1. Learn
  2. Align
  3. Perform
  4. Review

Align9 min read

When the Lights Go Out: What ISO 22301 Actually Does for Your Business

By J Damien Scott, Trusted Advisor

ISO 22301 is the international standard for business continuity management. This article explains what it actually requires, why it belongs in the boardroom rather than the risk register, and how to start applying its thinking before you pursue certification.

What the Standard Is, in Plain Terms

ISO 22301 sets out the requirements for a business continuity management system, often shortened to BCMS. It is published by the International Organization for Standardization, and its current edition dates from 2019. By ISO's own account, it applies to organizations of all sizes and types across the private, public, and not-for-profit sectors. A management system is simply a structured way of setting objectives, meeting them, measuring the result, and improving. ISO 22301 applies that discipline to one goal: keeping your most important products and services running through a disruption.

It is worth being clear about what the standard does not do. It does not tell you how long your systems may be down or dictate a single technology. Instead, it gives you a repeatable framework for deciding those things yourself, based on your own analysis, and then proving that your arrangements work. Because the requirements are written in auditable 'shall' language, an independent body can certify your system, which gives customers, regulators, and partners a credible signal that your continuity plans are real.

Resilience is not the absence of disruption. It is the ability to keep serving customers when disruption arrives, and to recover before the harm compounds.

Why Leaders Should Care

Business continuity is often filed under compliance and left there. That is a costly habit, because the downside of being unprepared is measurable. The U.S. Federal Emergency Management Agency has estimated that roughly 40 percent of small businesses never reopen after a disaster, with more closing in the year that follows. Preparation does not remove the threat, but it materially changes the odds of recovery.

Two further forces are pushing continuity onto the executive agenda. The first is customer expectation. Large buyers increasingly ask suppliers to demonstrate continuity arrangements during procurement, and certification is a clean way to provide that evidence. The second is regulation, which in many sectors now expects a demonstrable continuity capability rather than a paper plan. The tangible payoff of the standard is not the certificate itself. It is the shorter outage, the customer you keep, and the reputation you protect.

How It Works: The Ideas That Matter

Strip away the clause numbers and ISO 22301 rests on a few practical ideas that any leader can grasp. The standard begins with a business impact analysis, or BIA. This is the exercise of identifying which activities are most time-critical and how quickly each must recover before the harm becomes unacceptable. Not everything is equally urgent. Payroll can wait a day; a payment platform cannot wait an hour. The BIA forces that honest ranking.

From the analysis come a handful of defined objectives that drive every later decision. The recovery time objective is how fast an activity must be back. The recovery point objective is how much recent data you can afford to lose, which decides how often you back up. The minimum business continuity objective is the reduced but acceptable level of service you sustain while you recover. These targets turn a general wish to be resilient into measurable commitments.

Once you know what must recover and how fast, you select practical arrangements: alternate sites, remote working, resilient technology, a second supplier, tested backups. ISO's guidance recommends weighing each option against the impact it is meant to avoid. A continuity plan has little value if it is long, generic, or stored only on the system that just failed. Good plans are short, specific, and available offline when an incident hits.

This is the step many organizations skip and later regret. An untested plan is an assumption, not a capability. Regular exercises, from tabletop discussions to full failovers, are the most reliable way to find gaps while the stakes are low. The standard runs on a continual improvement cycle. Every exercise, audit, and real incident feeds lessons back into the system, so the organization gets steadily better rather than filing plans that quietly go out of date.

Getting Started

You do not need certification to benefit from the thinking behind ISO 22301. A leadership team can begin this quarter by asking three questions. Which products and services would hurt us most if they stopped? How quickly must each recover, and can we actually do it? When did we last test that answer under realistic conditions? Honest responses usually reveal a gap worth closing.

For organizations that do pursue certification, the route is well established. An accredited certification body assesses the system in two stages, a readiness review followed by a deeper implementation audit, and the resulting certificate is valid for three years, subject to annual surveillance audits. Because ISO 22301 shares its structure with standards such as ISO 27001 for information security, it integrates cleanly with systems you may already run.

The Bottom Line

Resilience is not the absence of disruption. It is the ability to keep serving customers when disruption arrives, and to recover before the harm compounds. ISO 22301 gives that ambition a method. It replaces hope with analysis, plans with practiced capability, and good intentions with evidence. For any leader who has wondered what would really happen if the lights went out, that is a conversation worth having before the answer is tested for you.

GRCISO 22301Business ContinuityResilienceRisk ManagementGRC

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes