Who it is for and the format
The course targets those responsible for organizational resilience: executives and owners, risk managers, operational risk specialists, internal auditors, heads of IT and information security, and continuity officers in regulated financial organizations. It also works as a structured start for teams building a BCM system from scratch.
Format: 2 days, 16 academic hours, 6 modules. On-site at your company or live online with the instructor (convenient for distributed teams). Groups up to 8; for larger groups we adapt the cases. Testing and a certificate upon completion.
The programme: 6 modules
Module 1. Foundations of business continuity management (BCM). Business continuity and operational resilience; ISO 22301 and national standards; regulatory expectations, including central bank requirements for financial organizations; roles, accountability and the place of BCM in enterprise risk management.
Module 2. Business impact analysis (BIA) and risk assessment. The critical process register; RTO and RPO; pricing an hour and a day of downtime; hunting single points of failure across IT, people, suppliers and sites; prioritization.
Module 3. The business continuity plan (BCP) and disaster recovery plan (DRP). The structure of a working plan; recovery and redundancy strategies; manual workarounds for critical operations; backups and IT recovery requirements.
Module 4. Crisis management and the crisis plan. The crisis team: authority and activation; first-24-hours checklists; crisis communications — what to tell staff, clients and the press; classic failures dissected on real cases.
Module 5. Cyber resilience: ransomware and cyberattack readiness. The ransomware scenario and the first hours; 3-2-1 backups; recovery after an attack; connecting information security with continuity — the «second half of defense».
Module 6. Exercises, metrics and continuous improvement. Exercise types and tabletop cyber drills; resilience metrics and the executive continuity dashboard; auditing the BCM system; keeping the system alive rather than on paper.
What you get
- Practical skills: running a BIA, pricing downtime, building continuity and recovery plans, organizing exercises.
- Ready-to-use tools: document templates, first-24-hours checklists, a crisis communications structure.
- Real case debriefs: ransomware attacks, IT outages, supplier losses — lessons learned.
- Testing and a certificate.
- Industry adaptation, including your regulatory requirements.
Want a baseline first? Take the free 5-minute maturity check. For self-paced study, see the online BCM and ISO 22301 course.
Pricing
FAQ
When can we run the course? Contact us to pick dates — weekdays or weekends both work.
On-site or online? The base format is on-site; all materials are adapted for live online delivery as well.
Is there a certificate? Yes — testing at the end, with a certificate upon passing.
Can one person take it individually? Yes, self-paced with a closing online session with the instructor; pricing on request.
What if the group exceeds 8 people? We clarify the goals and either split groups or adapt the business cases for a larger audience.