Business Continuity
Business Continuity for Cyber Assurance: What Assessors Want
Published 15 May 2026
The two numbers everything hinges on
- RTO (Recovery Time Objective) – how quickly a function must be back up.
- RPO (Recovery Point Objective) – how much data loss is tolerable.
Set these per business function, agreed with the function owner – not by IT in isolation.
What the plan must contain
- Critical business functions and their RTO/RPO
- Dependencies (people, systems, suppliers, premises)
- Disruption scenarios (cyber incident, supplier outage, premises loss, key person)
- Recovery procedures for each scenario
- Communications plan (staff, customers, regulators, ICO if applicable)
- Roles and responsibilities (named individuals, with deputies)
- Invocation criteria and authority
- Testing schedule and most recent test evidence
Scenarios assessors expect you to cover
- Ransomware that encrypts production data
- Loss of primary cloud provider for 24+ hours
- Loss of key supplier (payroll, hosting, comms)
- Loss of premises
- Loss of a key person
Testing is non-negotiable
You must evidence at least one annual test. A tabletop exercise is fine for Level 1; Level 2 expects more rigour over the 3-year cycle. Capture: date, participants, scenario, what worked, what didn't, actions, owners, and follow-up review.
Backups and BCP are not the same thing
Backups are part of recovery. A plan that says "we have backups" without restore-test evidence, named recovery owners, and an actual procedure will fail. See the risk register guide for how recovery feeds back into risk.
