Cybersecurity

Blog space

Business Continuity Management (BCM) – How to Build a Programme Resilient to Cyber Attacks

Inside this article:

  • Key strategies for strengthening business resilience and minimising the impact of disruptions
  • The latest regulatory requirements for business continuity, including DORA and NIS2
  • Practical criteria and tools for identifying critical processes within your organisation
business continuity management BCM

Updated: 3 July 2026

What is Business Continuity Management BCM and why does the traditional approach fall short? W sekcji o DORA zmień:Business Continuity Management (BCM) is a management system governing an organisation’s ability to continue critical operations during a disruption – from infrastructure failures and natural disasters to deliberate cyber attacks. The key parameters of BCM are RTO (Recovery Time Objective – the target time to restore a service) and RPO (Recovery Point Objective – the acceptable amount of data loss).

Traditional BCM plans were designed around hardware failures or natural disasters, with an assumed, limited blast radius. Cyber attacks – ransomware, wipers, APT campaigns – break these assumptions: the cause of the disruption may be unknown for days, the recovery environment may be compromised alongside the production environment, and a single incident may simultaneously affect systems, identity infrastructure, and communications.

BCM and cyber attacks – at a glance:

  1. Sophos State of Ransomware 2024: the average downtime following a ransomware attack was 22 days – organisations with tested BCM plans and isolated backups recover significantly faster
  2. DORA (Arts. 11-12) requires financial institutions to have a documented ICT continuity policy with defined recovery objectives and tested backup arrangements
  3. NIS2 Art. 21 requires business continuity, backup management, disaster recovery, and crisis management as minimum risk management measures for essential and important entities
  4. A backup connected to the production domain will be encrypted alongside the production environment during a ransomware attack – an immutable or offline backup is a requirement, not an option
  5. BCM must account for supplier attack scenarios (such as MOVEit 2023, which affected over 2,700 organisations through a single product)
  6. Patronusec supports organisations in building BCM programmes resilient to cyber attacks – from BIA and scenario analysis through BCP/DRP plans to testing and DORA and NIS2 compliance


How does cyber-resilient BCM differ from traditional BCM?

Traditional BCM rests on three assumptions that cyber attacks invalidate. First: that the cause of disruption is known. In a ransomware or APT incident, the root cause may be unknown for days or weeks. Second: that the recovery environment is intact. A backup connected to the production domain is encrypted alongside it. Third: that disruption is localised. A supplier attack cascades to clients who did nothing wrong.

Key differences:

Traditional BCMCyber-resilient BCM
Scenario: hardware failure, natural disasterScenario: ransomware, wiper, APT, supply chain attack
Cause known immediatelyCause may be unknown for days
Recovery environment intactBackup may be encrypted or destroyed
Blast radius containedAttack may simultaneously affect IT, OT, and communications
Recovery: restore from backupRecovery: isolate first, establish scope, then restore
Identity assumed intactActive Directory may be compromised – begin recovery from Identity

Implications for BCM architecture:
BCM plans must include cyber scenarios. The BIA must identify not only “what is critical” but also “what cannot be unavailable for X hours during a cyber attack.” The DR plan must define the recovery sequence on the assumption that Active Directory and management systems may be compromised.

Patronusec Insight: From our work with clients, most BCM plans do not answer the fundamental question of a cyber incident: “Where do we start recovery if we do not know what is compromised?” That answer must be documented and tested before an incident occurs. As part of our vCISO service, we help clients run tabletop exercises for ransomware scenarios – decision simulations that surface gaps in plans before a real incident reveals them.

How should a Business Impact Analysis address cyber attack scenarios?

A Business Impact Analysis is the foundation of BCM – without it, you do not know what to protect first. For cyber scenarios, the BIA must go beyond “what is critical” and ask questions specific to cyber incidents.

Key BIA questions for cyber scenarios:

For each business process:

  • What is the maximum tolerated period of disruption (MTPD)?
  • What is the acceptable data loss (RPO)?
  • Can this process operate manually if IT systems are unavailable?
  • What external dependencies (suppliers, APIs, SaaS) could be used to attack this process?
  • Does this process require Active Directory to function?

Specific questions for ransomware scenarios:

  • Do we have an offline or immutable backup of this system?
  • How long will restoring from that backup take – and do we know this from a test?
  • Do operating procedures for this process exist in paper or offline form?
  • Who has authority to decide whether to pay or refuse to pay a ransom?

Documentation required by DORA and NIS2:

DORA Art. 11.5 requires documented “policies and procedures on backup and recovery and restoration methods” with clearly defined recovery objectives. NIS2 Art. 21.2 requires “business continuity and crisis management plans.”


Want to test whether your current BCM plan would survive a ransomware attack?

Patronusec conducts tabletop exercises for cyber attack scenarios – decision simulations with the board and IT team that identify gaps in BCM and DRP plans. Within a single workshop day, you leave with a concrete list of actions to implement.

Book a BCM tabletop exercise


How do you satisfy DORA and NIS2 business continuity requirements?

DORA and NIS2 impose specific BCM requirements that go beyond a traditional approach.

