Glossary · OT cybersecurity
Business continuity
Also known as: Business continuity management (BCM)
German: Geschäftskontinuität
In management systems, business continuity is the capability of an organization to continue delivering products and services at acceptable predefined levels during and after a disruption. Business continuity management plans for disruptions such as cyberattacks, equipment failures or supply outages.
- OT security
- Standards
In one sentence
Business continuity is an organization's capability to keep delivering products and services at acceptable levels during and after a disruption.
Example
The continuity plan of a food manufacturer defines how long each line may be down after a ransomware attack and which lines are restored first.
How it applies
- Planning: A business impact analysis identifies critical production processes, the maximum tolerable downtime and the dependencies on OT systems, suppliers and people. ISO 22301 describes the requirements for a business continuity management system.
- Operation: OT incidents often hit continuity harder than IT incidents because production stops. Continuity plans should include manual or degraded operation where it is safe, and the conditions under which a plant must stay shut down.
- Compliance: NIS 2 lists business continuity, including backup management, disaster recovery and crisis management, among the cybersecurity risk-management measures for covered entities.
- Documentation: Operating documentation supports continuity when it describes safe shutdown, restart after an unplanned stop and restore procedures in a form that works under stress, for example on paper or offline copies that remain available during an IT outage.
Business continuity vs. disaster recovery
Business continuity keeps the business running during a disruption, including workarounds and communication. Disaster recovery is the narrower technical task of restoring systems and data.