Business Continuity Management (BCM)

EXPERTISE FOR OVER 35 YEARS.

Business Continuity Management (BCM)

Act quickly when it matters. We support you in building your business continuity management. From business impact analysis and scenario-based emergency plans to moderated tabletop exercises with your crisis team. Practical and efficient.

A structured business continuity management system noticeably relieves pressure in three dimensions.

Minimize risks

Protect yourself from reputational and financial losses.

With documented emergency plans and clearly defined crisis roles, you safeguard your business processes against outage risks. You reduce the probability of severe crises and limit their economic impact.

Handle crises efficiently

React in a structured way, not by improvisation.

With proven procedures, clear escalation paths, and a trained crisis team, you act in an orderly way in an emergency. Decisions are made faster, communication is clear, and responsibilities are unambiguous.

Reduce downtime

Restore your IT systems and processes quickly.

Together with you, we define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for your critical business processes. Based on this, we lay the groundwork for you to develop practical recovery plans and sustainably reduce your downtime.

What is Business Continuity Management?

Business Continuity Management is a systematic approach to ensuring critical business processes continue during disruptions. BCM includes identifying critical processes, assessing outage risks, developing emergency plans, and regularly testing these plans. The leading international standard is ISO 22301.

Difference from disaster recovery. Disaster recovery focuses on the technical restoration of IT systems after outages. Business Continuity Management is broader and also includes organizational measures, alternative working methods, supplier outage scenarios, and crisis communication.

Difference from crisis management. Crisis management describes the leadership structure and communication during an acute incident. BCM is the structural preparation for it. It is the plan that takes effect during a crisis.

Why SHE for Business Continuity Management

ISO 27001 certified since 2020.

We built information security management in our own practice and know the ISO world from an audit perspective. We bring this experience into every BCM implementation. This helps you avoid typical pitfalls and reach certifiable documentation faster.

SME-focused consulting approach.

Instead of focusing on extensive theory, we help you develop practical solutions. Together, we create actionable emergency plans, document crisis management team processes, and facilitate realistic tabletop exercises—so your organization is prepared in the event of an emergency.

German team in Ludwigshafen.

250 employees in Ludwigshafen and Cluj. Consultants who can audit you on site and escalate personally in a crisis. They know your language, your authority structures, and the reality of German mid-sized businesses.

Who needs a BCM system?

Three drivers are currently pushing companies to build BCM.

NIS2 obligation. Section 30 BSIG requires NIS2-affected companies to implement measures for maintaining operations and backup management. A documented BCM system based on ISO 22301 is the most practical way to prove this requirement in an audit-ready manner.

ISO 27001 Annex A. Companies already certified to ISO 27001 face requirements for information security continuity (A.5.29, A.5.30) in Annex A. A BCM structure based on ISO 22301 fulfills these requirements cleanly and without duplication.

Supply chain requirements. Large clients in automotive, pharma, and chemicals increasingly require BCM evidence from suppliers, often as part of supplier audits or in a TISAX context. If you cannot provide evidence, you lose contracts.

Industry examples. Manufacturing companies with continuous production, logistics providers with time-critical shipments, financial service providers with DORA obligations, healthcare providers with service obligations, and IT service providers with critical availability SLAs.

Norms and standards

ISO 22301 is the central international standard for BCM. It defines requirements for a business continuity management system and is certifiable. The accompanying guideline ISO 22313 explains practical implementation.

ISO 22301:2019. The current version defines requirements for risk assessment, business impact analysis, continuity strategies, emergency plans, exercises, and continual improvement. It follows the Plan-Do-Check-Act cycle and is compatible with ISO 27001 and ISO 9001.

ISO 22313. This guideline supplements the requirements of ISO 22301 with practical implementation recommendations. The guideline is not certifiable, but it can serve as a valuable guide for establishing and further developing a business continuity management system, particularly when designing crisis management team structures and planning exercises.

BSI Standard 200-4. The German standard "Business Continuity Management" specifies ISO 22301 for German public administration and critical infrastructures. It is a mandatory reference for KRITIS operators and public administration.

Connection to NIS2 and ISO 27001. Section 30 BSIG minimum measures require operational continuity, backup management, and crisis management. ISO 27001 Annex A.5.29 and A.5.30 require information security continuity. A BCM system according to ISO 22301 fulfills both requirements without maintaining two parallel structures.

Background

Ready for the next step?

Talk to our BCM lead in Ludwigshafen about your critical processes, compliance requirements, and the realistic effort for a BCM system according to ISO 22301. We listen first, then recommend.

Build your BCM with SHE

Required
Required
Required
Required
Required
Required
Ansprechpartner

Contact Person

Let’s talk about your project.

Book a free initial consultation with our team at
+49 621 5200-0.
 

FAQ

What is Business Continuity Management?

Business Continuity Management is a systematic approach to keeping critical business processes running during disruptions. BCM includes identifying critical processes, assessing outage risks, developing emergency plans, and testing them regularly. The leading international standard is ISO 22301.

What is the difference between BCM and disaster recovery?

Disaster recovery focuses on the technical restoration of IT systems after outages. Business Continuity Management is broader and also includes organizational measures, alternative ways of working, supplier outages, and crisis communication. Disaster recovery is therefore part of BCM, not its counterpart.

Which standard regulates Business Continuity Management?

ISO 22301:2019 is the central international standard and can be certified. The accompanying guideline ISO 22313 explains practical implementation. For German public administration and KRITIS operators, BSI Standard 200-4 also applies.

Who needs BCM?

Companies subject to NIS2 must demonstrate measures to maintain operations. ISO 27001-certified companies use BCM to meet Annex A.5.29 and A.5.30 requirements. Suppliers in automotive, pharma, and chemicals are increasingly required by major clients to provide BCM evidence.

What does ISO 22301 mean?

ISO 22301 is the international standard for business continuity management systems. It defines requirements for risk assessment, business impact analysis, continuity strategies, emergency plans, exercises, and continual improvement. It follows the Plan-Do-Check-Act cycle and is compatible with ISO 27001 and ISO 9001.

How long does a BCM project take?

An initial business impact analysis typically takes four to six weeks. Emergency concepts and implementation require an additional three to six months, depending on the number of critical processes. Including the first tabletop exercise, you should plan six to twelve months for a full setup.

What is the difference between ISO 22301 and ISO 22313?

ISO 22301 is the certifiable requirements standard. It defines what you must do. ISO 22313 is the guideline. It shows how you can do it. We use ISO 22313 as a practical reference, especially for crisis team structures and exercise formats.

What is a business impact analysis?

The business impact analysis is the systematic analysis of your business processes to identify critical dependencies and maximum tolerable downtimes. From the BIA, we derive recovery time objectives and recovery point objectives. These define the following technical and organizational solution architecture. The BIA is the first phase of every BCM build according to ISO 22301.