+31 88 8040 777

Stay operational when things go wrong, with a solid continuity plan

Business Continuity Management (BCM) ensures that your organization can keep functioning even during a crisis, a cyber incident or the failure of critical systems. ZETA delivers the full process: from BCM policy to a working Business Continuity Plan (BCP) and exercises.

BCM / BCP
ISO 22301 / NIS2
BIA basis
BCM policy
BCP plan
Exercises

BCM vs. BCP, what is the difference?

Two concepts that are connected but each play their own role

The system

BCM

Business Continuity Management
  • What: The overarching management system and policy
  • Scope: Strategy, governance, roles and cycle
  • Standard: ISO 22301 (the international BCM standard)
  • Lifespan: Continuous, the policy is reviewed periodically
  • ZETA delivers: BCM policy document, roles & responsibilities
The plan

BCP

Business Continuity Plan
  • What: The operational plan with procedures and concrete actions
  • Scope: A step-by-step approach per scenario (outage, fire, cyberattack)
  • Standard: Part of BCM; also a NIS2 requirement
  • Lifespan: Per crisis type; tested at least annually
  • ZETA delivers: A BCP document per critical scenario + exercise plan

What does a BCM/BCP process deliver?

From policy document to working plan, ready for NIS2 and ISO 22301

BCM policy & governance

A documented BCM policy with objectives, scope, roles and responsibilities. The basis for every audit and the proof that you take continuity seriously.

Working BCP document

For each critical scenario (cyber incident, fire, data center outage, supplier failure) a concrete plan: who does what, in what order, with which resources and contacts.

Roles & communication

Crisis team composition, escalation paths, a communication protocol towards employees, customers and the press. Including contact lists and decision trees for crisis situations.

Exercises & testing

A plan without a test is not a plan. ZETA guides tabletop exercises and realistic crisis simulations to check whether the BCP really works under pressure.

Building on the BIA

The BCM/BCP process builds directly on the results of a Business Impact Analysis: critical processes, RTO/RPO and dependencies have already been established.

NIS2 & ISO 22301

NIS2 requires organizations to have a documented continuity policy. ISO 22301 is the international standard. ZETA delivers documentation that aligns with both.

Annual review

Organizations change, and so do threats. ZETA offers a maintenance subscription for the annual review of the BCM policy and BCP, so that it stays up to date.

Audit-ready evidence

All documents are prepared in line with audit requirements: version control, approval history, test reports. Ready for use during NIS2 supervision, ISO audits or insurance acceptance.

Our BCM/BCP approach

Structured, practical and tailored to your organization

Step 1: BIA & risk analysis

If no BIA is available yet, we start here. Critical processes, RTO/RPO and financial impact are established as the basis for the BCP.

Step 2: BCM strategy

Together we determine the continuity strategy: which recovery solutions, which fallback options, which priorities. Governance, roles and the communication structure are defined.

Step 3: BCP documentation

For each critical scenario a fully worked-out BCP: a step-by-step plan, those responsible, contact lists, escalation paths and communication templates.

Step 4: Exercise & improve

A tabletop exercise or a full crisis simulation. The findings lead directly to improvements in the BCP. ZETA guides the evaluation and documents the test results.

Ready for when things go wrong?

Fill in the form for a no-obligation conversation about BCM/BCP