Work out what your organisation cannot afford to lose, write arrangements your own people could pick up and run, then put those arrangements in front of a real situation and find out. I take on the whole of that, whichever part of it you are missing, or run it for you month to month.
Four things I keep finding when I exercise and audit continuity arrangements. This is my own view from the work itself, not research, and it recurs often enough to design around.
It was written by one or two people, approved, and filed. The people who would have to run it have often never read it. Where there is no plan at all, the same holds for whatever everyone assumes the arrangements to be, because those assumptions have never been compared out loud.
Contracted response times, site detail, supplier numbers and staff contacts live in the system that is unavailable, or in the building your people cannot get into. An exercise finds that in an afternoon. An incident finds it at four in the morning.
Plans say who leads. Fewer say who leads while that person is on a flight, and fewer still say what the deputy is allowed to spend without asking. Organisations discover in the room that a great deal rests on two or three individuals in ways that have never been written down.
Systems come back and the plan stops. The reconciliation, the backlog and the account you owe other people all begin at that point, and they usually run longer than the disruption did.
Some organisations need the whole sequence. Some already hold an analysis and need the plan written. Some hold a plan that has never been used. I take on whichever part is missing and say plainly where I think you should begin.
Interviews and workshops with the people who run the work. No questionnaire sent round by email. What comes out of it is written down and evidenced.
Written from your analysis, in your language, short enough that your duty manager would open it at seven in the morning. Owned by your people rather than by me.
A plan is finished when your people have used it. A facilitated session puts your people into a situation and establishes what they would actually do, which is where the gaps show. The rest of this page covers how that runs.
Arrangements go out of date quietly. A plan written against last year's premises, systems and staff will be wrong in places you have not yet noticed, which is why the review needs to be arranged in advance.
Some organisations want a defined job with a finished deliverable at the end of it. Some want the exercise on its own. Some want continuity held alongside the rest of their risk, quality and compliance picture, month to month, run by a fractional director who already knows the organisation.
Scoped at the outset and quoted as a package, so you know what you are getting and what it costs before anything starts. The work runs to that scope and finishes with documents your people own.
Booked on its own, whether or not I wrote the plan. Where arrangements already exist, this is the fastest way I know to find out how good they are.
Continuity sits inside a wider risk, quality and compliance picture. For a few organisations I run that picture myself, a couple of days a month, sitting with the leadership team and doing the work between meetings.
A situation develops in stages. At each stage the group says what they would genuinely do, using the plans, systems and contacts they actually have. I hold the pace, press where it matters and record what happens.
We are exercising the arrangements and the assumptions underneath them. Where we find a weakness, that is the exercise doing its job.
The programme covers losing the premises, losing your own systems, a possible cyber compromise, dependency on a provider, competing demand you cannot meet, the outright failure of a supplier, decisions taken without the usual people, something that happened out of hours and went unnoticed, a disruption that has run for a week, and the weeks after restoration.
Each one is pitched at a level, from a short structured conversation through to an executive tabletop, and each assumes only what the sessions before it have established. Which one you start with comes out of the first conversation.
Ahead of the session you answer a set of questions about your building, your working patterns, your obligations and the words your people actually use. The material for the day is written from those answers.
Some of what I ask about will be commercially sensitive or restricted. Where that applies, hold it back and we raise it verbally on the day, with only the people you have chosen to be there.
Most of the organisations I work with do this because they want an honest answer to a question that has been nagging at them, and because a leadership team that has worked through it once is quicker and steadier when something real happens. That is reason enough on its own.
Where a standard is in play, the record follows without extra work. The analysis, the plan and the exercises follow the principles of ISO 22301, the international standard for business continuity management, which asks for an exercise programme built on suitable scenarios, held at planned intervals, each followed by a formal report and corrective actions.
Following those principles is a different thing from implementing the whole management system and certifying against it. Most of the organisations I work with want the first. Where you genuinely need the second, I will say so, and that is a larger piece of work.
Organisations with no certified management system get the same value and none of the paperwork burden.
All conversations are treated as strictly confidential. If you want to know what your organisation would actually do, that is a conversation worth having before anything happens.