuity as one lens over a shared control set, rather than as a separate programme, is what makes it sustainable.



Max Edwards

Max works as part of the ISMS.online marketing team and ensures that our website is updated with useful content and information about all things ISO 27001, 27002 and compliance.

Watch a platform demo

See how 1,000+ teams run their compliance frameworks in a 3-minute platform tour

platform dashboard full on mint

We’re a Leader in our Field

4/5 Stars
Users Love Us
Leader - Summer 2026
High Performer - Summer 2026 Small Business UK
Regional Leader - Summer 2026 EU
Regional Leader - Summer 2026 EMEA
Regional Leader - Summer 2026 UK
High Performer - Summer 2026 Mid-Market EMEA

"ISMS.Online, Outstanding tool for Regulatory Compliance"

— Jim M.

"Makes external audits a breeze and links all aspects of your ISMS together seamlessly"

— Karen C.

"Innovative solution to managing ISO and other accreditations"

— Ben H.