Business continuity exercising
An unexercised plan is a hypothesis.
Tabletop, functional, cyber and full scale exercises that prove your plans work, sharpen the people behind them, and produce the evidence ISO 22301, NIS2 and DORA expect.
What is a business continuity exercise?
A business continuity exercise is a controlled rehearsal of how your organisation responds to disruption. It takes the plans you have written, a cyber attack, a site loss, a supplier failure, a data centre outage, and tests them against a realistic scenario, with the people who would actually have to respond. The output is evidence: what held, what failed, and what to fix before reality runs the test for you.
Exercising is also an obligation. ISO 22301 requires a standing exercise programme, NIS2 expects continuity and crisis measures whose effectiveness is assessed, and DORA requires financial entities to test digital operational resilience against severe but plausible scenarios. One well designed exercise produces the assurance and the audit trail at the same time.
The exercise ladder
Four formats, from low disruption to full realism. Most programmes climb the ladder over time: each rung builds the confidence, and the evidence, for the next.
The formats, compared
Which exercise fits depends on what you need to prove, to whom, and how much disruption you can absorb.
| Format | Who is in the room | Typical duration | What it proves |
|---|---|---|---|
| Tabletop exercise | Executive and crisis teams around one table | Halber Tag | Roles, decisions and escalation paths are understood, and the plan holds as a document. |
| Functional exercise | One team or capability, with its real tools | Half to one day | A specific capability, such as IT recovery, relocation or emergency communications, works in practice. |
| Cyber crisis exercise | IT, security, communications and leadership together | One day | The organisation can decide, communicate and recover under a realistic cyber scenario such as ransomware. |
| Full scale exercise | Multiple teams, sites and systems, live | One to two days | The whole response works end to end under conditions close to a real disruption. |
How an exercise runs
Six steps, from scoping to the corrective actions that feed the next cycle. Designed and facilitated by practitioners who have managed real crises.
Scenarios that feel real
Scenarios come from our library and are tailored to your industry and threat profile. They are severe but plausible: hard enough to expose weaknesses, close enough to reality that the lessons transfer.
- Ransomware and destructive cyber attack
- Site loss and denial of access
- Critical supplier or shared platform failure
- IT and data centre outage
- Power and utilities disruption
- Workforce absence and pandemic conditions
How often to exercise
Typical intervals between exercises of each format. Your cadence is calibrated to your risk profile, regulatory obligations and maturity during scoping.
What the regulators and standards expect
One exercise, run properly, produces the evidence several regimes ask for.
| Rahmen | What it expects | What the exercise gives you |
|---|---|---|
| ISO 22301 | An exercise programme that validates continuity strategies and plans over time (Clause 8.5). | A documented exercise record, evaluation report and corrective actions, ready for certification audits. See our BCM service. |
| NIS2 | Business continuity and crisis management among the Article 21 measures, with their effectiveness assessed. | Evidence that continuity and crisis arrangements are tested, not just written. See our NIS2 service. |
| DORA | A digital operational resilience testing programme for financial entities, including severe but plausible scenarios. | Response and recovery tested against realistic ICT disruption, with board ready reporting. See our DORA service. |
| EASA Part-IS | Tested readiness to detect and respond to information security events in aviation. | Aviation scenarios exercised across operations and information security. Read our Part-IS guide. |
| Swiss ISG | Resilient arrangements for critical infrastructure operators in Switzerland. | Exercised response arrangements that stand up to regulator scrutiny. Read our Swiss ISG guide. |
Prefer to build the capability in house?
We also train your own people to design and run exercises, through our accredited training practice.
Krisenmanagementübungen
Learn to design, run and evaluate crisis exercises inside your own organisation.
Programm entdecken › AusbildungTop Team Simulations
High pressure simulations for executive teams and boards.
Programm entdecken › AusbildungOperation HELVETIA
Our flagship immersive exercise experience.
Programm entdecken ›Häufig gestellte Fragen
What is a business continuity exercise?
What is the difference between a tabletop and a full scale exercise?
How often should we exercise?
Do exercises satisfy ISO 22301, NIS2 and DORA requirements?
Will an exercise disrupt our operations?
Who designs and runs the exercise?
Entdecken Sie mehr
Verwandte Dienstleistungen
Geschäftskontinuitätsmanagement
BIA, ISO 22301-konforme Strategie, Pläne und Validierung: ein Kontinuitätsprogramm, das so konzipiert ist, dass es auch bei einer echten Störung bestehen kann.
Den Service entdecken ›REGULATION AND CRISISKrisenmanagement
Doktrin, Strukturen und Kommunikationsmaßnahmen, die den Höhepunkt eindämmen und die Erholung verkürzen, verankert in ISO 22361.
Den Service entdecken ›CONTINUITY AND RESILIENCEOrganisatorische Resilienz
Die Struktur über den Plänen: Risiko, Kontinuität, Krise, Cyber und Personal auf einer gemeinsamen Grundlage gemäß ISO 22316.
Den Service entdecken ›CYBER AND SECURITYCyberresilienz
Über die Prävention hinaus: die Fähigkeit, Widerstand zu leisten, zu reagieren und sich zu erholen, während die grundlegenden Dienstleistungen weiterlaufen.
Den Service entdecken ›CYBER AND SECURITYInformationssicherheit
Vertraulichkeit, Integrität und Verfügbarkeit werden durch ein lebendiges ISMS geschützt, das auf ISO 27001 ausgerichtet ist.
Den Service entdecken ›CYBER AND SECURITYLieferkettensicherheit
Das Risiko, das Sie von Lieferanten und gemeinsam genutzten Plattformen übernehmen: erfasst, zugesichert, vertraglich festgelegt und ausgeübt, gemäß ISO 28000, NIS2 und DORA.
Den Service entdecken ›REGULATION AND CRISISNIS2-Konformität
Von der Festlegung des Anwendungsbereichs bis hin zu den Maßnahmen nach Artikel 21 und der 24-Stunden-Meldebereitschaft gemäß Richtlinie (EU) 2022/2555.
Den Service entdecken ›RISK AND GOVERNANCERisikomanagement
Vom Risikouniversum zum kontrollierten Risiko: Identifizierung, stressbewusste Bewertung, eigenverantwortliche Behandlung und Live-Überwachung.
Den Service entdecken ›RISK AND GOVERNANCE7A Risikomanagement-Rahmenwerk
Unser firmeneigenes, entscheidungsorientiertes Betriebsmodell: Exposition und Entscheidungssicherheit werden für den Vorstand separat gemessen.
Den Service entdecken ›RISK AND GOVERNANCEKI-Governance und Resilienz
Governance ist in jede Ebene intelligenter Systeme integriert, vom Modellverhalten bis zur Rechenschaftspflicht des Vorstands und der ISO 42001.
Den Service entdecken ›SECTOR FRAMEWORKDAEDALUS Flughafen-Resilienz-Rahmenwerk
Das Airport Resilience Framework: fünf Domänen als ein Betriebsmodell für den gesamten Flugplatz, angetrieben vom 7A-Motor, in den Editionen für kommerzielle Luftfahrt, Fracht- und Geschäftsluftfahrt.
Den Service entdecken ›Find out whether your plans survive contact.
Tell us what you need to prove, to your board, your auditor or your regulator, and we will design the exercise that proves it. Conversations are confidential.