ISO 22301-aligned BCDR. Plans you can actually use.
Business impact analysis, RTO/RPO definition, plan authoring, tabletop exercises and review cycles. Aligned to ISO 22301:2019 and ISO/IEC 27031:2025 ICT readiness guidance.
What we mean by BCDR
Business Continuity and Disaster Recovery is the structured work of figuring out what your organisation has to keep doing during a disruption, what it can tolerate losing, and how it gets back to normal. The output is plans people can use under pressure — not binders that sit in a cabinet.
Programmes are aligned to ISO 22301:2019, the international standard for business continuity management systems, and to ISO/IEC 27031:2025 for ICT readiness for business continuity (the current revision that supersedes the 2011 edition). We deliver the programme to be certification-ready whether you choose to certify or not.
Key facts
- ISO BCMS
- 22301
- ICT readiness
- 27031
- Programme stages
- 5
- Test cadence
- Annual
What we do
Four service pillars covering the BCDR lifecycle — from first BIA through annual exercise.
Business Impact Analysis
Identify critical processes, dependencies and disruption tolerance. Quantified outputs that drive RTO/RPO decisions.
RTO / RPO definition
Recovery Time Objective and Recovery Point Objective per critical process, agreed with leadership and stress-tested in exercises.
Plan authoring
Documented recovery strategies, runbooks, communications plan, roles and responsibilities. Written to be usable at 02:00, not just to file.
Tabletop exercises
Facilitated exercises with leadership and key responders. Findings logged and tracked through to resolution.
How a programme runs
Five stages from scoping to annual review. Most engagements run the full programme; some pick up at exercise or maintenance.
- 1
Scoping call
30 minutes, freeCritical processes, dependencies, regulatory drivers, existing plans. We do not start with the framework — we start with what would actually break if you lost a building or a supplier.
- 2
Business Impact Analysis
Scope-dependentProcess criticality, RTO/RPO drafting, dependency mapping. Output is the data layer the rest of the programme is built on.
- 3
Strategy & plan authoring
Scope-dependentRecovery strategies, runbooks, communications plan, test plan. Plans aligned to ISO 22301:2019 management-system structure and ISO/IEC 27031:2025 ICT readiness.
- 4
Tabletop exercise
1 weekFacilitated exercise with leadership and key responders. Findings logged. Action items assigned to named owners with deadlines.
- 5
Review & maintenance
AnnualAnnual review cycle and plan updates after material change. Optional ongoing retainer for plan maintenance and exercise facilitation.
The five-stage programme
The structure of a BCDR programme aligned to ISO 22301:2019 and ISO/IEC 27031:2025.
Why 1 Sequence Cyber
Standards-aligned, certification-ready
Programmes are aligned to ISO 22301:2019 (the international BCMS standard) and ISO/IEC 27031:2025 (ICT readiness for business continuity, the current revision that supersedes the 2011 edition). Outputs map cleanly into ISO 22301 certification audit evidence.
Integrated with the wider security programme
BCDR is not a standalone activity. It overlaps with ISO 27001:2022 Annex A 5.29 and 5.30 (information security continuity), with PCI DSS Requirement 12.10 (incident response), and with UK GDPR Article 32 (availability). We deliver the programme as part of an integrated security view rather than a single-purpose silo.
Ready to scope a BCDR programme?
Tell us your critical processes, your existing plans (if any), and what is driving the requirement. We’ll come back with a proposal within 48 hours.
Back to all services.