Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

Business Continuity Management

Sooner or later, every company faces disruptions to its IT systems, supply chains, or workforce. A robust Business Continuity Management (BCM) system ensures that critical processes continue to run or resume quickly even in the event of such disruptions. mgm security partners supports you in establishing, operating, and further developing your BCM system, using a methodologically sound approach based on BSI Standard 200-4 and ISO 22301, and aligned with the regulatory requirements of DORA and NIS-2.

BCM is becoming mandatory: DORA requires financial institutions to have a tested business continuity and emergency management system, while NIS-2 mandates measures to maintain operations and manage crises. A structured BCM system based on BSI 200-4 or ISO 22301 is the proven way to demonstrably meet these requirements.

Background

Fundamentals

What BCM Does

Business Continuity Management is an organization’s systematic approach to dealing with disruptions and emergencies. It ensures that time-critical business processes are identified, prioritized, and—in the event of an emergency—can be continued or resumed within acceptable downtime limits. At the core of BCM are the analysis of the effects of outages (Business Impact Analysis), the resulting prevention and response strategies, and proven emergency and recovery plans.

We support you throughout the entire BCM lifecycle, from the initial implementation of a Business Continuity Management System (BCMS) to ongoing operations and continuous improvement. We base our approach on the BSI 200-4 standard and ISO 22301, and translate the requirements of DORA and NIS-2 into concrete, appropriate measures for your organization.

BSI 200-4
Methodological Framework for a BCMS Based on the Current BSI Standard
ISO 22301
An internationally recognized standard, designed to be certifiable upon request
DORA / NIS-2
Regulatory requirements for business continuity and crisis management have been met
Tried and tested
Emergency plans that have proven their effectiveness through tests and drills

BCM is not a project, but a cycle

Fundamentals

An effective BCM is not established in a single step, but rather goes through a continuous cycle of analysis, design, implementation, testing, and improvement. Its structure follows the BSI 200-4 standard and ISO 22301.

The BCM Lifecycle: The "Tests and Exercises" phase ensures the effectiveness of the planned measures.

The challenge

Attention!
  • Disruptions caused by IT, personnel, buildings, or suppliers are virtually unavoidable
  • DORA and NIS-2 require a verifiably tested continuity management system
  • Critical processes and acceptable downtime are often not clearly defined
  • Emergency plans exist, but they are outdated, unknown, or have never been tested
  • BCM methodology in accordance with BSI 200-4 or ISO 22301 is not consistently available internally
  • In an emergency, there is a lack of clear roles, reporting channels, and decision-making structures

Our Added Value

Result
  • Structured Implementation of a BCMS in Accordance with BSI 200-4 and ISO 22301
  • Business Impact Analysis and Risk Analysis as a Solid Basis for Decision-Making
  • Practical emergency and recovery plans instead of documents that just sit in a drawer
  • Translation of the DORA and NIS 2 requirements into appropriate measures
  • Testing through emergency and crisis drills with documented effectiveness
  • Regulatory and technical expertise from a single source, with access to penetration testers and auditors

An Overview of Our BCM Support

Offer

From setting up the management system to conducting a business impact analysis and testing and maintaining emergency plans. We tailor the scope and depth of our services to your specific situation and regulatory requirements.

  • Initiation, Vision, and Scope
  • BCM Guidelines and Role Model
  • Involvement of Management and Functional Departments
  • Compliance with BSI 200-4 and ISO 22301
  • Identification of Time-Sensitive Business Processes
  • Determining Acceptable Downtime (MTA / RTO)
  • Dependencies on IT, personnel, and service providers
  • Prioritization as the Foundation for Strategy
  • Analysis of Relevant Threat and Failure Scenarios
  • Assessment of Existing Preventive Measures
  • Development of Prevention and Coping Strategies
  • Balancing Effort, Risk, and Appropriateness
  • Emergency, Restart, and Recovery Plans
  • Crisis Management, Reporting Channels, and Emergency Alerts
  • Emergency Manual and Immediate Actions
  • Integration with IT Service Continuity (ITSCM)
  • Design and Implementation of Emergency and Crisis Drills
  • From the planning meeting to the full-scale drill
  • Structured Analysis and Lessons Learned
  • Identification of specific improvement measures
  • Maintenance of BIA, Strategies, and Emergency Plans
  • Management Review and Key Performance Indicators
  • Preparing for Audits and Regulatory Compliance
  • Continuous Improvement Process (CIP)

BSI 200-4, ISO 22301, DORA, and NIS-2—all from a single source

We build your BCM on a recognized methodological foundation and ensure that it also meets the regulatory requirements that apply to you. We work with you to select the appropriate framework, tailored to the size and risk profile of your organization. If necessary, we clarify the scope of impact and requirements through our DORA and NIS2 consulting services.

