Template

Business Continuity Exercise Plan Template

A full BCM exercise structure with scenario library, measurable objectives, inject schedule, evaluation criteria, evidence, after-action reporting and retest.

Exercises should demonstrate decisions and capabilities, not simply prove that a meeting occurred. Start with specific objectives, choose a scenario that stresses those objectives, define observable success criteria, collect evidence and turn findings into owned corrective actions.

Exercise plan template

SectionRequired content
Purpose and scopeServices, plans, sites, suppliers, systems and teams in scope/out of scope
Objectives3–6 measurable objectives linked to actual continuity risks or recent gaps
ScenarioPlausible disruption with enough ambiguity to require decisions
Assumptions / artificialitiesWhat is simulated, what is real, what systems must not be touched
Participants and rolesPlayers, controllers, facilitators, observers, evaluators, suppliers
Inject scheduleTimed events that reveal new facts or degrade assumptions
Evaluation criteriaExpected behaviours/outcomes and evidence source
Safety / stop criteriaConditions that stop or pause the exercise
CommunicationsExercise channels, “EXERCISE” labelling and external-message controls
After-action processHot wash, evidence review, root cause, action owners, due dates and retest

Scenario library

ScenarioWhat it testsUseful complications
Ransomware with data-integrity concernCyber/BCM/DR coordination and clean recoveryBackups exist but identity is compromised; key supplier also degraded
Cloud-region failureArchitecture, failover, DNS/network dependencies, business validationFailover capacity lower than peak; external API allow-list missing
Primary workplace inaccessibleRemote/alternate-site strategy and staffingTransport disruption and 30% absenteeism
Critical supplier outageThird-party escalation, substitution, customer prioritisationSupplier cannot give ETA; alternate requires onboarding lead time
Telecom/contact-centre outageCustomer communications and alternate channelsMobile network congestion; public misinformation
Payment/market cutoff disruptionPriority rules, transaction integrity, regulatory/customer communicationBacklog approaches cutoff; manual control capacity limited
Severe weather / regional eventMulti-site and people resiliencePower, transport and supplier impacts are correlated

Example 90-minute tabletop inject timeline

TimeInjectExpected decisions / evidence
T+0Critical customer platform unavailable; monitoring shows regional infrastructure issueAssess service impact, start incident log, identify RTO/MBCO and activation authority
T+15Provider says restoration estimate is 4h; service RTO is 2hActivate continuity strategy; identify minimum service and priority population
T+30Alternate environment is available but one identity dependency is failingEscalate dependency; decide controlled workaround; update forecast
T+45Social media reports customers cannot access funds/servicesApprove customer message; align facts, channel and next update
T+60Supplier used by both primary and alternate route reports degradationRe-evaluate assumptions/concentration; protect scarce capacity
T+75Technology says service is technically restored; reconciliation is incompleteDo not confuse technical availability with business readiness; define validation gate
T+90Backlog is growing after restorationPrioritise backlog, set clearance forecast, define stand-down and lessons actions

Evaluator worksheet

ObjectiveObservable behaviourEvidenceRatingFinding / action
Activate within 20 minAuthority identified; activation decision recordedTimestamp + decision logMet / Partial / Not met
Achieve minimum service within RTOMBCO started and measuredQueue/throughput recordsMet / Partial / Not met
Manage communicationsFirst approved message issued to defined audienceMessage + approval/timeMet / Partial / Not met
Validate recoveryBusiness owner completes validation before full releaseTest cases/sign-offMet / Partial / Not met
Manage supplier dependencyEscalation, ETA, workaround and concentration decision trackedVendor ticket + decisionMet / Partial / Not met

After-action report structure

  1. Executive summary and exercise scope
  2. Objectives and scenario
  3. What worked and should be preserved
  4. Findings by objective
  5. Root/causal factors where known
  6. Recovery-objective and capability gaps
  7. Decisions that need governance approval
  8. Corrective actions with owner, priority and due date
  9. Evidence repository
  10. Retest criteria and target date

A finding is stronger when it states condition, impact and action. Example: “The DR platform recovered in 95 minutes, but business validation required another 35 minutes because test data and an authorised validator were not pre-arranged. This would exceed the two-hour service RTO. Action: create a controlled validation pack, nominate two alternates and retest.”

Official references and further reading

  • FEMA exercise resources — US preparedness resources that can support structured exercise planning.
  • ISO 22398:2013 — International guidelines for exercises and testing in the security/resilience domain.
  • BCI GPG 7.0 — Includes validation as a professional practice.

Scenario library: vary the dependency, not only the disaster name

ScenarioPrimary learning objectiveUseful injects
Cyber / ransomwareDecision between containment and rapid recovery; clean restore; communicationsPrivileged account compromise, backup uncertainty, regulator/customer inquiry
Supplier outageConcentration, escalation, substitution and contracted capacitySupplier declares regional incident; alternate supplier has 50% capacity
Workforce lossSuccession, cross-skilling, shift sustainability40% absenteeism; two key approvers unavailable
Facility lossAlternate location, remote work, equipment and accessBuilding closed 72 hours; local transport disrupted
Cloud / SaaS outageExternal dependency, failover boundaries, manual workflowStatus page gives no ETA; API unavailable; data export is delayed
Data integrity eventRPO, reconciliation, duplicate/lost transactionsRecovery point uncertain; downstream system processed partial batch
Telecom outageMulti-carrier, emergency channels, customer routingMobile voice degraded; internet circuit also affected
Regional eventMultiple dependencies and scarce resources fail togetherSite, staff, supplier and transport constraints overlap

Evaluation rubric

ObjectivePass evidencePartialFail
ActivationCorrect authority activates within target and records rationaleActivated with delay or unclear rationaleNo activation / wrong authority
Minimum serviceMBCO demonstrated with measured throughputWorkaround runs but below required capacityNo viable workaround
CommunicationsPriority stakeholders receive approved, accurate updates through working channelsSome groups/channels delayedCritical stakeholder not informed
Recovery validationTechnology and business checks completed before releaseSome validation informalService released without business/control validation
LearningActions have owner, date, risk and retest methodActions genericNo accountable corrective action

Exercise inject design rules

  • Each inject should connect to an exercise objective; do not add noise only to make the scenario dramatic.
  • Give participants enough information to decide, but preserve realistic uncertainty.
  • Mix operational, supplier, technology, people and communication consequences when testing end-to-end resilience.
  • Record the expected decision/evidence for evaluators before the exercise starts.
  • Time-jump only when the objective needs a later consequence; explain the simulated clock clearly.
  • Do not grade individuals for exploring options in a learning exercise unless evaluation criteria explicitly require a capability demonstration.
  • End with a formal hot wash, evidence review and action ownership rather than a generic “successful exercise” statement.