Phase 1
Business impact analysis (BIA)
We identify critical processes, dependencies and maximum tolerable periods of disruption, and set the recovery objectives (RTO and RPO) agreed with the business.
Information security
Responding coherently and effectively to unforeseen events that disrupt normal operations is not something you improvise: it is designed, documented and —above all— tested.
We establish the redundancy needed in equipment and resources, develop the business impact analysis for serious incidents that take services down, and produce the business continuity plan (BCP) and the disaster recovery plan (DRP). The work closes with real tests of both plans: an untested plan is a hypothesis, not a control.
Phase 1
We identify critical processes, dependencies and maximum tolerable periods of disruption, and set the recovery objectives (RTO and RPO) agreed with the business.
Phase 2
We evaluate options for redundancy, backup, alternate sites and third-party agreements, weighing the cost of each strategy against the impact it avoids.
Phase 3
We document the BCP and the DRP: roles and responsibilities, activation criteria, recovery procedures, call tree and crisis protocols.
Phase 4
We run tests —tabletop, restore or failover— document the results and adjust the plans with the lessons learned.
The BCP answers how the business keeps operating during the disruption, including manual workarounds. The DRP is narrower: how infrastructure and systems are recovered. The DRP is a part of the BCP, not a synonym for it.
No. A backup whose restore has never been tested is not a continuity control. The restore test —with times measured against the committed RTO— is what turns a backup into a real capability.
Yes. It is a standalone project, although it fits naturally as part of the ISMS if ISO/IEC 27001 implementation is taken on later.
your business partner