DORA (Digital Operational Resilience Act) – BCM requirements:

DORA Art. 11 (ICT business continuity policy) requires:

  • A documented ICT continuity policy approved by the management body
  • ICT business continuity plans and response and recovery plans
  • Testing of plans at least annually
  • Implementation of “redundant ICT capacities” for critical processes

DORA Art. 12 (disaster recovery plans) requires:

  • A backup policy with defined RPOs and backup frequency
  • Recovery and restoration procedures with guaranteed RTOs
  • Regular testing of backup and recovery
  • Secure isolation of backups from the production network

NIS2 – BCM requirements:

NIS2 Art. 21.2 requires essential and important entities to implement measures including:

  • Business continuity, including backup management and disaster recovery
  • Security incident management
  • Crisis management

NIS2 does not specify precise RTOs or RPOs – these are set by the organisation based on the BIA and risk assessment. However, national implementing legislation may add more detailed requirements.

Patronusec Insight: The difference between DORA and NIS2 on BCM is a frequent source of confusion. DORA is more prescriptive and sector-specific (primarily financial institutions and ICT providers) – with concrete requirements for testing and documentation. NIS2 is broader and less prescriptive – it grants more latitude to the organisation. For organisations subject to both (for example, a fintech subject to both NIS2 and DORA), we recommend starting with DORA as the more demanding standard – satisfying DORA typically implies satisfying NIS2 as well. We discuss this during a free vCISO consultation.

How do you test BCM plans – and what does DORA require?

An untested BCM plan is a document, not a safeguard. DORA Art. 11.6 requires testing of ICT business continuity plans at least annually.

Types of BCM tests:

Document review: Verification that plans are current, complete, and consistent with the current architecture. Does not test real-world execution. Minimal value for cyber resilience.

Tabletop exercise: A decision simulation – participants (board, IT, business) discuss a scenario without activating real systems. Identifies gaps in decision-making processes, communications, and escalation paths. Particularly valuable for ransomware and crisis communication scenarios.

Simulation exercise: Activation of BCP/DRP procedures in a controlled test environment. Verifies whether procedures work in practice, not only on paper.

Full failover test: Actual switch to the DR environment. The most demanding to organise, but provides genuine confidence that the system works. Requires a maintenance window and detailed planning.

What DORA requires from tests:

DORA Art. 11.6 specifies that tests must be “scenario-based” and must incorporate lessons from previous incidents. Test results must be reported to the management body. Significant institutions must conduct TLPT every three years as the deepest level of testing.

FAQ – Business Continuity Management

What is the difference between a BCP and a DRP?

A BCP (Business Continuity Plan) is the broader plan for maintaining critical business functions during a disruption – covering processes, communications, alternative locations, and people. A DRP (Disaster Recovery Plan) is the more technical plan for recovering IT systems and infrastructure after a failure. A DRP is a component of a BCP – the BCP defines “what must remain operational,” and the DRP defines “how we restore the IT systems that make that possible.”

How often should backups be tested?

At least annually – DORA requires annual testing, and ISO 27001 (Annex A Control A.5.30) and operational best practice suggest more frequent testing for critical systems. A practical recommendation: critical systems (customer databases, payment systems) – restoration test quarterly. Others – annually. Tests must be documented.

Do I need a separate DR environment?

Not an absolute requirement, but a practical necessity for systems with low RTOs. Systems with an RTO below 4 to 8 hours typically require a DR environment (hot standby or warm standby). Systems with an RTO of 24 hours or more may be recoverable from backup without a dedicated DR environment. The decision should follow from the BIA.

What do we do if our backup has been encrypted by ransomware?

If the backup was connected to the production network, it may have been encrypted. In that case: (1) check whether you have an offline or immutable backup (tape, object storage with object lock, air-gapped); (2) contact your backup solution provider – some tools have immutable versioning; (3) check cloud provider snapshots (for example, AWS S3 Glacier Vault Lock); (4) consider engaging an IR firm – in some cases partial recovery of encrypted data is possible. This is precisely the situation that BCM should prevent through backup isolation.

How much does a BCM project with Patronusec cost?

BCM project scope includes BIA, scenario identification, BCP/DRP plan development, and tabletop exercises. Cost depends on the size of the organisation, the number of critical processes, and the current BCM maturity level. Patronusec provides a fixed-price quotation after a free scoping call. In the vCISO model, BCM is one of the functions we manage on an ongoing basis.

Is ISO 22301 required, or is DORA/NIS2 sufficient?

ISO 22301 is a BCM standard – certification is not required by DORA or NIS2, but it can be useful as a demonstration of maturity. Many organisations implement BCM using ISO 22301 as a framework without pursuing certification. DORA and NIS2 define minimum requirements – ISO 22301 provides a more complete governance framework.


Business Continuity Management (BCM) – free consultation

Patronusec supports organisations in building BCM programmes resilient to cyber attacks – from BIA and cyber scenario analysis through BCP and DRP plans to testing and documentation required by DORA and NIS2.

In a free 30-minute consultation we will help you:

  • Assess current BCM programme gaps against DORA and NIS2 requirements
  • Identify critical cyber scenarios your current BCM plan may not address
  • Plan a BCM update project or tabletop exercise
  • Choose a support model: one-off project or ongoing vCISO support

Free consultation | vCISO – BCM management | ISO 27001 | DORA compliance | NIS2

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top