Business Continuity Planning
The Emergency Plan Handles the Crisis. Nobody Plans for the Day After.Last month, a manufacturing organisation approached Technique Works to build its business continuity programme from the ground up. Not a gap assessment. A full build: the templates, the continuity management platform, the training framework, and the implementation support to build up the system at their facility. They had an emergency response plan. It was current, detailed, and compliant. What they did not have was a tested recovery architecture for events that would stop the business rather than a department, and they had arrived at that conclusion not through an external audit but through a direct question: 'What happens to our operations, our customer commitments, and our contractual obligations if our primary facility is forced to stop for a month?' That engagement led to a pattern. Our Gulf region office has seen a steady increase in enquiries from organisations asking the same question in different ways. Organisations in a region where disruption has moved from theoretical to observable and where events in recent months that most operators would previously have placed outside their planning horizon have occurred are now confronting the gap between their emergency response capability and their actual recovery architecture. The question driving those conversations is not whether they have an emergency plan. Most do. The question is whether they plan how an organisation-level event affects the business in the weeks and months after the incident is brought under control. That gap, visible in both regions, is what this edition addresses. SECTION 1: Emergency preparedness and business continuity are not the same programme.In many industrial organisations, they are treated as one, owned by the same function, documented together, and tested in the same exercises. The distinction between them is lost. The cost of that confusion becomes visible when a serious event occurs. Emergency preparedness is the response to a specific, contained event. A fire in one production area. A chemical release in one part of the plant. A piece of critical equipment that fails in one section of the facility. The scope is operational and local. The decision-makers are the emergency coordinator, the site management team, and the incident commander. The duration is measured in hours. The objective is to control the hazard, protect people, and stabilise the situation. Business continuity is activated at a different threshold, when an event threatens to stop the organisation's core processes entirely. A cyberattack that brings down the IT infrastructure and, with it, every system the operation depends on. A facility event that halts production and breaks supply commitments to major customers. A disruption in the operating environment that makes working from the primary location impossible for an extended period. When that threshold is crossed, the nature of what is required changes completely. The decisions required during a business continuity event are not HSEQ decisions. They are decisions about which contractual obligations the company can meet and which it cannot. These decisions include whether to activate an alternative production site, which regulatory authority to notify, how to communicate with investors, and what to tell the supply chain partner and when. Those decisions belong to the CEO, the general manager, and in serious cases the board of directors. The HSEQ director is one contributor to the business continuity plan, responsible for a defined set of processes within it. He does not run the response. He does not have the authority to make the decisions that BCP requires at scale. This distinction has a direct consequence for how organisations should approach BCP ownership. If the primary accountable party is the CEO, then the CEO needs to know whether the plan reflects the actual exposures the business faces, not as a governance checkbox, but as an operational reality. Most do not know. Most have delegated that question down and assumed it was answered. Recommended Reading: The Case
SECTION 2: ISO 22301, the international standard for Business Continuity Management Systems, defines the framework.It requires organisations to identify their critical business functions; assess the impact of disruption through a Business Impact Analysis (BIA), and set Recovery Time Objectives and Recovery Point Objectives that are operationally grounded and commercially credible. In practice, most organisations have a gap in their BIA. A Recovery Time Objective is the honest answer to one question: how long can this function stop before the disruption becomes a business-level event, not just an operational inconvenience? In manufacturing, that answer is defined by the customer supply agreement, the contractual penalty clause, and the inventory buffer the customer is carrying downstream. Ask yourself: what does it cost when your main production line stops for one day? Now extend that by seven days. By thirty. At what point does the financial consequence stop being manageable and start threatening the quarter, the year, or the relationships that took years to build? That calculation is not a theoretical exercise. It is the Business Impact Analysis, and it can only be done