Business Continuity Planning

Explore top LinkedIn content from expert professionals.

  • View profile for Amine Gzouli

    Amazon Security | Sr. Security & Compliance Specialist | Turning InfoSec compliance into a growth engine: Reduce risk, cut red tape, and move at business speed

    5,648 followers

    “We are ISO 27001 certified, are we DORA compliant?” Not so fast. ISO 27001 and DORA both focus on cybersecurity and risk management, but they serve very different purposes. If you're a financial institution or an ICT provider working with financial institutions in the EU, DORA compliance is mandatory, and ISO 27001 alone won’t get you there. Let’s break it down: 1. Regulatory vs. Voluntary Framework ↳ ISO 27001 – A voluntary international standard for information security management. ↳ DORA – A mandatory EU regulation for financial entities and their ICT providers, with strict oversight and penalties for non-compliance. 2. Scope and Focus ↳ ISO 27001 – Offers a customizable scope tailored to organizational needs, focusing on information security (confidentiality, integrity, availability) based on specific risk assessments and chosen controls. ↳ DORA – Enforces a standardized scope across financial entities, extending beyond security to operational resilience. It ensures institutions can withstand, respond to, and recover from ICT disruptions while maintaining service continuity. 3. Key Compliance Gaps 🔸 Incident Reporting ↳ ISO 27001 – Requires incident management but doesn’t impose strict deadlines or mandate reporting to regulators, as it is a flexible standard. ↳ DORA – 4 hours to report a major incident, 72 hours for an update, 1 month for a root cause analysis. 🔸 Security Testing ↳ ISO 27001 – Requires vulnerability management but leaves testing methods and frequency to organizational risk. ↳ DORA – Annual resilience testing, threat-led penetration testing every 3 years, continuous vulnerability scanning. 🔸 Third-Party Risk Management: ↳ ISO 27001 – Covers supplier risk but with general security controls. ↳ DORA – Enforces contractual obligations, exit strategies, and regulatory audits for ICT providers working with financial institutions. 4. How financial institutions and ICT providers can address the delta? ✅ Perform a DORA Gap Analysis – Identify missing controls beyond ISO 27001. (Hopefully, you're not still at this stage now that DORA has been mandatory since January 17, 2025.) ✅ Upgrade Incident Response – Implement real-time monitoring and reporting mechanisms to meet DORA’s deadlines. ✅ Enhance Security Testing – Introduce formalized resilience testing and threat-led penetration testing. ✅ Strengthen Third-Party Risk Management – Update contracts, prepare for regulatory audits, and ensure exit strategies comply with DORA. ✅ Improve Business Continuity Planning – Move from cybersecurity alone to full digital operational resilience. 💡 ISO 27001 is just the tip of the iceberg - beneath the surface lie significant gaps that only DORA addresses. 👇 What’s the biggest challenge in aligning with DORA? Let’s discuss. ♻️ Repost to help someone. 🔔 Follow Amine El Gzouli for more.

  • View profile for Jonathan N.

    Enterprise Risk & Resilience Leader | Cybersecurity | Governance Risk & Compliance | Data Protection & Data Privacy | Data Center Infrastructure | Business Continuity | Disaster Recovery | Aspiring Chief of Staff

