Cookies verwalten
Diese Website verwendet Cookies, um Informationen über Ihr Surfverhalten zu sammeln. So können wir Ihnen relevantere Inhalte und Werbematerialien bereitstellen und Ihre Interessen besser verstehen, um die Website zu verbessern. Weitere Informationen finden Sie in unserer Cookie-Richtlinie
Cookies verwalten
Cookie-Einstellungen
Für den ordnungsgemäßen Betrieb der Website notwendige Cookies sind immer aktiviert.
Andere Cookies sind konfigurierbar.
Essenzielle Cookies
Immer aktiv. Diese Cookies sind unerlässlich, damit Sie die Website und ihre Funktionen nutzen können. Sie können nicht deaktiviert werden. Sie werden als Reaktion auf Ihre Anfragen gesetzt, beispielsweise beim Festlegen Ihrer Datenschutzeinstellungen, beim Anmelden oder beim Ausfüllen von Formularen.
Analyse-Cookies
Deaktiviert
Diese Cookies sammeln Informationen, die uns helfen zu verstehen, wie unsere Websites genutzt werden, wie effektiv unsere Marketingkampagnen sind und wie wir unsere Websites für Sie personalisieren können. Eine Liste der von uns verwendeten Analyse-Cookies finden Sie hier.
Werbe-Cookies
Deaktiviert
Diese Cookies liefern Werbeunternehmen Informationen über Ihre Online-Aktivitäten, damit diese Ihnen relevantere Werbung anzeigen oder die Häufigkeit der Anzeigenschaltung begrenzen können. Diese Informationen können an andere Werbeunternehmen weitergegeben werden. Eine Liste der von uns verwendeten Werbe-Cookies finden Sie hier.
Übungen zur Geschäftskontinuität | Resilience Guard GmbH
Home / Consulting / Business Continuity Exercises

Business continuity exercising

An unexercised plan is a hypothesis.

Tabletop, functional, cyber and full scale exercises that prove your plans work, sharpen the people behind them, and produce the evidence ISO 22301, NIS2 and DORA expect.

What is a business continuity exercise?

A business continuity exercise is a controlled rehearsal of how your organisation responds to disruption. It takes the plans you have written, a cyber attack, a site loss, a supplier failure, a data centre outage, and tests them against a realistic scenario, with the people who would actually have to respond. The output is evidence: what held, what failed, and what to fix before reality runs the test for you.

Exercising is also an obligation. ISO 22301 requires a standing exercise programme, NIS2 expects continuity and crisis measures whose effectiveness is assessed, and DORA requires financial entities to test digital operational resilience against severe but plausible scenarios. One well designed exercise produces the assurance and the audit trail at the same time.

4
Exercise formats, tabletop to full scale
3
Regimes evidenced: ISO 22301, NIS2, DORA
12
Industries we serve and exercise
1
Board ready report after every exercise

The exercise ladder

Four formats, from low disruption to full realism. Most programmes climb the ladder over time: each rung builds the confidence, and the evidence, for the next.

The exercise ladder Four exercise formats ascend from tabletop to functional to cyber crisis to full scale. Realism and disruption increase along the ladder, and so does the assurance gained. REALISM AND DISRUPTION ASSURANCE GAINED 01 · TABLETOP Talk the plan through Leadership, low disruption 02 · FUNCTIONAL Test one capability for real Teams and systems in scope 03 · CYBER CRISIS Face a live cyber attack IT, comms and leadership 04 · FULL SCALE Activate end to end Sites, systems and people The exercise ladder Four exercise formats from tabletop to full scale. Realism, disruption and assurance increase down the ladder. REALISM, DISRUPTION AND ASSURANCE INCREASE 01 · TABLETOP Talk the plan through Leadership, low disruption 02 · FUNCTIONAL Test one capability for real Teams and systems in scope 03 · CYBER CRISIS Face a live cyber attack IT, comms and leadership 04 · FULL SCALE Activate end to end Sites, systems and people

The formats, compared

Which exercise fits depends on what you need to prove, to whom, and how much disruption you can absorb.

