By Rachael Elliott
Both business continuity and IT professionals have a role to play in resilience, but how do we improve working partnerships in this area? Both areas have distinct, but often complementary knowledge and outlook. Business continuity professionals know how to ensure that their organization has the means to recover critical activities in the event of a crisis. Meanwhile, IT professionals know how to build an information security management system (ISMS) which will identify threats, address system vulnerabilities, and ensure correct action is taken in the event of an impactful cyber attack.
Most business continuity and resilience professionals will be aware of standards (e.g. ISO 22301), frameworks (e.g. the DRI International Professional Practices for Business Continuity Management), or regulations (e.g. the Digital Operational Resilience Act – DORA) that guide or mandate professionals to construct programmes to ensure business continuity and/or operational resilience of their organizations. Whereas information security professionals will be more familiar with the ISO/IEC 27001 standard for information security.
The big question is what happens in the event of an IT software or systems outage? Which of the two sides should take charge? Are some professionals still treading on eggshells and worrying they are encroaching on the territory of another department’s expertise? And is the language of ‘sides’, ‘encroachment’, and ‘territory’ indicative of the problem that needs addressing? At the heart of resilience management is taking a holistic approach, building cohesiveness and collaboration, and breaking down silos.
Step forward ISO/IEC 27031
The update of the ISO/IEC 27031 standard in May 2025 has quietly launched and goes some way in helping to standardise the uncoordinated middle ground identified above.
ISO/IEC 27031 was initially published in 2011 as Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity. This version is now withdrawn replaced by the 2025 edition, titled Cybersecurity — Information and communication technology readiness for business continuity.
So, what has improved in the update of this 14-year-old standard and how does it help to help improve joint working between IT and business continuity professionals? Important areas include:
- Direct business continuity management (BCM) integration: Clause 6 of the standard ties ICT Readiness for Business Continuity (IRBC), directly into the BCM lifecycle (governance and strategy selection) rather than both sides being siloed. Furthermore, Clause 7 in the standard requires using insights from the BIA (e.g. critical IT services, dependencies, critical suppliers) to set IRBC scope and expectation to directly ensure that technology requirements match business priorities.
- Mapping directly to the three Ps of business continuity – people, processes, premises: Clause 9.2 guides organizations on how to select IRBC strategies across skills, technology, data, processes, and suppliers, which helps to ensure ICT integration is not purely focused on tooling solutions and the technology side.
- Talking the same language: Clauses 10.2–10.3 cover activation, escalation, and ICT recovery plans aligned to recovery time objectives (RTOs) and recovery point objectives (RPOs). It also specifically calls for RTO, RPO, and minimum business continuity objectives (MBCO) as the key targets that ICT must meet.
The updated standard now also acknowledges reliance on external cloud services and advises organizations to integrate dependencies with these and other critical third parties, to ensure readiness for disruption in supply chains.
The new standard definitely fills a gap and, as it is for guidance only, organizations can align their operations to it without the costs involved with formal certification. However, as the previous article in this series discussed, compulsory adherence to rules, standards, and regulations can help to ensure board support and buy-in for programmes. Without this, financial support will often be prioritised for those programmes that focus on profitability – and short-term productivity at that.
IT software and service resilience needs prioritising – it’s not all about cyber
Cyber resilience is of huge importance to organizations, particularly with the advent of artificial intelligence (AI). Attacks can be generated by individuals with very little IT knowledge and deepfakes can trick staff into transferring large sums of funds. Attacks not only lead to major financial losses but also bring about severe reputational harm which, for some businesses, may be irreparable.
Cyber security rightly earns its place as a board priority, but other IT issues frequently fail to warrant the attention they deserve. Indeed, the Uptime Institute’s Annual Outage Analysis 2024 showed that outages due to cyberattacks or ransomware were only fourth in the list of leading causes for outages (11%), whereas IT software and configuration (23%), network software and configuration (22%), and power (11%) cumulatively accounted for 56% of outages. Therefore, to stop more outages taking businesses out for days, there is a need to go beyond what a guidance standard such as ISO/IEC 27031 can offer to the industry.
A way forward?
“Treat IT resilience like we treat safety.”
This quote comes from the title of a July 2025 paper by the BCS, British Computer Society, on the back of the recently published policy statement on the UK Government’s planned Cyber Security and Resilience Bill.
While the BCS paper acknowledges that the new Bill will be a major step forward, it is calling for IT resilience to be given similar consideration to how health and safety is treated within an organization. The three-pronged approach suggested is:
- Better visibility of data on the impact of digital incidents to users: by providing greater transparency of data, the impact of incidents can be better quantified through highlighting the frequency and effects of these incidents.
- Visibility of all digital incidents over a defined threshold: this would include all incidents, not just those caused by cybercrime. Initially, this should be across all critical national infrastructure (CNI) sectors, but ultimately across all sectors.
- Government support for the sharing of vulnerabilities, root causes, and impacts: this would be across all sectors and could be based on an existing platform.
Currently, while data may be available for some sectors, there is a lack of ordered collaboration and cohesive information. Some organizations might track data points for their own cyber security purposes – right down to millions of near misses in some cases – while others already have committees to tackle cyber vulnerabilities internally. The BCS paper is calling for this to change, calling for organizations to take public accountability for the effects of digital incidents on their end users. Until this happens, a lack of culpability means senior management will still be able to turn a blind eye to incidents.
Where does this leave us?
It certainly feels that IT and digital resilience is gaining gravitas through the launch of new regulations (notably the FCA/PRA/Bank of England in the UK, DORA in the European Union, the CPS 230 APRA standard in Australia, and the MAS regulations in Singapore), government acts, and the introduction of the ‘bridging’ ISO 27031 standard between IT resilience and business continuity. In just 12 months, it appears IT systems resilience has moved forward significantly.
Furthermore, there is a sense of unity between the very different documents discussed in this paper: there is a united risk picture that does not underplay the importance of non-cyber failures; and there is an increased push for better data to inform IRBC assumptions and the BIA, as well as supplier choices. There is also greater consideration towards digital third-party risk, together with outcome metrics that matter to users and customers, rather than solely focusing on ensuring internal operations continue to function effectively.
However, the third point of the BCS paper is probably the key to changing the way IT resilience is considered. Organizations need to change the way they incorporate IT into their overall resilience strategies to protect them from succumbing to potentially business-ending outages.
The author
Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.







