Business continuity and crisis management
Business continuity and crisis management require organizations to ensure that essential services can be maintained or quickly restored following a significant cyber incident. This involves implementing technical recovery capabilities—such as backups—and organizational frameworks for managing disruptions and communicating during a crisis.
What it means
The intent is resilience rather than just prevention. While other NIS2 controls focus on stopping attacks, this requirement assumes that a failure will eventually occur and demands a structured plan to survive it with minimal impact on the delivery of essential services.
In practice, this covers two distinct but related areas: technical recovery (disaster recovery) and organizational response (crisis management). Technical recovery focuses on data integrity and system availability, while crisis management focuses on decision-making, personnel coordination, and external communication.
The scope is centered on "essential" functions. Organizations must identify which processes are critical to their operations and prioritize those for continuity planning, rather than attempting to apply the same recovery rigor to every non-critical internal system.
How to meet it
- Conduct a Business Impact Analysis (BIA) to identify critical services and define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Develop and document a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) detailing step-by-step procedures for restoring operations.
- Implement a robust backup strategy that includes encrypted, offsite, or immutable backups to protect against ransomware.
- Establish a Crisis Management Team (CMT) with clearly defined roles, responsibilities, and an escalation matrix for decision-making.
- Create a crisis communication plan to notify regulators, partners, and affected customers in accordance with NIS2 reporting timelines.
- Schedule and perform regular testing of these plans through tabletop exercises or technical failover simulations.
Evidence an auditor asks for
- Copies of the current BCP/DRP documentation and the associated Business Impact Analysis.
- Logs showing successful backup completions and records of periodic restoration tests (proving backups actually work).
- Reports from recent crisis simulation exercises, including "lessons learned" and evidence that plans were updated based on those results.
- A documented Crisis Management Team directory with contact details and defined escalation paths.
Common pitfalls
- "Paper Compliance": Maintaining a detailed plan that has never been tested or is too generic to be actionable during a real emergency.
- Confusing backups with recovery: Assuming that having data backups is the same as having a recovery process; without an orchestration plan, restoring terabytes of data can take longer than the RTO allows.
- Ignoring dependencies: Failing to account for third-party vendors or cloud providers in the continuity plan, leaving a gap when a critical external service fails.