FormatWho is in the roomTypical durationWhat it proves
Tabletop exerciseExecutive and crisis teams around one tableHalber TagRoles, decisions and escalation paths are understood, and the plan holds as a document.
Functional exerciseOne team or capability, with its real toolsHalf to one dayA specific capability, such as IT recovery, relocation or emergency communications, works in practice.
Cyber crisis exerciseIT, security, communications and leadership togetherOne dayThe organisation can decide, communicate and recover under a realistic cyber scenario such as ransomware.
Full scale exerciseMultiple teams, sites and systems, liveOne to two daysThe whole response works end to end under conditions close to a real disruption.

How an exercise runs

Six steps, from scoping to the corrective actions that feed the next cycle. Designed and facilitated by practitioners who have managed real crises.

Step 1
Scope and objectives
What must be proven, for which plans, teams and obligations. Success criteria agreed with you up front.
Step 2
Scenario and inject design
A severe but plausible scenario from our library, tailored to your industry, with a timed sequence of injects.
Step 3
Delivery and facilitation
Run by senior practitioners who have managed real crises, with trained observers scoring against the criteria.
Step 4
Hot debrief
Immediate structured feedback while the experience is fresh, captured from every team in the exercise.
Step 5
Evaluation report
A board ready report: what held, what failed, evidence for ISO 22301, NIS2 and DORA, and a corrective action plan.
Step 6
Corrective actions into the next cycle
Findings update your plans and training, and set the objectives of the next exercise. Assurance compounds.

Scenarios that feel real

Scenarios come from our library and are tailored to your industry and threat profile. They are severe but plausible: hard enough to expose weaknesses, close enough to reality that the lessons transfer.

  • Ransomware and destructive cyber attack
  • Site loss and denial of access
  • Critical supplier or shared platform failure
  • IT and data centre outage
  • Power and utilities disruption
  • Workforce absence and pandemic conditions

How often to exercise

Tabletop exerciseevery 6 months
Functional exerciseevery 12 months
Cyber crisis exerciseevery 12 months
Full scale exerciseevery 18 to 24 months

Typical intervals between exercises of each format. Your cadence is calibrated to your risk profile, regulatory obligations and maturity during scoping.

What the regulators and standards expect

One exercise, run properly, produces the evidence several regimes ask for.

RahmenWhat it expectsWhat the exercise gives you
ISO 22301An exercise programme that validates continuity strategies and plans over time (Clause 8.5).A documented exercise record, evaluation report and corrective actions, ready for certification audits. See our BCM service.
NIS2Business continuity and crisis management among the Article 21 measures, with their effectiveness assessed.Evidence that continuity and crisis arrangements are tested, not just written. See our NIS2 service.
DORAA digital operational resilience testing programme for financial entities, including severe but plausible scenarios.Response and recovery tested against realistic ICT disruption, with board ready reporting. See our DORA service.
EASA Part-ISTested readiness to detect and respond to information security events in aviation.Aviation scenarios exercised across operations and information security. Read our Part-IS guide.
Swiss ISGResilient arrangements for critical infrastructure operators in Switzerland.Exercised response arrangements that stand up to regulator scrutiny. Read our Swiss ISG guide.

Häufig gestellte Fragen

What is a business continuity exercise?
A controlled rehearsal of your organisation's response to disruption. It tests real plans and real people against a realistic scenario, and produces evidence of what held, what failed and what to fix.
What is the difference between a tabletop and a full scale exercise?
A tabletop talks the plan through around one table with low disruption. A full scale exercise activates teams, sites and systems live, end to end. Most organisations climb from tabletop to full scale over successive exercises.
How often should we exercise?
As a rule of thumb: tabletops every six months, functional and cyber crisis exercises annually, and a full scale exercise every eighteen to twenty four months. The right cadence depends on your risk profile and regulatory obligations, and is agreed during scoping.
Do exercises satisfy ISO 22301, NIS2 and DORA requirements?
They produce the evidence those regimes ask for. ISO 22301 requires a standing exercise programme, NIS2 expects the effectiveness of continuity and crisis measures to be assessed, and DORA requires resilience testing against severe but plausible scenarios. Each exercise ends with a documented evaluation report and corrective action plan.
Will an exercise disrupt our operations?
Only as much as you choose. Tabletops are near zero disruption. Functional and full scale exercises are scoped with you so that realism is maximised while operations stay protected.
Who designs and runs the exercise?
Senior Resilience Guard practitioners who have managed real crises, supported by trained observers who score the exercise against agreed criteria.

