Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Six Business Continuity Strategy Planning Mistakes To Avoid At All Costs
Articles

The Six Business Continuity Strategy Planning Mistakes To Avoid At All Costs

ISBuzz TeamBy ISBuzz TeamJanuary 29, 2020Updated:May 2, 20257 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Businessman pressing multimedia type of modern buttons with virtual background
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Any organisation can face significant downtime, data loss and employee displacement if unprepared when a disaster strikes. All of these can have a serious and detrimental impact on the viability of a business. So, planning for them can help companies identify risks and take relevant steps to manage them.

Business continuity supports the strategic objectives of an organisation by identifying its priorities and proactively building the capability to continue activities that support those priorities in the event of a disruption. It is an on-going process of continuous improvement that reflects the internal and external operating environment. If implemented and maintained correctly, is not simply a tick-box compliance exercise or a rainy-day insurance policy, but something that can deliver day-to-day measurable value to an organisation. 

Managing risk is a normal part of doing business and one of the roles of the executive is to make sure that the organisation is best placed to reap the opportunities from any uncertain situation rather than suffer disruption because of it. This requires understanding the threats that the business faces, the vulnerabilities of the organisation and the business impact that could result if the threats coincided with the vulnerabilities and then taking action to reduce the potential downside of the risk without compromising the upside. For example, it may be logistically or economically advantageous to locate  business operations near a river or rely on a migrant workforce for seasonal work. However, in such cases it would be negligent not to take steps to minimise the probability of flooding by ensuring essential services were not on the ground floor or ensure that there was a ready pool of seasonal workers so that issues such as Brexit did not adversely impact the business. Likewise, cyber criminality is rapidly increasing at the same time that businesses are becoming more and more reliant on information technology and therefore technical security measures are a necessity.

Although, such measures will undoubtedly reduce the probability of disruption, they will never eliminate it completely and therefore organisations needs to be prepared to respond to both disruptions that they can anticipate and those that they don’t.

However, implementing a business continuity programme is only half the battle though, and there are certain things organisations should avoid doing to ensure their responses to disruptions aren’t rendered ineffective.

  1. Managing the wrong risks

Human risk perception is notoriously flawed. We are pre-programmed to fear risks with the largest negative impact and are more accepting of risks that we have most control over. For example air travel is one of the safest forms of transport, yet more people fear it than travelling by car.  We apply the same biases to our businesses. However, there are two dimensions to risk: likelihood and impact and when assessing what may disrupt our business and what to invest in to prevent it happening we need to take both dimensions into account. For example, Sungard AS invocation statistics show that power outages, network issues and hardware failures account for nearly two thirds of all business interruptions yet organisations often ignore these risks and invest in measures for the more exotic risks such as terrorism and targeted cyber attacks.  Therefore, don’t fall into the trap of concentrating on a narrow set of extreme risks: employ a formal risk assessment method and be clinical, as opposed to emotional, about what you protect.

  1. Failing to update

If organisations already have business continuity measures in place, then they’re ahead of the game but they still need to be reviewed and maintained on a regular basis. The risk landscape is  constantly changing,. Out of date measures will almost certainly leave a company vulnerable and unable to effectively respond and recover to a disruption.

  1. Lack of testing and exercising

As well as keeping the business continuity measures up to date, it’s also important to practice implementing them through frequent exerciseing and testing. Several times a year will allow businesses to see if the business continuity programme is working and if there are areas of weakness that need modification. Threats change and evolve, becoming more sophisticated every year, therefore testing the measures often will ensure your staff remain aware of the risks that the business faces and what to do if they materialise.. 

  1. Not backing up

In the event of a business disruption, organisations may be reliant on  backup data, which could be stored at a different secure location. This practice is a frontline weapon when it comes to defending against threats such as  cyberattacks and should form a central pillar of any business continuity programme. If backups of data that is necessary for business recovery do not happen regularly, companies could find that data is rendered useless because it’s out of date. Make sure to keep backed up data secure and look out for any errors and risks. Finally, backup data is only of any use if you have an alternative means to process it and therefore measures should be put in place to recover priority applications and systems or have alternatives in place should recover take too long.

  1. Not training  the whole organisation on continuity 

Failure to make everyone aware of the risks that the business faces, what to do in the event of disruption and the priorities of the business can leave companies vulnerable no matter how comprehensive their business continuity capability is. It’s vital for everyone to know what to do in an emergency – whether it’s a natural disaster or a massive data breach. An organisations staff are the first line of defence. They are the first to identify when things are going wrong and they are the experts in knowing how to prevent disruptions escalating to crisis situations. A successful continuity programme is one involves everyone in the organisation and harnesses their expertise. 

  1. Not identifying the priority activities

Everything that a business does is important. Some activities contribute directly to the creation of products and services that are sold to create profit, whilst some are associated with corporate social responsibility or staff and community welfare. Unfortunately, at the time of disruption an organisation needs to prioritise its activities. Failure to prioritise, or agree those priorities will result on people pulling in different directions.    An integral part of any business continuity programme is the Business Impact Analysis (BIA) that identifies the business processes associated with the priority products and services together with their dependencies such as IT applications and people. This analysis allows organisations map which systems are critical to the continued operation and which should be prioritised in terms of risk-management and budget allocation. This is an instance of working smarter, not harder and ensuring that key systems are effectively protected and swiftly recoverable following disruption to restore normal business function.

Implementing and maintaining business continuity to cope with cyber-attacks or other disasters within an organisation is no easy task. While the theory is reasonably straightforward, the practice is frequently beset by conflicting priorities and agendas as well as resource and time constraints. 

Being able to rely on a consulting practice that has experience of successfully implementing and managing disaster recovery and business continuity programmes means that achieving effective continuity capabilities in line with corporate policy and regulatory requirements can be achieved effectively, efficiently and in line with industry good practice.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}