Every organisation I have worked with had a business continuity plan. Most had never opened it under pressure.
I have built and run business continuity management systems, implemented ISO 22301, and sat through more crisis exercises than I can count. Later, as a CEO, I lived through the kind of weeks that continuity plans are written for – and learned how little of the document I actually reached for.
That is not an argument against planning. It is an argument for understanding what a plan can and cannot give you.
The plan is a starting point, not an outcome
A continuity plan does three things well: it forces you to decide what matters most before the crisis, it tells people who has the mandate to act, and it removes the need to invent basic logistics while the building is metaphorically on fire.
What it cannot do is make decisions for you. Real disruptions rarely match the scenario on page 14. The supplier that fails is not the one you assessed. The ransomware hits on the Friday before a holiday. Two things go wrong at once, and the second one is the one that hurts.
Resilience is the organisation's ability to keep making sensible decisions when the script has run out. It lives in people, relationships and habits – not in a binder.
Where resilience actually comes from
Looking back at the organisations that handled disruption well, a few patterns stand out.
They knew what they would sacrifice. Resilient organisations have already agreed which services, customers and processes get protected first – and which ones get switched off to protect them. That is a leadership decision, and it is uncomfortable, which is why it so often gets postponed until it is made badly, at 2 a.m.
They had exercised, not just documented. A tabletop exercise with the actual leadership team, once or twice a year, does more for resilience than any amount of plan-writing. Not because the scenario is realistic, but because people discover who freezes, who talks over everyone, and who quietly gets things done.
Their decision rights were clear. In a crisis the question "who can decide this?" should take seconds, not a meeting. If the answer depends on who is in the room, you have a plan but not a mandate.
They talked to their suppliers before they had to. Operational resilience today is mostly third-party resilience. If your critical supplier's continuity arrangement is a paragraph in a contract you have never tested, you do not have one.
They were honest about dependencies. Single points of failure are rarely technical. More often they are one person who knows how the invoicing system really works, or one relationship that keeps a key customer loyal.
Do and don't
Do define your critical activities and your tolerance for their disruption in plain terms: "We can survive two days without X, not five." Then build backwards from that.
Do run at least one leadership-level exercise a year. Make it short, make it uncomfortable, and make the CEO participate rather than observe.
Do map the people, systems and suppliers that your critical activities actually depend on – including the informal ones.
Do treat every real incident, however small, as a free exercise. Debrief it. Write down what surprised you.
Don't let the continuity plan live only in the risk or IT function. If the commercial director has never seen it, it is not the company's plan.
Don't measure resilience by the thickness of the documentation. A twelve-page plan that people know beats a two-hundred-page plan that no one has read.
Don't assume your cloud provider, your outsourcing partner or your payment provider is your resilience strategy. They are part of your risk.
Don't wait for the crisis to decide who speaks to customers, regulators and the press. The communication plan is the part that gets improvised most and forgiven least.
A reminder
The plan gets you through the first hour. Your people, your priorities and your practice get you through the rest.
If you only have time for one thing this year, do not rewrite the plan. Run the exercise.
---
Maj Britt Arberg is the founder of House of Moon. She is an ISO 22301 Lead Implementer, has implemented and managed business continuity and information security management systems in Big Four advisory, and has held executive responsibility as a CEO in the energy transition sector.