RUEN
Home/Readiness testing
Implementing BCM

Testing crisis readiness: methods and a checklist

A plan on paper and real readiness are different things. The only way to know whether a business would survive a serious disruption is to test it before the disruption happens. Here are the methods, from tabletop exercises to a full stress test.

Published: 24 July 2026 · Author: Evgeny Telenkov · ≈ 6 min read

Why test readiness

In our experience most continuity plans do not survive first contact with reality: contacts are out of date, the named owner has left, the backup will not restore, and decisions in the first hours are taken by someone without the authority to take them. Testing surfaces all of this early, while fixing it is still cheap. For companies working to ISO 22301, regular testing is a direct requirement of the standard.

Methods of testing: from simple to deep

  • Tabletop exercises. The management team works through a scenario around a table: who finds out first, who decides, what we tell clients. Takes 3-4 hours and exposes most organisational gaps. More in the article on continuity exercises.
  • Stress simulation. The team lives through a realistic scenario — most often a ransomware attack — with timed injects: decisions, communications, recovery. This is the format of our continuity stress test, run with an external facilitator.
  • Technical tests. Actually restoring systems from backups with the clock running — part of the IT disaster recovery plan.
  • Full stress test. A diagnostic of the continuity system plus a simulation plus the economics of downtime — the most complete snapshot of readiness in a short time.

What to measure

  1. Recovery time. How long recovery actually takes, against the target RTO.
  2. Data loss (RPO). How much data is lost when you roll back to the last backup.
  3. Money. The cost of a day of downtime and the share of revenue at risk — the language leadership actually responds to.
  4. Quality of decisions. Speed, gaps in authority, readiness of communications — recorded by an observer.
In practice: our two-day continuity stress test combines every level: a diagnostic day (100+ questions), a ransomware stress simulation with the leadership team, and a report for the CEO — damage in money terms, weak points and a 90-day plan.

Checklist of first steps

  1. Pick one scenario — the most painful for your industry (ransomware fits almost everyone).
  2. Gather the management team and the owners of key functions — 6 to 12 people.
  3. Run a tabletop session: 3-4 hours on the scenario, with an observer recording the gaps.
  4. Cost a day of downtime — roughly is fine, based on revenue.
  5. Write down the findings and assign owners and deadlines for the fixes.
  6. Repeat in six to twelve months — readiness fades without repetition.

Frequently asked questions

Where do we start with readiness testing?

With a tabletop session on a single scenario with the management team: ransomware or the loss of a key supplier. It takes 3-4 hours and exposes the main gaps.

How often should readiness be tested?

At least once a year on one scenario, and more often for critical IT systems. After any significant change, run an unscheduled check.

What should be measured during a test?

Actual recovery time against the target RTO, tolerable data loss (RPO) and the cost of a day of downtime in money. Plus the quality of decisions and communications.

From standard requirements to a working system

The assessment shows the gap between documents and reality. The system is then built by your people in the programme or by ours turnkey.

Evgeny Telenkov
Evgeny Telenkov
Director, business continuity practice · PhD in Economics · Academic Director & Chief Examiner
Risk Manager of the Year in Russia 2020 (RusRisk). Built business continuity from scratch at Nornickel, more than 20 plans; led risk functions at Beeline, Rosneft and EY. Chief risk officer of a 20 billion dollar petrochemical megaproject. Deputy chair of Rosstandart technical committee 010 "Risk management", co-author of six national standards. Author of the ERGP and SAFE programmes.