correctly when the person conducting it has access to the contract register, the commercial commitments, and the business's financial model. That person is not typically the HSEQ director. That is why the BCP that was built without involving the CEO or CFO is almost always incomplete in the places that matter most. The 2022 UNDRR Global Assessment Report on Disaster Risk Reduction found that fewer than 30% of surveyed enterprises had tested their business continuity plans under conditions requiring real operational decisions, not conference-room tabletops, but exercises that forced leadership to execute the recovery sequence under time pressure, with incomplete information, and against the actual terms of their commercial obligations. The gap between the document and the tested capability is where organisations find out, too late, what their plans are really worth. For Gulf-region operations, the UAE's NCEMA business continuity standards require BCM frameworks to be tested against real operational dependencies. Those standards are increasingly referenced in procurement processes across the region's industrial sector, and organisations that cannot demonstrate tested continuity capability are finding that this gap is affecting their commercial positioning, not just their compliance status. For Western European operations, the EU Critical Entities Resilience Directive, which has been in effect since October 2024, extends the regulatory obligation from emergency response into recovery architecture for operators across eleven critical sectors. The direction in both regions is consistent: emergency response is the beginning of the governance obligation, not its end. Recommended Reading: The Evidence
CASE STUDYA pharmaceutical manufacturing site in the Netherlands conducted a full business continuity exercise for an IT security breach scenario. The scenario was chosen deliberately: a cyberattack that takes down the organisation's IT infrastructure takes down every system the operation depends on: manufacturing execution, batch records, quality systems, supply chain management, and communications. An IT breach is not a technology incident with operational side effects. It is an organisation-wide shutdown event. Everything stops. The exercise was comprehensive. The entire organisation was involved in the exercise. All relevant stakeholders participated. Multiple scenarios had been designed, documented, and prepared in advance. By the standard of what preparation usually looks like, the work had been done. The exercise revealed that the organisation was not ready. The gap was not in the documentation. It was in the execution under realistic conditions. When the scenarios ran, coordination between functions that the plan assumed would work did not function as described. Recovery decisions that appeared straightforward in a document review required pre-authorisations that had not been established. Communication flows that worked during the planning process broke down under the load of a simulated multi-function incident. The people who were supposed to make certain decisions during a BCP activation did not know that those decisions were theirs to make. That last point is the most important. In a business continuity event, the decision-making authority must be pre-assigned, pre-communicated, and understood by everyone in the response structure before the event occurs. It cannot be negotiated during the event. The organisation discovered, through the drill, that this clarity did not exist. The output was a corrective and preventive action register. Accountability was assigned. The gaps were closed. The organisation's continuity capability after the exercise was materially better than before, because the exercise was designed to challenge the plan, not confirm it, and because the right people were in the room. That last condition, the right people, is not guaranteed. In this case, senior leadership ran the business continuity exercise, not just the HSEQ and IT functions. That is what made the authority gap visible. A drill run at the functional level would have confirmed the functional procedures and missed the command structure entirely. Recommended Reading: BCP Exercise Design
SECTION 3: THE PRINCIPLEMay's edition argued that documentation does not equal readiness, and that a plan written against the scenarios the planners anticipated will fail when the real event falls outside those parameters. That argument resonated because it described something that operational leaders recognised. June's argument is one level up. The emergency plan is for the incident. The business continuity plan is for the business. They are different in scope, different in duration, and different in who is accountable. When a serious disruption threatens core revenue-generating processes, the CEO—not the HSEQ director—bears responsibility for the response. That accountability has a specific implication: the CEO needs to know whether the BCP reflects the actual range of events the business faces. This analysis does not include the events that appeared on the risk register two years ago. The actual range includes scenarios that have moved from unlikely to observable in the operating environments where the business operates, as well as those that still seem remote but carry consequences that the business could not absorb if they were to materialise. The pharmaceutical site found these scenarios through an exercise. The Gulf-region organisations seeking BCP programmes are finding them through exposure to these scenarios. The right time to identify it is before either of those conditions exists. The certification is the baseline. The tested capability is what determines the outcome. Recommended Reading: The Principle