    2,432 followers

    🚨 Closing the Gap: Strengthening ICT Resilience 💪🏽 When ISO/IEC 27031:2025 was published, it caught my attention immediately. While ISO/IEC 27001 and ISO 22301 provide strong foundations in information security and business continuity, they treat ICT as a supporting player, not the lead. Yes, I know ISO/IEC 27031 isn’t a certifiable standard. My posts are about creating robust resilience frameworks that extend beyond achieving certification as a company. This is where ISO/IEC 27031 can be used as a supplemental guideline to create additional company controls to mature/improve resiliency. In today’s reality, ICT is the backbone. If it fails, everything else follows. That’s why I’ve moved quickly to integrate new ICT-specific controls into the framework my team has developed. Why? 1️⃣ Bridge the gap between security, continuity, and ICT readiness. 2️⃣ Reduce recovery times and data loss after incidents. 3️⃣ Align with global best practices and demonstrate resilience maturity. How? Here’s what you should consider implementing: ✅ Set precision recovery targets: Establish ICT-specific Minimum Business Continuity Objectives (MBCO), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO) for every critical service. ✅ Map the entire digital backbone: Document end-to-end system dependencies, data flows, and architecture to prioritize recovery where it matters most. ✅ Plan for the unthinkable: Build ICT-specific disruption scenarios into our enterprise risk models, from ransomware to cross-region outages. ✅ Know exactly when to act: Define explicit triggers for activating ICT continuity plans and integrating them into enterprise incident response. ✅ Engineer resilience into the core: Require tested redundancy strategies for infrastructure, applications, and data layers. ✅ Prove it in the field: Expand exercise programs to validate full ICT restoration capabilities under realistic, high-pressure scenarios. ✅ Put vendors on the hook: Hold critical third parties to contractual recovery SLAs, with testing and performance reporting. ✅ Track readiness like a KPI: Measure ICT resilience through dedicated metrics, scorecards, and internal audits to ensure continual improvement. 🤌🏽 The result: The framework my team has developed now forms a three-standard powerhouse, ISO/IEC 27001 + ISO 22301 + ISO/IEC 27031, that strengthens our ability to operate through anything, from cyberattacks to data center failures. 🤪 (Don’t worry, we’ve included NIST to develop our framework as well) 📘 Next step: I’ll continue to share lessons learned with the broader resilience community and encourage adoption across industries as we continue to implement any changes. #ISO27031 #ResilienceByDesign #ICTResilience #BusinessContinuity #CyberResilience #ComplianceCulture #RiskManagement #ISO27001 #ISO22301 #Resilience #ProgramArchitecture #BCDR

  • View profile for Mayurakshi Ray

    Independent Director| Audit, Risk & Tech Strategy Committee Chair, Member | Qualified CA | 30 Years in Cyber Governance, Risk & Digital Trust| Strategic Advisor to CXOs and Boards| Ex Big 4| GRC & Cyber Leader

    7,020 followers

    The recent regulatory guidelines, viz RBI Master Directions of Nov 2023 and SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) of Aug 2024 lay added importance to cyber resilience, business continuity and disaster recovery, incident response and recovery from cyber incidents. Boards are being increasingly attentive and seeking deeper insights on the organizations' preparedness to respond to and recover from cyber incidents. Being part of the Boards of regulated entities, I saw this quarter's IT Strategy and Technology Committee meetings, as well as the Board meetings delve deep and enquiring with the security and technology leadership and sometimes, directly from the MD/CEO, on : 1. Cyber incidents reported, their impact and root-cause assessments. Note : for the organizations, these were mostly hits or false positives. 2. Resilience scores, with Q-o-Q and Y-o-Y comparatives 3. Business Continuity Drills and results 4. Disaster Recovery exercises and results 5. Health check report on the primary as well as the recovery sites, including cloud DR assessments 6. Cyber / technology risk assessments 7. Compliance and reporting (technology) 8. Ongoing governance and improvement around the Cyber Crisis Management Plan (or similar plan, by whatever nomenclature it's defined) 9. Adequacy of technology & security resourcing and training 10. Data protection, with special emphasis on vendor / third party access to critical data & resources and controls around the same The above were some of the top discussion points, but not the only ones. As Boards are made more and more involved and responsible over governance of the organizations' cyber security, resilience, technology governance and risk assurance, Board members will engage more regularly on discussions about cyber risks, inquire of the management their capacity-capability-readiness to respond to and recover effectively from cyber incidents. And above all, the Board would like to ensure compliance to all the relevant regulatory provisions, including on technology and #cybersecurity. To all Technology and Security leaders - the message is very clear, the regulators and the Boards would like to see much more than mere tick mark exercise, specially if you're a regulated entity. - read through each clause in the directions & circulars from regulators - assess thoroughly your current status, including process, operations, technology architecture, procedures, documentation et all - perform risk assessment - technology and operations, over each part of your business - conduct data flow analysis, ascertain your data protection strategy - analyze your third party / vendor connections at all business touchpoints Once you analyze your current state, compare with the requirements given by regulatory directions. Then, step-by-step, put in the measures, updates, upgrades. These are critical steps and require expert acumen - take help from external experts, as required. #technologygovernance

  • View profile for Sanjay Katkar

    Co-Founder & Jt. MD Quick Heal Technologies | Ex CTO | Cybersecurity Expert | Entrepreneur | Technology speaker | Investor | Startup Mentor

