Skip to main content
    NixInfinity-AI
    Business Continuity

    Business Continuity for Cyber Assurance: What Assessors Want

    Published 15 May 2026

    The two numbers everything hinges on

    • RTO (Recovery Time Objective) – how quickly a function must be back up.
    • RPO (Recovery Point Objective) – how much data loss is tolerable.

    Set these per business function, agreed with the function owner – not by IT in isolation.

    What the plan must contain

    1. Critical business functions and their RTO/RPO
    2. Dependencies (people, systems, suppliers, premises)
    3. Disruption scenarios (cyber incident, supplier outage, premises loss, key person)
    4. Recovery procedures for each scenario
    5. Communications plan (staff, customers, regulators, ICO if applicable)
    6. Roles and responsibilities (named individuals, with deputies)
    7. Invocation criteria and authority
    8. Testing schedule and most recent test evidence

    Scenarios assessors expect you to cover

    • Ransomware that encrypts production data
    • Loss of primary cloud provider for 24+ hours
    • Loss of key supplier (payroll, hosting, comms)
    • Loss of premises
    • Loss of a key person

    Testing is non-negotiable

    You must evidence at least one annual test. A tabletop exercise is fine for Level 1; Level 2 expects more rigour over the 3-year cycle. Capture: date, participants, scenario, what worked, what didn't, actions, owners, and follow-up review.

    Backups and BCP are not the same thing

    Backups are part of recovery. A plan that says "we have backups" without restore-test evidence, named recovery owners, and an actual procedure will fail. See the risk register guide for how recovery feeds back into risk.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions