What is business continuity management?
Business continuity management is the discipline of keeping an organisation's essential services running during and after a disruption. It identifies critical activities through a business impact analysis, sets recovery targets, and maintains tested plans, people and escalation routes. Ontech ICTM holds the analyses, plans, risks and supplier dependencies in one module.
Business continuity management (BCM) asks a business question first: which services must keep going, and for how long could the organisation survive without each of them? The answers come from a business impact analysis (BIA), which sets a maximum tolerable downtime and recovery targets for each critical activity.
Those targets then shape everything else — the continuity plans, the people and escalation chains who carry them out, the risks worth reducing and the suppliers whose failure would hurt most. Technology recovery is one part of this; the detailed restoration of systems and data is covered by disaster recovery.
ICTM's Business Continuity module keeps these pieces together. BIAs, plans, the risk register, key personnel and vendor dependencies are linked, plans carry versions and review dates, and a language model can produce a first draft of a plan for your team to refine.
What ICTM does for business continuity management
Business impact analysis
Record each critical business activity with its maximum tolerable downtime (MTD) and its recovery time and recovery point objectives, so recovery priorities are set by business need rather than by guesswork.
Versioned continuity and DR plans
Keep business continuity and disaster recovery plans with version numbers, approval status and review dates, including the recovery steps each plan calls for.
AI-drafted plans
Generate a first draft of a continuity plan from your recorded information, then edit and approve it. Drafting can use a locally hosted language model.
Risk register inside the module
Score continuity risks on a 5×5 likelihood and impact matrix, record inherent and residual risk levels, and assign mitigations with owners and review dates.
Escalation chains and key personnel
Record who must be contacted, in what order and by which method when an incident escalates, and keep a register of key personnel with their role, department, site, contact details and whether they are critical.
Vendor dependencies and single points of failure
Map which suppliers each application depends on, record their SLA uptime, RTO and RPO, and flag suppliers whose failure would stop a service on its own.
AI impact and vendor-risk analysis
Ask ICTM for an AI analysis of business impact or supplier risk to challenge your assumptions. The output is advisory and stays in your records for review.
Continuity risk in the unified risk score
Business-continuity risk is one of the inputs to ICTM's unified risk score, so gaps in continuity planning show up in the organisation-wide view.
ICTM modules: Business Continuity · Vendor Risk
Business continuity and disaster recovery in ICTM
| Business continuity | Disaster recovery | |
|---|---|---|
| Main question | Which services must keep running, and how? | How do we restore systems and data? |
| Scope | People, processes, premises, suppliers and technology | IT systems, applications and data |
| What ICTM records | BIAs, continuity plans, risks, escalation chains, vendor dependencies | Backup jobs and results, DR exercises, recovery steps |
| Key measures | Maximum tolerable downtime, RTO and RPO targets | Backup frequency score, target versus actual RTO and RPO in exercises |
Use cases
Running a first business impact analysis
Agree MTD, RTO and RPO for each critical activity with business owners and record them where IT can plan against them.
Keeping plans reviewable
Replace plans lost in shared drives with versioned, approved plans that show when each was last reviewed.
Understanding supplier exposure
Find the applications that rely on a single supplier and decide whether to add an alternative or accept the risk.
Preparing for regulatory scrutiny
Show regulators and auditors a documented BIA, current plans and a scored continuity risk register.
Onboarding a new continuity lead
Give a new BCM owner one place to see the plans, people, risks and dependencies they inherit.
Benefits
Recovery priorities set by the business
BIA targets make it clear which services come back first.
Plans that stay current
Versions, approval status and review dates make stale plans easy to spot.
Faster first drafts
AI drafting gives teams a starting point instead of a blank page.
Fewer hidden dependencies
Supplier single points of failure are recorded and visible before they cause an outage.
Frequently asked questions
What is a business impact analysis?
A business impact analysis (BIA) identifies an organisation's critical activities and works out the effect of losing each one over time. It produces recovery targets — maximum tolerable downtime, recovery time objective and recovery point objective — which then drive continuity and disaster recovery planning.
What is the difference between business continuity and disaster recovery?
Business continuity keeps the whole organisation operating through a disruption, covering people, premises, suppliers and processes as well as technology. Disaster recovery is the technical part: restoring IT systems and data within the targets the continuity work has set. ICTM covers both, with backups and DR exercises on its disaster recovery side.
Can ICTM write our business continuity plan?
ICTM can generate a first draft from the information you have recorded, using a language model that can run on your own server. The draft is a starting point: your team edits it, approves it and owns it, and ICTM keeps its versions and review dates.
Does ICTM call staff automatically during an incident?
No. ICTM records escalation chains, key personnel and their preferred contact method, so everyone knows who to call and in what order. It does not place calls or send call-out messages itself, so use your existing notification tools for that step.
How often should a business continuity plan be reviewed?
Review a plan at least once a year and whenever something significant changes, such as a new core system, a new supplier, an office move or lessons from an exercise or real incident. ICTM records a review date on each plan so overdue reviews are visible.