    35,990 followers

    Jaguar Land Rover. Factories stalled. Supply chains bleeding. Hundreds of millions in losses. All because of one thing: a cyber attack. When “everything is connected,” one breach doesn’t just take down a server. It takes down plants. Workers. Suppliers. Customers. Entire ecosystems. That’s the reality of today’s business world. A single compromise can bring global operations to a standstill. And here’s the uncomfortable truth: Most businesses still treat cybersecurity like a checkbox. Something you outsource. Something you worry about after growth. But attacks like this remind us: security is not an IT problem. It’s a business survival problem. So what can every business (big or small) learn from this? → Build resilience into every layer. Don’t let “everything connected” mean “everything vulnerable.” → Monitor the dark web. Your stolen data often shows up there before you even know you’re breached. → Know your supply chain risk. Your weakest vendor can be the hacker’s easiest way in. → Test your incident response before you need it. Recovery speed decides the damage. → Treat cybersecurity as core to strategy, not an afterthought. Because downtime doesn’t just kill servers. It kills trust. Your customers won’t remember how fast you shipped features. They’ll remember how you protected their data when it mattered. Still think cybersecurity slows you down? Ask JLR’s factories what real downtime looks like. #CyberSecurity #DarkWebMonitoring #Ransomware #SupplyChainSecurity  #BusinessContinuity #DataProtection #CyberResilience #InfoSec #CISO #RiskManagement

  • CISA has released its new Operational Technology (OT) Cybersecurity Guide, and it deserves board-level attention. For years, OT systems, the technology behind our power grids, water systems, manufacturing plants, and pipelines, were designed for reliability and safety, not cybersecurity. But as IT and OT environments have converged, the attack surface has expanded dramatically. We’ve already seen what this means in practice: ⚠️ Colonial Pipeline (fuel supply disruption) ⚠️ Oldsmar Water Plant (attempted poisoning) ⚠️ Ransomware groups are increasingly threatening physical operations to force payment. The CISA guide is a practical step forward, outlining what every OT-dependent organization should do: ✔️ Know your assets. Visibility is the foundation of OT security. ✔️ Segment IT and OT networks. Strong separation is essential. ✔️ Secure remote access. Enforce MFA, monitor, and log everything. ✔️ Patch with care. Use compensating controls when downtime isn’t possible. ✔️ Prepare for incidents. OT-specific monitoring, response plans, and recovery options must be in place. ✔️ Build resilience. Backups, redundancy, and even manual controls as a fallback. ✔️ Train people. Both IT and OT teams need a shared understanding of cyber risk. This isn’t just a technology problem. It’s a resilience problem. For executives, OT risk belongs on the same agenda as financial, legal, and regulatory risk. The impact of failure isn’t just data loss; it’s downtime, safety hazards, and national security implications. CISA’s guide is a reminder that OT security is no longer optional. It is a core part of modern business continuity. Please feel free to contact me if you need help or want more information on this. 🔔 Follow me for more real-world takes on cybersecurity, leadership, and tech strategy ♻️ Useful? Share to help others! #CyberSecurity #OperationalTechnology #RiskManagement #CriticalInfrastructure #CISA #BusinessContinuity

  • View profile for Shiv Kataria

    Securing Critical Infrastructure & Global Manufacturing | OT/ICS Security Strategy & Governance | IEC 62443 · CISSP · GIAC GRID | AI for Cyber Defense

