Continuity Strategy

Business Continuity Strategy Guide: From BIA to Feasible Recovery

Continuity strategy converts BIA requirements into funded, testable recovery capabilities across people, premises, technology, information, suppliers and logistics.

A continuity strategy is the bridge between business requirements and executable recovery. The BIA tells you how quickly an activity should recover, how much data loss is tolerable and what minimum resources are needed. Strategy determines how those requirements will actually be achieved and what residual risk remains.

Start with requirements, not preferred solutions

Do not begin by declaring that every team will work from home or that every application will use active-active architecture. First define the recovery requirement, minimum capacity, dependency sequence and duration assumptions. Then compare feasible options. A strategy selected before requirements are understood usually becomes either unnecessarily expensive or incapable of meeting the need.

Evaluate all resource dimensions

DimensionStrategy questionsEvidence
PeopleWhich skills are scarce? Can work move across teams or locations?Cross-training, succession, staffing model
PremisesRemote work, alternate site, reciprocal site or relocation?Capacity and access tests
TechnologyRestore, warm standby, hot standby, active-active?Measured RTO/RPO and failover tests
InformationWhat records are essential and how are they protected?Backup, replication and offline-access evidence
SuppliersCan the supplier recover? Is there an alternative?Contract, assurance, alternate-source readiness
LogisticsWhat inventory, transport or equipment constraints exist?Buffer levels, routes, lead times

Use a strategy decision record

For each priority activity, document the requirement, options considered, cost/capacity assumptions, selected option, dependencies, implementation actions, owner and residual risk. This prevents the organisation from forgetting why a strategy was selected and makes later review much easier when assumptions change.

Check dependency feasibility

A four-hour process strategy is not credible if its only application has a twelve-hour recovery target, the required specialist is unavailable for eight hours, or the alternate site cannot connect to a critical supplier. Build a dependency sequence and compare recovery requirements across the chain. Where requirements conflict, either improve the dependent capability, introduce a workaround, segment the service, or formally accept the risk.

Worked example: customer contact service

The BIA requires minimum customer contact within two hours and 70% normal capacity within eight hours. Option A is a fully duplicated contact centre. Option B is remote work with cloud telephony. Option C is overflow to an outsourced provider. Analysis shows remote work meets the two-hour requirement but home connectivity cannot reliably support 70% capacity during a regional outage. The selected strategy therefore combines remote work for the first response with contracted overflow for capacity. The plan defines the activation threshold for the provider and the exercise programme tests both routing and customer-data access.

Strategy is not the same as a plan

The strategy defines the capability: what will recover, to what level, by when and through which option. The plan defines the actions to activate that capability during disruption. Writing a detailed plan cannot compensate for an unfunded or technically impossible strategy.

Cost and resilience trade-offs

Compare options using total cost and consequence, not only implementation price. Include recurring fees, testing effort, data replication, licensing, standby staffing, supplier retainers and operational complexity. Also quantify what risk remains. Management can then make an informed decision rather than assuming the cheapest strategy is adequate.

Define minimum operating capacity

Recovery is rarely binary. Identify minimum acceptable service levels at meaningful time points: for example 20% within two hours, 60% within eight hours and normal service within 24 hours. Link each level to staffing, technology, workspace and supplier requirements. This makes exercises measurable and avoids claiming “recovered” when only a small fraction of demand can be handled.

Implementation and assurance checklist

  • Recovery requirements are approved and traceable to BIA evidence.
  • Options were compared rather than assumed.
  • Shared dependencies and capacity conflicts were analysed.
  • Selected strategies have named owners and funding.
  • Contracts and licenses needed during disruption are active.
  • Manual workarounds have realistic duration and throughput limits.
  • Exercise objectives test the strategy's critical assumptions.
  • Residual risks are accepted at the appropriate authority level.

Review triggers

Review strategy after major process redesign, new technology, supplier changes, mergers, facility changes, significant incidents, failed exercises or material changes in impact tolerance. An annual review date alone is not enough if the operating model changes during the year.

Stress-test concentration risk

Strategies that look independent may share the same cloud region, telecom carrier, building, specialist team, logistics route or upstream supplier. Map these concentration points and test scenarios that remove the shared dependency. A second supplier is not meaningful diversification if both suppliers depend on the same manufacturer or transport hub. Record where true diversification is unavailable and ensure the residual risk is visible.

Define strategy acceptance criteria

Before declaring a strategy implemented, specify the evidence required: contracts executed, alternate capacity available, data synchronized, access pre-provisioned, staff trained, procedures approved and exercise results within tolerance. “Solution purchased” is not the same as “continuity capability ready.” Acceptance criteria should be owned jointly by the business and the teams that provide the recovery capability.

Frequently asked questions

What is the difference between recovery strategy and continuity strategy?

The terms often overlap. In practice, continuity strategy can cover the broader set of options for maintaining or resuming business activities, while recovery strategy may refer to a specific resource or technology recovery approach.

Should every critical process have an alternate site?

No. The correct strategy depends on requirements and dependencies. Remote work, workload transfer, reciprocal arrangements, manual workarounds or supplier solutions may be more appropriate.

When is risk acceptance appropriate?

When a gap cannot reasonably be eliminated immediately, management may accept the residual risk with documented rationale, authority, duration and review conditions. Risk acceptance should not be used to hide an unanalysed gap.

Worked example: selecting a feasible continuity strategy

A service requires 60 trained operators, a specialist application and access to controlled records. The BIA sets a six-hour recovery target, but the alternate office has only 20 seats and remote access supports 25 concurrent users. The strategy cannot simply state “relocate or work remotely.” The design must combine options: preserve a minimum service with 20 priority operators, expand remote-access capacity, cross-train a second shift, pre-position secure equipment and define which lower-priority activities pause. Cost, activation time, capacity and residual risk are compared before approval. This turns strategy from a list of options into an engineered response to a quantified requirement.

Turn strategy selection into a capacity equation

Strategy decisions become more defensible when minimum resource requirements are expressed quantitatively. For each recovery period, define the transactions or service volume that must be sustained, the minimum competent staff, required work positions, critical applications, data currency, supplier inputs and any physical inventory. Compare that requirement with the capacity actually available through the proposed strategy. The difference is the recovery gap.

Example: staged recovery

If normal demand is 1,000 cases per day but the BIA establishes that 350 priority cases must be processed during the first 24 hours, the strategy does not need full production capacity immediately. It does need enough trained people, system licenses, communications channels and downstream capacity to complete those 350 cases. Document which cases are prioritized, who authorizes deferral, how the backlog is controlled and when capacity increases. This prevents vague claims such as “work remotely” from being treated as a complete continuity strategy.

Failure-mode review

Before approval, challenge the strategy against correlated failures: the alternate site may share power or telecoms with the primary site; remote workers may depend on the same identity platform; two suppliers may rely on one upstream provider. Record these common-mode dependencies and either diversify them, create a workaround or accept the residual risk explicitly.