Business Continuity & DR

ISO 22301-aligned BCDR. Plans you can actually use.

Business impact analysis, RTO/RPO definition, plan authoring, tabletop exercises and review cycles. Aligned to ISO 22301:2019 and ISO/IEC 27031:2025 ICT readiness guidance.

What we mean by BCDR

Business Continuity and Disaster Recovery is the structured work of figuring out what your organisation has to keep doing during a disruption, what it can tolerate losing, and how it gets back to normal. The output is plans people can use under pressure — not binders that sit in a cabinet.

Programmes are aligned to ISO 22301:2019, the international standard for business continuity management systems, and to ISO/IEC 27031:2025 for ICT readiness for business continuity (the current revision that supersedes the 2011 edition). We deliver the programme to be certification-ready whether you choose to certify or not.

Key facts

ISO BCMS
22301
ICT readiness
27031
Programme stages
5
Test cadence
Annual

What we do

Four service pillars covering the BCDR lifecycle — from first BIA through annual exercise.

Business Impact Analysis

Identify critical processes, dependencies and disruption tolerance. Quantified outputs that drive RTO/RPO decisions.

RTO / RPO definition

Recovery Time Objective and Recovery Point Objective per critical process, agreed with leadership and stress-tested in exercises.

Plan authoring

Documented recovery strategies, runbooks, communications plan, roles and responsibilities. Written to be usable at 02:00, not just to file.

Tabletop exercises

Facilitated exercises with leadership and key responders. Findings logged and tracked through to resolution.

How a programme runs

Five stages from scoping to annual review. Most engagements run the full programme; some pick up at exercise or maintenance.

  1. 1

    Scoping call

    30 minutes, free

    Critical processes, dependencies, regulatory drivers, existing plans. We do not start with the framework — we start with what would actually break if you lost a building or a supplier.

  2. 2

    Business Impact Analysis

    Scope-dependent

    Process criticality, RTO/RPO drafting, dependency mapping. Output is the data layer the rest of the programme is built on.

  3. 3

    Strategy & plan authoring

    Scope-dependent

    Recovery strategies, runbooks, communications plan, test plan. Plans aligned to ISO 22301:2019 management-system structure and ISO/IEC 27031:2025 ICT readiness.

  4. 4

    Tabletop exercise

    1 week

    Facilitated exercise with leadership and key responders. Findings logged. Action items assigned to named owners with deadlines.

  5. 5

    Review & maintenance

    Annual

    Annual review cycle and plan updates after material change. Optional ongoing retainer for plan maintenance and exercise facilitation.

The five-stage programme

The structure of a BCDR programme aligned to ISO 22301:2019 and ISO/IEC 27031:2025.

Why 1 Sequence Cyber

Standards-aligned, certification-ready

Programmes are aligned to ISO 22301:2019 (the international BCMS standard) and ISO/IEC 27031:2025 (ICT readiness for business continuity, the current revision that supersedes the 2011 edition). Outputs map cleanly into ISO 22301 certification audit evidence.

Integrated with the wider security programme

BCDR is not a standalone activity. It overlaps with ISO 27001:2022 Annex A 5.29 and 5.30 (information security continuity), with PCI DSS Requirement 12.10 (incident response), and with UK GDPR Article 32 (availability). We deliver the programme as part of an integrated security view rather than a single-purpose silo.

Frequently asked questions

Related services: incident response · SOC as a Service · ISO 27001.

Ready to scope a BCDR programme?

Tell us your critical processes, your existing plans (if any), and what is driving the requirement. We’ll come back with a proposal within 48 hours.

Back to all services.