Implementing BCM

Testing crisis readiness: methods and a checklist

A plan on paper and real readiness are different things. The only way to know whether a business would survive a serious disruption is to test it before the disruption happens. Here are the methods, from tabletop exercises to a full stress test.

Published: 24 July 2026 · Author: Evgeny Telenkov · ≈ 6 min read

Why test readiness

In our experience most continuity plans do not survive first contact with reality: contacts are out of date, the named owner has left, the backup will not restore, and decisions in the first hours are taken by someone without the authority to take them. Testing surfaces all of this early, while fixing it is still cheap. For companies working to ISO 22301, regular testing is a direct requirement of the standard.

Methods of testing: from simple to deep

What to measure

  1. Recovery time. How long recovery actually takes, against the target RTO.
  2. Data loss (RPO). How much data is lost when you roll back to the last backup.
  3. Money. The cost of a day of downtime and the share of revenue at risk — the language leadership actually responds to.
  4. Quality of decisions. Speed, gaps in authority, readiness of communications — recorded by an observer.
In practice: our two-day continuity stress test combines every level: a diagnostic day (100+ questions), a ransomware stress simulation with the leadership team, and a report for the CEO — damage in money terms, weak points and a 90-day plan.

Checklist of first steps

  1. Pick one scenario — the most painful for your industry (ransomware fits almost everyone).
  2. Gather the management team and the owners of key functions — 6 to 12 people.
  3. Run a tabletop session: 3-4 hours on the scenario, with an observer recording the gaps.
  4. Cost a day of downtime — roughly is fine, based on revenue.
  5. Write down the findings and assign owners and deadlines for the fixes.
  6. Repeat in six to twelve months — readiness fades without repetition.

Start with the free assessment

13 questions, 5 minutes — your resilience level, the main risks and first steps.

Frequently asked questions

Where do we start with readiness testing?

With a tabletop session on a single scenario with the management team: ransomware or the loss of a key supplier. It takes 3-4 hours and exposes the main gaps.

How often should readiness be tested?

At least once a year on one scenario, and more often for critical IT systems. After any significant change, run an unscheduled check.

What should be measured during a test?

Actual recovery time against the target RTO, tolerable data loss (RPO) and the cost of a day of downtime in money. Plus the quality of decisions and communications.

Evgeny Telenkov
Evgeny Telenkov
Chief risk officer · PhD in Economics · Risk Manager of the Year in Russia 2020
20 years in risk management. Led risk functions at Beeline, Nornickel, Rosneft and EY. Built business continuity plans for Nornickel, Rostec, NSD and DIA. Trained 300+ specialists in risk management and BCM.