Business continuity testing has a budget line and usually an annual slot in the diary. Most of what that budget buys is confirmation that the plan works, which is the least useful result a test can return. Really effective testing is designed to stretch both plans and teams in order to develop both, rather than just tick a box.
What is a test for?
The easy assumption for designing any rehearsal is to write a scenario the plan and the team can comfortably cope with, leaving senior people reassured that everything is in hand. The mindset the Army drills into its youngest recruits runs the other way: expect reality to diverge from expectations, because the world is too complex and too adversarial to predict, so resilience is about being more ready for anything, rather than just the expected. After all, no plan survives contact with the enemy.
Design following this mindset prefers to test plans to destruction, putting more and more pressure on them until they fail, to better understand where the most important threats and vulnerabilities lie, and how any assumptions underpinning the plan might not hold up. This is a business continuity test that provides the opportunity to develop resilience and flexibility, rather than just reassurance.
This approach does not indicate being difficult for its own sake; pushing every variable to an extreme produces a scenario that breaks the plan and demoralises the team, without any real scope for learning. The art in exercise design is in identifying the assumptions carrying the weight of the plan and pressurising one or two of them at a time, so that the team can see where the cracks appear. And not every exercise needs to be a test; a few iterations to build confidence and competence may be needed before a team is ready to be tested.
What is actually under test?
An effective business continuity test exercise is a rehearsal for both the contingency plan and the people who will be expected to execute it. The plan should be used as a script throughout, providing the agreed pathway to understand the challenge and mitigate its impacts. This allows participants to find the critical points where a combination of factors works in an unexpected way: a key decision-maker is on holiday, the media know the story before you’ve briefed them and the hotel conference room you had earmarked as your temporary HQ has been triple-booked by other firms for the same purpose. None of those is exotic, but a plan that has never had to cope with these sorts of factors remains aspirational, and a triumph of hope over rigour.
In a tabletop exercise built this way, updates arrive a little faster than the team would like and while the first one fits with the plan, by the third one, the situation has gone beyond the expectations of the plan and the team is trying to maintain a shared picture, agree what matters most and act before the next update lands. Good facilitation lets that moment run as a learning experience, ideally before pausing to debrief, confirm learning and running the exercise on. While causing participants to panic would be unhelpful, a little pressure is key to building confidence and responsibility before the day when it really matters.
What are the outputs?
The exercise is the key event to this process, but several outputs are required for the test to have genuine utility.
Firstly, the debrief, run properly as a structured after action review, provides an opportunity to go over both the plan and the team’s execution of it. This is the opportunity to capture the specific changes required to improve the plan, but also to reflect on how the team worked together under pressure. This second element not only sets the conditions for improved execution of this plan, but for any task which brings this team together.
Beyond the AAR, insights, observations and lessons captured during the exercise need to be recorded, so that they become the basis for further work on the plan. On the compliance and standards front, ISO 22301 requires, at clause 8.5, an exercise programme that validates the arrangements over time, and at 8.6 an evaluation of what the exercises showed. The process described above is one that produces the sort of evidence which an auditor will need to see.
Summary
Business continuity testing that comfortably confirms the plan provides no original information through which to adapt and improve. An effective test picks out the assumptions that carry the weight of the plan, puts them under pressure and makes a learning opportunity out of the whole exercise.
Testing Plans is a service we deliver for clients, from design through delivery and on improvements. If your continuity plan has not been tested for a while, or has only ever passed, get in touch and we can talk through where to start.
Frequently asked questions
What is business continuity testing?
Business continuity testing is the practice of exercising a business continuity plan against a realistic scenario to find out whether it works, where its assumptions fail and whether the people named in it can execute it under pressure. Done well, it is an exercise designed to find the plan’s breaking point rather than to confirm the plan.
How often should a business continuity plan be tested?
ISO 22301 expects a programme of exercises at planned intervals and after any significant change to the organisation, its systems or its people. Annual is the common baseline. The progression matters more than the frequency: a first exercise the team can pass, then a harder one that finds the break.
What is the difference between a business continuity test and an exercise?
In ISO 22398 a test has a measurable pass or fail outcome and an exercise is a practice activity. Most of what organisations call business continuity testing is exercising in the standard’s terms. The distinction matters less than the design: an exercise built to confirm the plan and one built to find where it breaks produce very different evidence.