Business Continuity Management: Building Organizations That Absorb Shocks and Keep Moving

Business Continuity Management featured image

In July 2024, a faulty software update from a single security vendor grounded airlines, halted retail tills, and disrupted hospitals across the world. Nothing was breached, and nothing was stolen. The lesson of that day is the core lesson of business continuity: organizations depend on chains of technology and third parties whose failure modes do not care whose fault they are. What matters is how fast the organization can keep operating through the failure.

For South African organizations the point hardly needs making. Load shedding, cable theft, flooding, civil disruption, and ransomware have made interruption a recurring operating condition rather than a hypothetical. Business continuity management, or BCM, is the discipline that converts that reality from an existential threat into a managed risk.

At a glance

  • Interruption is expensive and common: Sophos’s annual ransomware survey puts average downtime after an attack at 24 days, with recovery costs averaging R24 million ($1.53 million) excluding any ransom.
  • Unpreparedness is the expensive option: organizations with tested incident response plans cut per-incident costs by 61%, an average saving of about R43 million ($2.66 million).
  • Continuity is a lifecycle, not a document: business impact analysis, strategy, plans, exercising, and improvement, run continuously in the manner of ISO 22301.
  • Recovery math is a leadership decision: recovery time and recovery point objectives, set against the maximum tolerable period of disruption, define how much resilience the business is buying.

Why Continuity Is a Strategic Capability

The economics are stark. Across industries, an hour of downtime costs mid-sized organizations R800,000 to R1.6 million ($50,000 to $100,000), with financial services losing roughly R42,000 per minute and manufacturing up to about R270,000 per minute. In 2025, 53% of ransomware victims recovered within a week, up from 22% in 2023, yet a significant minority still took more than a month to restore operations. The difference between those two groups is rarely luck. It is preparation: backups that are immutable, plans that are exercised, and people who have rehearsed the worst day of their professional lives in advance.

South African organizations know these numbers in their bones. Years of load shedding turned every business in the country into an involuntary continuity tester, and the July 2021 cyberattack on Transnet’s Durban container terminal halted cargo operations for days, forcing manual vessel logging and leaving trucks backed up outside the harbour. Continuity is not a theoretical discipline here. It is recent, local history.

Board attention follows. Regulators and insurers increasingly ask not whether an organization has a continuity plan, but when it was last exercised and what it proved. A plan that has never been tested is a hypothesis, and hypotheses fail at the worst possible time.

The Anatomy of a BCM Programme

Mature continuity programmes follow the discipline codified in ISO 22301. They begin with a business impact analysis, identifying which processes actually carry the organization’s revenue, safety, and legal obligations when they stop. They layer a risk assessment over that analysis, asking what could plausibly interrupt those processes and for how long. They then define continuity strategies: alternate sites and workloads, redundant suppliers, backup architectures, and the people arrangements that keep decisions flowing. Strategies become plans with named roles, invocation criteria, and communication trees. And plans are exercised and improved on a fixed rhythm, because every rehearsal surfaces an assumption that would otherwise have failed live.

Business continuity management lifecycle of five stages in a continuous loop
The BCM lifecycle: business impact analysis, risk assessment, continuity strategy, plan development, and testing and exercising, running as a continuous loop.

The lifecycle framing matters because continuity decays. Systems change, vendors change, people change jobs, and the plan that was accurate eighteen months ago is quietly wrong today. Treating BCM as an annual document refresh is how organizations end up invoking a map of a city that no longer exists.

The Recovery Math: RTO, RPO, and MTPD

Three numbers govern every continuity investment. The recovery time objective, or RTO, is how long a process can be down before the damage becomes unacceptable. The recovery point objective, or RPO, is how much data the organization can afford to lose, measured backwards from the moment of failure to the last recoverable copy. The maximum tolerable period of disruption, or MTPD, is the hard ceiling beyond which the organization’s viability, licence, or duty of care is in question. Set these deliberately and every technical choice, from backup frequency to failover architecture, becomes a consequence of a business decision rather than an accident of procurement.

Timeline of an incident showing recovery point objective and recovery time objective against maximum tolerable disruption
An interruption timeline: the RPO measures back to the last recoverable data point, the RTO spans from failure to restored service, and the MTPD marks the outer limit the business can tolerate.

The research shows what these disciplines are worth in practice. Regular backup testing is associated with recovery fifteen days faster, immutable backups with ten days faster, and formal incident response plans with twelve days faster. Preparation does not just reduce loss. It compresses the incident itself.

Making It Real: People, Communication, and the Supply Chain

Continuity is often treated as a technology programme with a human appendix. In practice, the hardest hours of any incident are organizational: who declares the crisis, who speaks to customers, who decides to fail over, and how teams coordinate when the primary tools they coordinate with are the tools that are down. Exercising must therefore rehearse decisions and communication, not just restoration. It must also reach outward: with third-party failure now among the most common interruption modes, continuity due diligence belongs in vendor contracts, not just in the vendor questionnaire.

What Leaders Should Do Now

1. Commission a real business impact analysis. Rank processes by revenue, safety, and legal exposure per hour of downtime. Everything else in the programme depends on this being true rather than assumed.

2. Set RTO and RPO for the crown jewels, and fund them. Recovery objectives are business decisions with price tags. Making them explicit turns resilience from a wish into a budget line.

3. Exercise twice a year, at least once with executives in the room. A tabletop that surfaces three broken assumptions is worth more than a hundred-page plan nobody has opened.

4. Harden the data layer. Immutable, regularly tested backups are the single most proven recovery accelerator in the data.

5. Extend continuity to third parties. Identify the vendors whose failure becomes your outage, and contract for notification, assistance, and exit before you need any of them.


Sources: Sophos State of Ransomware 2025; Statista and Halcyon ransomware downtime analyses 2025; IBM Cost of a Data Breach Report 2025; ISO 22301 business continuity management systems standard.

The organizations that walk out of disruptions with their reputations intact are almost never the ones that were lucky. They are the ones that decided, in advance, what they would protect, how fast they would recover, and who would do what when the lights went out. That is the discipline Lebone Marang and Summer builds with executives: continuity strategies that are exercised, measured, and owned at the right level. If your organization’s answer to a week without its core systems is currently a shrug, that is a conversation worth having today.

Facebook
Twitter
WhatsApp
Email