    25,572 followers

    𝗢𝗧 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗯𝘂𝗱𝗴𝗲𝘁𝘀 𝗻𝗲𝗲𝗱 𝗮 𝗿𝗲𝘀𝗲𝘁. Too often, OT cybersecurity is still positioned as a compliance expense. But in industrial environments, that is too narrow. The better way to look at it is: 𝗢𝗧 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 = 𝘂𝗽𝘁𝗶𝗺𝗲 𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 + 𝗼𝘂𝘁𝗮𝗴𝗲 𝗮𝘃𝗼𝗶𝗱𝗮𝗻𝗰𝗲 + 𝗳𝗮𝘀𝘁𝗲𝗿 𝗿𝗲𝗰𝗼𝘃𝗲𝗿𝘆. One important message from recent OT security investment discussions is clear: 𝗧𝗵𝗲 𝗵𝗶𝗴𝗵𝗲𝘀𝘁-𝗶𝗺𝗽𝗮𝗰𝘁 𝗰𝗼𝗻𝘁𝗿𝗼𝗹𝘀 𝗮𝗿𝗲 𝗻𝗼𝘁 𝗮𝗹𝘄𝗮𝘆𝘀 𝘁𝗵𝗲 𝗺𝗼𝘀𝘁 𝗲𝘅𝗽𝗲𝗻𝘀𝗶𝘃𝗲 𝗼𝗻𝗲𝘀. The practical moves still matter the most: • 𝗞𝗻𝗼𝘄 𝘄𝗵𝗮𝘁 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 Asset inventory and visibility remain the foundation. You cannot protect what you cannot see. • 𝗗𝗲𝘀𝗶𝗴𝗻 𝗳𝗼𝗿 𝗰𝗼𝗻𝘁𝗮𝗶𝗻𝗺𝗲𝗻𝘁 Segmentation, defensible architecture, and secure remote access reduce the blast radius when something goes wrong. • 𝗣𝗿𝗲𝗽𝗮𝗿𝗲 𝗳𝗼𝗿 𝘁𝗵𝗲 𝗯𝗮𝗱 𝗱𝗮𝘆 An OT-specific incident response plan, tested backups, and recovery playbooks can save weeks of downtime. • 𝗠𝗮𝗻𝗮𝗴𝗲 𝗿𝗶𝘀𝗸, 𝗻𝗼𝘁 𝗷𝘂𝘀𝘁 𝗽𝗮𝘁𝗰𝗵𝗲𝘀 OT vulnerability management cannot simply copy the IT model. It has to consider safety, availability, process impact, and compensating controls. • 𝗖𝗼𝗻𝘃𝗲𝗿𝗴𝗲 𝘄𝗶𝘁𝗵𝗼𝘂𝘁 𝗰𝗼𝗻𝗳𝘂𝘀𝗶𝗼𝗻 Unified IT/OT visibility and monitoring are becoming essential, but ownership, response roles, and operational boundaries must be clear. 𝗠𝘆 𝘁𝗮𝗸𝗲: A practical OT security roadmap should start with controls that directly improve resilience, recovery, and operational continuity. Not every program has to begin with a large platform purchase. Sometimes the highest-value investments are: 𝗩𝗶𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆. 𝗦𝗲𝗴𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻. 𝗦𝗲𝗰𝘂𝗿𝗲 𝗿𝗲𝗺𝗼𝘁𝗲 𝗮𝗰𝗰𝗲𝘀𝘀. 𝗢𝗳𝗳𝗹𝗶𝗻𝗲 𝗯𝗮𝗰𝗸𝘂𝗽𝘀. 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲 𝗿𝗲𝗮𝗱𝗶𝗻𝗲𝘀𝘀. Because in OT, the best cybersecurity investment is not only the one that passes an audit. It is the one that prevents downtime before it becomes a crisis. #OTSecurity #IndustrialCybersecurity #ICS #IEC62443 #CyberResilience #OperationalTechnology #RiskManagement

  • View profile for Antonio Vizcaya Abdo

    Turning Sustainability from Compliance into Business Value | ESG Strategy & Governance Advisor | TEDx Speaker | LinkedIn Creator | UNAM Professor | +129K Followers

    129,184 followers

    Business Climate Resilience 🌎 Climate-related disruptions are increasing in frequency and severity, creating material risks for business operations, supply chains, and local communities. Addressing these challenges requires a structured and forward-looking approach to climate resilience. The World Economic Forum presents a framework that outlines ten key actions across three pillars: enhancing resilience, capitalizing on opportunities, and shaping collaborative outcomes. These actions are designed to help organizations avoid economic loss, drive sustainability-linked value, and strengthen systemic responses. Enhancing resilience involves asset-level climate hazard mapping, crisis response planning, and contingency strategies for workforce productivity during extreme weather. Addressing single points of failure and diversifying service delivery and supply chain models is essential to minimize operational disruption. Capturing new opportunities requires understanding long-term consumption shifts, adapting local business models, and directing R&D toward sustainable materials, circular models, and resilient infrastructure. Climate-smart portfolio strategies can position climate adaptation as a source of competitive advantage. Systemic resilience depends on coordinated action across the value chain. Collaboration with public, private, and grassroots stakeholders can unlock shared value frameworks, support regenerative practices, and enable the deployment of early warning systems and nature-based financial mechanisms. To operationalize these priorities, businesses are encouraged to activate key enablers within 24 months. These include integrating climate risk into enterprise risk management, conducting detailed audits of capabilities, and aligning capital investment decisions with resilience objectives. Data intelligence, scientific partnerships, and responsible use of technology—particularly AI—will be critical to improve foresight, enable adaptive planning, and enhance the quality of strategic decision-making in the context of escalating climate volatility. #sustainability #sustainable #business #esg

  • View profile for Mansour Al-Ajmi, Cert. Dir.
    Mansour Al-Ajmi, Cert. Dir. Mansour Al-Ajmi, Cert. Dir. is an Influencer

    CEO, X-Shift | Independent Board Director | GCC BDI Certified | Governance, M&A & Transformation