Entdecken Sie mehr

Verwandte Dienstleistungen

CONTINUITY AND RESILIENCE

Geschäftskontinuitätsmanagement

BIA, ISO 22301-konforme Strategie, Pläne und Validierung: ein Kontinuitätsprogramm, das so konzipiert ist, dass es auch bei einer echten Störung bestehen kann.

Den Service entdecken ›
REGULATION AND CRISIS

Krisenmanagement

Doktrin, Strukturen und Kommunikationsmaßnahmen, die den Höhepunkt eindämmen und die Erholung verkürzen, verankert in ISO 22361.

Den Service entdecken ›
CONTINUITY AND RESILIENCE

Organisatorische Resilienz

Die Struktur über den Plänen: Risiko, Kontinuität, Krise, Cyber ​​und Personal auf einer gemeinsamen Grundlage gemäß ISO 22316.

Den Service entdecken ›
CYBER AND SECURITY

Cyberresilienz

Über die Prävention hinaus: die Fähigkeit, Widerstand zu leisten, zu reagieren und sich zu erholen, während die grundlegenden Dienstleistungen weiterlaufen.

Den Service entdecken ›
CYBER AND SECURITY

Informationssicherheit

Vertraulichkeit, Integrität und Verfügbarkeit werden durch ein lebendiges ISMS geschützt, das auf ISO 27001 ausgerichtet ist.

Den Service entdecken ›
CYBER AND SECURITY

Lieferkettensicherheit

Das Risiko, das Sie von Lieferanten und gemeinsam genutzten Plattformen übernehmen: erfasst, zugesichert, vertraglich festgelegt und ausgeübt, gemäß ISO 28000, NIS2 und DORA.

Den Service entdecken ›
REGULATION AND CRISIS

NIS2-Konformität

Von der Festlegung des Anwendungsbereichs bis hin zu den Maßnahmen nach Artikel 21 und der 24-Stunden-Meldebereitschaft gemäß Richtlinie (EU) 2022/2555.

Den Service entdecken ›
RISK AND GOVERNANCE

Risikomanagement

Vom Risikouniversum zum kontrollierten Risiko: Identifizierung, stressbewusste Bewertung, eigenverantwortliche Behandlung und Live-Überwachung.

Den Service entdecken ›
RISK AND GOVERNANCE

7A Risikomanagement-Rahmenwerk

Unser firmeneigenes, entscheidungsorientiertes Betriebsmodell: Exposition und Entscheidungssicherheit werden für den Vorstand separat gemessen.

Den Service entdecken ›
RISK AND GOVERNANCE

KI-Governance und Resilienz

Governance ist in jede Ebene intelligenter Systeme integriert, vom Modellverhalten bis zur Rechenschaftspflicht des Vorstands und der ISO 42001.

Den Service entdecken ›
SECTOR FRAMEWORK

DAEDALUS Flughafen-Resilienz-Rahmenwerk

Das Airport Resilience Framework: fünf Domänen als ein Betriebsmodell für den gesamten Flugplatz, angetrieben vom 7A-Motor, in den Editionen für kommerzielle Luftfahrt, Fracht- und Geschäftsluftfahrt.

Den Service entdecken ›

Find out whether your plans survive contact.

Tell us what you need to prove, to your board, your auditor or your regulator, and we will design the exercise that proves it. Conversations are confidential.