  • BSI Standard 200-4: Step-by-Step Implementation of a BCMS with BIA, Risk Analysis, and Emergency Plan, Compatible with BSI IT-Grundschutz.
  • ISO 22301: A business continuity management system (BCMS) based on an internationally recognized standard, designed and implemented to be certifiable upon request.
  • DORA (Financial Sector): Business continuity, emergency and crisis management, including regular testing in accordance with digital operational resilience requirements.
  • NIS-2: Measures to ensure business continuity, backup, and crisis management as part of risk management obligations.
  • Integration with the ISMS: BCM complements the Information Security Management System and draws on shared risk and asset frameworks.

What Our BCM Support Includes

Approach

We'll set up your BCM, operate it together with you, and test it. You'll receive the foundational knowledge and expert guidance you need to ensure your business continuity remains effective over the long term.

  • Establishment and Further Development of the BCMS in Accordance with BSI 200-4 and ISO 22301
  • Business Impact Analysis and Risk Analysis
  • Development of emergency, recovery, and crisis plans
  • Establishment of the Crisis Management Structure, Including Roles and Reporting Channels
  • Design, Implementation, and Evaluation of Exercises
  • Preparing for Audits and Regulatory Compliance

From Analysis to BCM in Practice

We’ll implement your BCM in a structured manner without overcomplicating things. We’ll work together primarily remotely, though on-site meetings for workshops and exercises can be arranged upon request.

  • 1 – Assessment: Joint evaluation of your BCM maturity level; clarification of the target state, scope, and regulatory framework.
  • 2 – Analysis & Planning: Business impact analysis, risk analysis, and development of business continuity strategies and emergency plans.
  • 3 – Implementation & Testing: Developing emergency plans, establishing a crisis management structure, and testing them through appropriate drill formats.
  • 4 – Operation & Improvement: Ongoing maintenance, management review, and continuous improvement to ensure that the BCM remains up to date.

BCM in Relation to Your Other Topics

Business continuity is closely linked to regulatory requirements, information security, and crisis drills. Depending on the specific situation, we combine BCM support with our other services.

Business Impact Analysis

The starting point for every BCM. We identify your critical processes and the RTO, MTA, and RPO targets as the foundation for planning.

Emergency Drills for BCM

Plans alone aren't enough. We plan and facilitate emergency and crisis drills and demonstrate the effectiveness of your BCM.

DORA & NIS2 Consulting

DORA and NIS-2 require a tested business continuity and crisis management plan. We’ll assess your compliance status and work with you to implement the requirements.

Regulatory, Methodological, and Technical Solutions from a Single Source

  • Over 25 years of experience in IT security consulting
  • BCM in accordance with the current BSI Standard 200-4 and ISO 22301
  • ISO 27001 certified and TISAX-compliant
  • Experience from projects for government agencies and operators of critical infrastructure

mgm security partners covers the full spectrum of IT security, from consulting to security analyses and penetration tests to training. For your BCM, this means: We combine BCM methodology in accordance with BSI 200-4 and ISO 22301 with regulatory expertise on DORA and NIS-2, as well as in-depth technical knowledge of IT service continuity. We are ISO 27001 and TISAX certified and work for the BSI, other government agencies, and KRITIS operators, among others.

BCM Support: Quick Answers to Your Questions

Both describe how to set up a business continuity management system. The BSI 200-4 standard is a very practical, step-by-step methodology from Germany that aligns well with the BSI IT-Grundschutz. ISO 22301 is the internationally recognized standard and the basis for certification. We’ll work with you to choose the right framework; often, it makes sense to combine the two.

DORA requires affected financial institutions to have a tested business continuity and emergency management plan. NIS 2 mandates measures for business continuity, backup management, and crisis management as part of risk management. A structured BCM is the proven way to demonstrably meet these requirements. We can help you determine how these regulations specifically apply to your organization through our DORA and NIS 2 consulting services.

Contingency plans are an important component, but without a business impact analysis, priorities are often not properly established, and without testing, their effectiveness remains uncertain. We review your existing documentation, fill in the missing elements of the lifecycle, and ensure that your plans are up to date, well-known, and practiced.

That depends on the size, complexity, and desired level of maturity. A streamlined, effective initial implementation—including BIA, a continuity strategy, and initial contingency plans—can often be achieved in just a few months. A fully developed, certifiable BCMS is built step by step. We take a risk-based approach and prioritize the most critical processes first.

Yes. Testing is an integral part of the BCM lifecycle and is even explicitly required by DORA. We design and facilitate appropriate exercise formats—ranging from plan reviews to full-scale exercises—and use the results to identify specific areas for improvement. You can find more details on our page about emergency exercises for BCM.

BCM and the Information Security Management System (ISMS) complement each other. Both are based on a shared view of critical processes and assets. An existing ISMS provides valuable groundwork for the BIA and risk analysis. We integrate both systems to help you avoid duplication and ensure consistency in your documentation.

Maximiliane Mayer

Make your business resilient. Contact us for a free initial consultation!