Use this tool to compare candidate recovery strategies before committing to a single solution. It is designed for situations where teams are choosing between manual workarounds, alternate sites, reciprocal arrangements, cloud recovery, additional redundancy, supplier diversification or other continuity treatments.
What this tool is designed to decide
Use current cost, recovery-time, capacity and dependency evidence for each strategy option. Score an option only after confirming what must be in place before activation; a nominally fast option that needs unavailable people, data or suppliers is not actually fast.
Treat the result as a structured comparison, not an automatic strategy approval. The preferred option should still be challenged against BIA requirements, maximum sustainable duration, concentration risk, legal constraints and the consequences of simultaneous demand across several services.
Interactive assessment
Rerun the comparison when RTO, MBCO, site footprint, supplier terms, application architecture or workforce assumptions change. A strategy score can become stale even when the strategy document itself has not changed.
How well the option meets the required recovery time.
Expected reduction in single points of failure and disruption exposure.
How much control the organization has over critical dependencies.
Value for money after implementation and operating cost.
Skills, time, complexity and organizational feasibility.
How to interpret the result
A score above 80 indicates that the option is broadly aligned with recovery requirements and is comparatively implementable, but it still requires evidence and testing. Scores between 65 and 79 usually indicate a workable option with specific weaknesses that should be treated before approval. Scores below 65 should trigger deeper design review, especially where the weakness relates to recovery speed or uncontrolled dependencies.
Retain the option set, scoring rationale, evidence source, decision owner, rejected alternatives and conditions attached to approval. This makes future management review able to see why the organization selected the option rather than only what was selected.
Recommended corrective actions
- Validate the option against approved RTO, MTPD and minimum service requirements.
- Run a dependency failure test for the proposed strategy rather than testing only the happy path.
- Document implementation cost, recurring cost, activation lead time and deactivation criteria.
- Define the trigger and authority for activating the strategy.
- Test the strategy with realistic staffing and access constraints before final approval.
If two options score similarly, use a scenario test to expose the difference. Vary outage duration, concurrent recovery demand and loss of a shared dependency; the more resilient strategy is the one whose critical assumptions remain credible under the agreed scenario.
Governance and assurance
- BCM owns the decision method; the business owner owns service requirements.
- Technology, facilities, supplier and finance stakeholders should challenge assumptions relevant to their domain.
- Management should explicitly approve residual gaps where the selected strategy cannot meet a critical recovery requirement.
Enter only values that reflect the current environment. The calculator runs in the browser and does not replace formal architecture, procurement, risk acceptance or investment approval records.
Common mistakes to avoid
Do not use a high score to conceal a single unacceptable failure mode. A recovery option that is affordable and quick but shares the same point of failure as production should be treated as a concentration problem requiring explicit management action.
Convert weaknesses into funded or accepted actions: capacity increase, alternate supplier, independent connectivity, access remediation, procedure update or scheduled recovery test. Give each action an owner and an evidence-based closure condition.
Evidence to retain
Adapt the scoring thresholds to the organization's risk appetite and approved recovery requirements. The tool is most valuable when teams use the same criteria across options and preserve the decision record for later challenge.
Worked strategy comparison example
Suppose a customer-facing service has an approved four-hour RTO and depends on a specialist team, a primary application and a third-party data feed. Option A is an alternate site with strong staffing but a six-hour technical restoration estimate. Option B is a manual workaround that can start within one hour but handles only 30 percent of normal demand and depends on the same third-party data feed. Option C is a cloud recovery design that meets the time target but requires a credential process that has never been tested outside the corporate network. The evaluator should not simply select the highest total score. It should surface the decisive constraint for each option, show which assumption needs evidence, and identify whether a combined strategy is needed—for example, manual service for the first two hours followed by technical recovery.
Decision record to retain
- Approved recovery requirement and minimum service level.
- Options considered, including options rejected early and why.
- Scoring criteria, source evidence and material assumptions.
- Shared dependencies and concentration risks across options.
- Decision authority, selected option, conditions and review date.
- Test or exercise required before the strategy is treated as proven.
Related BCM.Center knowledge
A common mistake is comparing availability percentages instead of recoverability. Strategy selection should test whether the required business service can be restored to the minimum acceptable level within the required time, with the necessary data and dependencies.
Decision record expectations
A recovery strategy decision should record more than the selected option. Capture the alternatives considered, assumptions used for recovery time, dependencies that must be available, estimated activation time, capacity limits, cost basis, implementation prerequisites and the residual gap against the approved business requirement. Where a strategy depends on third parties, identify contractual recovery commitments and any difference between a vendor's service restoration target and the organization's required business recovery time. The decision record should also define what evidence will prove the strategy works after implementation. That may include technical recovery tests, workspace activation exercises, manual-workaround demonstrations, supplier invocation tests or recovery-volume measurements. This creates a defensible link between BIA requirements, investment decisions and later assurance.