Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Business continuity»Business continuity and IT in resilience: improving collaboration (Page 8)
Business continuity

Business continuity and IT in resilience: improving collaboration

August 28, 20257 Mins Read
A digital hand points to an integration icon consisting of two cogs. This is surrounded by a number of IT and business related icons.

By Rachael Elliott

Both business continuity and IT professionals have a role to play in resilience, but how do we improve working partnerships in this area? Both areas have distinct, but often complementary knowledge and outlook. Business continuity professionals know how to ensure that their organization has the means to recover critical activities in the event of a crisis. Meanwhile, IT professionals know how to build an information security management system (ISMS) which will identify threats, address system vulnerabilities, and ensure correct action is taken in the event of an impactful cyber attack.

Most business continuity and resilience professionals will be aware of standards (e.g. ISO 22301), frameworks  (e.g. the DRI International Professional Practices for Business Continuity Management), or regulations (e.g. the Digital Operational Resilience Act – DORA) that guide or mandate professionals to construct programmes to ensure business continuity and/or operational resilience of their organizations. Whereas information security professionals will be more familiar with the ISO/IEC 27001 standard for information security.

The big question is what happens in the event of an IT software or systems outage? Which of the two sides should take charge? Are some professionals still treading on eggshells and worrying they are encroaching on the territory of another department’s expertise? And is the language of ‘sides’, ‘encroachment’, and ‘territory’ indicative of the problem that needs addressing? At the heart of resilience management is taking a holistic approach, building  cohesiveness and collaboration, and breaking down silos.

Step forward ISO/IEC 27031

The update of the ISO/IEC 27031 standard in May 2025 has quietly launched and goes some way in helping to standardise the uncoordinated middle ground identified above.

ISO/IEC 27031 was initially published in 2011 as Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity. This version is now withdrawn replaced by the 2025 edition, titled Cybersecurity — Information and communication technology readiness for business continuity.

So, what has improved in the update of this 14-year-old standard and how does it help to help improve joint working between IT and business continuity professionals? Important areas include:

  • Direct business continuity management (BCM) integration: Clause 6 of the standard ties ICT Readiness for Business Continuity (IRBC), directly into the BCM lifecycle (governance and strategy selection) rather than both sides being siloed. Furthermore, Clause 7 in the standard requires using insights from the BIA (e.g. critical IT services, dependencies, critical suppliers) to set IRBC scope and expectation to directly ensure that technology requirements match business priorities.
  • Mapping directly to the three Ps of business continuity – people, processes, premises: Clause 9.2 guides organizations on how to select IRBC strategies across skills, technology, data, processes, and suppliers, which helps to ensure ICT integration is not purely focused on tooling solutions and the technology side.
  • Talking the same language: Clauses 10.2–10.3 cover activation, escalation, and ICT recovery plans aligned to recovery time objectives (RTOs) and recovery point objectives (RPOs). It also specifically calls for RTO, RPO, and minimum business continuity objectives (MBCO) as the key targets that ICT must meet.

The updated standard now also acknowledges reliance on external cloud services and advises organizations to integrate dependencies with these and other critical third parties, to ensure readiness for disruption in supply chains.

The new standard definitely fills a gap and, as it is for guidance only, organizations can align their operations to it without the costs involved with formal certification. However, as the previous article in this series discussed, compulsory adherence to rules, standards, and regulations can help to ensure board support and buy-in for programmes. Without this, financial support will often be prioritised for those programmes that focus on profitability – and short-term productivity at that.

IT software and service resilience needs prioritising – it’s not all about cyber

Cyber resilience is of huge importance to organizations, particularly with the advent of artificial intelligence (AI). Attacks can be generated by individuals with very little IT knowledge and deepfakes can trick staff into transferring large sums of funds. Attacks not only lead to major financial losses but also bring about severe reputational harm which, for some businesses, may be irreparable.

Cyber security rightly earns its place as a board priority, but other IT issues frequently fail to warrant the attention they deserve. Indeed, the Uptime Institute’s Annual Outage Analysis 2024 showed that outages due to cyberattacks or ransomware were only fourth in the list of leading causes for outages (11%), whereas IT software and configuration (23%), network software and configuration (22%), and power (11%) cumulatively accounted for 56% of outages. Therefore, to stop more outages taking businesses out for days, there is a need to go beyond what a guidance standard such as ISO/IEC 27031 can offer to the industry.

A way forward?

“Treat IT resilience like we treat safety.”

This quote comes from the title of a July 2025 paper by the BCS, British Computer Society, on the back of the recently published policy statement on the UK Government’s planned Cyber Security and Resilience Bill.

While the BCS paper acknowledges that the new Bill will be a major step forward, it is calling for IT resilience to be given similar consideration to how health and safety is treated within an organization. The three-pronged approach suggested is:

  • Better visibility of data on the impact of digital incidents to users: by providing greater transparency of data, the impact of incidents can be better quantified through highlighting the frequency and effects of these incidents.
  • Visibility of all digital incidents over a defined threshold: this would include all incidents, not just those caused by cybercrime. Initially, this should be across all critical national infrastructure (CNI) sectors, but ultimately across all sectors.
  • Government support for the sharing of vulnerabilities, root causes, and impacts: this would be across all sectors and could be based on an existing platform.

Currently, while data may be available for some sectors, there is a lack of ordered collaboration and cohesive information. Some organizations might track data points for their own cyber security purposes – right down to millions of near misses in some cases – while others already have committees to tackle cyber vulnerabilities internally. The BCS paper is calling for this to change, calling for organizations to take public accountability for the effects of digital incidents on their end users. Until this happens, a lack of culpability means senior management will still be able to turn a blind eye to incidents.

Where does this leave us?

It certainly feels that IT and digital resilience is gaining gravitas through the launch of new regulations (notably the FCA/PRA/Bank of England in the UK, DORA in the European Union, the CPS 230 APRA standard in Australia, and the MAS regulations in Singapore), government acts, and the introduction of the ‘bridging’ ISO 27031 standard between IT resilience and business continuity. In just 12 months, it appears IT systems resilience has moved forward significantly.

Furthermore, there is a sense of unity between the very different documents discussed in this paper: there is a united risk picture that does not underplay the importance of non-cyber failures; and there is an increased push for better data to inform IRBC assumptions and the BIA, as well as supplier choices. There is also greater consideration towards digital third-party risk, together with outcome metrics that matter to users and customers, rather than solely focusing on ensuring internal operations continue to function effectively.

However, the third point of the BCS paper is probably the key to changing the way IT resilience is considered. Organizations need to change the way they incorporate IT into their overall resilience strategies to protect them from succumbing to potentially business-ending outages.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRII logo
Resilience Perspectives
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleIncident response planning emerges as a key cybersecurity control, says report
Next Article How organizations can stay resilient in the face of technology disruption

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A cargo ship being loaded at a port.

UK Government report explores supply chain risk and resilience

June 24, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?