01BCM in Accordance with BSI Standard 200-4 and ISO 22301
BSI Standard 200-4 (final version 1.0, dated May 2023; successor to BSI Standard 100-4) describes how to establish and operate a business continuity management system (BCMS). Its tiered model allows a resource-efficient entry across three maturity levels: the Reactive BCMS for a fast, basic emergency response capability, the Build-up BCMS for gradual expansion, and the Standard BCMS as the full implementation. The Standard BCMS level is compliant with the requirements of ISO 22301:2019, the internationally certifiable BCMS standard (supplemented by Amendment 1 in 2024). IT emergency management (IT service continuity management, ITSCM) interlocks BCM with IT operations and the ISMS.
02Key Metrics: MTA, RTO and RPO
The starting point is the business impact analysis (BIA): it identifies time-critical business processes, their resources and potential single points of failure. The maximum tolerable downtime (MTA in BSI terminology, internationally known as MTPD) defines how long a business process may be down at most; from this, the required recovery time objective (RTO) of the supporting resources is derived. The maximum acceptable data loss (recovery point objective, RPO) determines how old the most recent recoverable data set may be – and thus the backup frequency. What matters in practice is comparing these targets with the values that can actually be achieved (RTA/RPA): if the achievable values exceed the targets, there is a coverage gap that must be closed through technical measures or a defined minimum level of emergency operations (MBCO).
03Backup Strategies: 3-2-1, Offline and Immutable
The 3-2-1 rule has become the established rule of thumb for data backups: three copies of the data on two different types of media, with one copy stored at a different location. In its ransomware countermeasures catalogue, the BSI points out that attackers with previously obtained administrative privileges deliberately search for backups and encrypt them just like production systems – at least one copy should therefore be kept offline and disconnected from the network after the backup; this separation should be verified regularly. Immutable storage (for example via WORM or object-lock mechanisms) adds further protection, because saved states cannot be subsequently modified or deleted even with administrative privileges. Backups also include well-rehearsed restores: recovery and black start – bringing all servers and systems back up from scratch – should be tested in practice on a regular basis.
04Exercising and Testing: From Tabletop Exercises to Functional Tests
Emergency plans only become reliable once they have been exercised. BSI Standard 200-4 provides for an annual exercise schedule with graduated formats: plan reviews (internationally known as tabletop exercises) examine plans in a discussion-based setting, crisis team and command post exercises train crisis team operations under realistic conditions, alerting exercises test reachability and reporting channels, and functional tests demonstrate the technical effectiveness of individual emergency measures. Scenarios should play through different degrees of compromise – from individual systems to a total outage including unusable online backups. The evaluation and follow-up of each exercise feed back into plans and playbooks as improvements.
05Crisis Communication and Reporting Obligations
For emergency and crisis communication, concepts for dealing with the relevant stakeholder groups are prepared in advance – employees, customers, service providers, media and authorities. Statutory reporting obligations run in parallel with incident response: under Art. 23 of the NIS2 Directive, significant incidents require an early warning within 24 hours and an incident notification within 72 hours of becoming aware of the incident, followed by a final report no later than one month after the notification. The ability to communicate must be maintained even when an organization's own systems are encrypted – contact lists, response plans and the necessary access credentials should therefore be kept offline or in printed form.
06Regulatory Anchors: NIS2 and DORA
The NIS2 Directive (Directive (EU) 2022/2555) requires in Art. 21(2)(c), as a minimum measure, "business continuity, such as backup management and disaster recovery, and crisis management". For the financial sector, DORA (Regulation (EU) 2022/2554, applicable since 17 January 2025) goes further: financial entities other than microenterprises must maintain a sound and comprehensive digital operational resilience testing programme under Art. 24; ICT systems supporting critical or important functions must be tested at least once a year. In addition, financial entities designated by the competent authorities must carry out advanced testing by means of threat-led penetration testing (TLPT) at least every three years under Art. 26 – on live production systems supporting critical or important functions.