    28,366 followers

    If your automation stopped working tomorrow, how long could your business continue operating before your customers felt it? We’ve seen it: ■ Retailers frozen at checkout because POS systems failed. ■ Airlines grounded when scheduling tools crashed. ■ Banks paralyzed by cyberattacks. Automation, AI, data platforms, and cloud-based ecosystems have unlocked new opportunities for efficiency, personalization, and growth. But the more we integrate, the more dependent we become. What happens when a critical platform fails? Can your business still serve its customers if automation were to freeze for just a few hours? Or would a simple disruption cascade into a complete shutdown? Digital transformation shouldn’t mean digital fragility. I believe that technology should empower us, not hold us hostage. Here are some strategies to ensure your business stays resilient in a digital-first world: 1. Map your critical dependencies: Understand which platforms, tools, and systems are essential for serving customers. Identify single points of failure and create alternatives before issues arise. 2. Build manual backups: Train teams to handle key operations without full reliance on automation. This ensures continuity when systems fail or platforms go offline. 3. Stress-test your systems: Simulate platform outages or data disruptions to evaluate response times, identify weaknesses, and prepare contingency plans. 4. Invest in cybersecurity & redundancy: As businesses grow digitally, so do risks. Prioritize secure infrastructure, cloud backups, and fail-safe mechanisms to minimize disruption. 5. Empower people, not just platforms: Technology should enhance human capability, not replace it. By upskilling teams, companies ensure employees can step in when automation halts. As tech leaders, we need to rethink risk management, stress-test operations, and ensure customer experience doesn’t collapse when the tech stack hiccups. #Automation #AI #Data #Tech

  • View profile for Jennifer Motles 🌻

    Chief Sustainability Officer

    27,449 followers

    This morning's breakfast discussion with Business Insider reinforced something I see daily: #resilience isn't just a buzzword, it's become the defining capability that separates thriving organizations from those merely surviving. The conversation centered on how companies are leveraging #sustainability insights to build organizational resilience through comprehensive risk evaluation and translating climate considerations into sustainable competitive advantages. What struck me most was the shared recognition that these aren't separate initiatives, but interconnected strategies for long-term business continuity. Exercises like #doublemateriality and climate risk and opportunity assessments (#CCRO) have evolved far beyond compliance tools. They've become essential frameworks for understanding how environmental and social factors intersect with core business operations, supply chains, and strategic planning. When done rigorously, they reveal the connections between sustainability performance and business resilience that might otherwise remain invisible. Last week, we published our updated Sustainability Materiality Report, which reflects years of learning about how to make these assessments truly decision-useful rather than just comprehensive. The process taught us that the most valuable insights come not from identifying every possible risk, but from understanding which factors could fundamentally alter our business trajectory. As #ClimateWeek unfolds, these conversations feel particularly timely. Building deep understanding of both #mitigation and #adaptation strategies isn't just about environmental stewardship, it's about developing the organizational awareness needed to navigate an increasingly complex operating environment. Those around today's table represented diverse stakeholder groups, yet we all shared similar challenges: how to build systems that can anticipate change rather than simply react to it. The answer consistently pointed back to the quality of our risk assessment processes and our willingness to integrate those insights into strategic decision-making. #ClimateAction requires this level of institutional intelligence—the capacity to see connections, anticipate disruptions, and adapt accordingly. Companies that master this integration will find themselves better positioned not just for environmental challenges, but for the full spectrum of changes reshaping business today.

  • View profile for James Yates

    Chief Risk Officer | Head of Risk | Board Member | Thought Leader

    2,365 followers

    Too often, risk management operates in a parallel universe - technically sound, well-documented, but disconnected from the organisation’s actual goals, which results in risk processes that slow things down rather than enabling smarter, faster decisions. A risk framework should be a strategic asset. It should help leaders weigh trade-offs, allocate resources, and pursue growth with confidence, but that only happens when risk appetite, controls, and reporting are aligned with what the business is actually trying to achieve. This alignment doesn’t happen by accident, it requires deliberate effort. Risk teams need to understand the business model, the strategic priorities, and the pressures leaders are facing, and then they need to translate those into risk terms - what’s acceptable, what’s not, and where the real exposure lies. When risk and strategy are aligned, the conversation shifts. Risk management stops being a blocker and starts becoming a partner. It’s no longer about saying “no”, it’s about helping the business say “yes” to the right opportunities, with eyes wide open. #RiskManagement #StrategicAlignment #BusinessStrategy #RiskAppetite #Leadership #OperationalRisk

Explore categories