HSEQ MARKET INSIGHTS: JUNE 2026Four data points are shaping the business continuity conversation in the industrial sector right now. 1. Fewer than 30% of enterprises have tested their BCP under realistic conditions. The 2022 UNDRR Global Assessment Report on Disaster Risk Reduction found that fewer than three in ten surveyed enterprises had tested their business continuity plans under conditions requiring real operational decisions, not conference-room tabletops, but exercises with time pressure, incomplete information, and commercial obligations on the table. Most organisations have the document. Most have not tested whether the document reflects operational reality. Source: UNDRR Global Assessment Report on Disaster Risk Reduction, 2022. 2. GCC procurement is tightening BCM requirements. The UAE's NCEMA Business Continuity Management Standard requires BCM frameworks to be tested against actual operational dependencies. In the current environment, organisations across the GCC industrial sector that cannot demonstrate tested continuity capability are finding these gap-closing commercial options. Procurement qualification processes are increasingly citing BCM readiness, not just certification. Source: UAE NCEMA BCM Standard; Technique Works Gulf region engagement observations, 2026. 3. The EU CER Directive is live, and most European operators have not completed their gap assessment. The EU Critical Entities Resilience Directive (Directive 2022/2557) required transposition into member state law by October 2024. It extends the compliance boundary from emergency response to recovery architecture for operators in eleven designated critical sectors. Organisations that completed their ISO 22301 certification before 2023 and have not reviewed their BCP scope against the CER obligations likely carry an unmeasured gap. Source: EU Directive 2022/2557 on the Resilience of Critical Entities. 4. The BIA-contract gap is the most consistent finding in BCP engagements. Across Technique Works BCP engagements in Western Europe and the Gulf region, the most consistent finding is the same: Recovery Time Objectives set to satisfy an ISO auditor, rather than derived from customer supply agreements or contractual penalty clauses. The BIA exists. It is not commercially accurate. The result is a continuity plan that is compliant on paper but indefensible in the event of a real disruption. Source: Technique Works operational observations across 47 facilities in Western Europe and the GCC. QUESTIONS FOR YOU TO CONSIDERFive questions grounded in this edition's argument. They are not rhetorical. They are diagnostic. 1. When was your business continuity plan last reviewed at the CEO or board level, not reviewed by the HSEQ function but reviewed by the people who would be making the decisions if it were activated tomorrow? 2. Does your BCP address scenarios that are now observable in your operating regions but were not on your planning horizon when the document was last written? 3. Do the people who are supposed to make decisions during a BCP activation know, in advance, that those decisions are theirs? Has that authority been pre-assigned, communicated, and tested? 4. What is the Recovery Time Objective for your most critical production line or service function? Which customer contract or regulatory requirement set that number, and was the person who set it in the room when those commitments were made? 5. Has your BCP ever been tested under conditions that forced real operational decisions, under time pressure, against your actual commercial terms, with the people who would be leading the response actually running the exercise? If the answer to any of these is "I don't know" or "I'd need to consult with the HSEQ team", the BCP ownership question is already visible. PRACTICAL ACTIONFour steps. In sequence. The first one takes fifteen minutes. The last one takes ninety. Step 1. Pull your BCP from wherever it lives, and check the revision date and the approval chain. If the CEO or CFO is not in that chain, the document was built without the people who hold the commercial exposure. Step 2. Find the Business Impact Analysis. Locate the Recovery Time Objectives for your two or three most critical production or service functions. For each one, identify which customer contract or regulatory commitment drove that number. If no contract or obligation is referenced, the RTO is estimated rather than analysed. Step 3. Identify the three decisions that would need to be made in the first 72 hours of a BCP activation. For each decision, name the person who holds the authority to make it. Then confirm that the person knows they hold it. Step 4. Schedule 90 minutes with the GM and the HSEQ director. Not to review the document. To ask one question: if we had to activate this tomorrow, who would call the customers, and what would they say? PERSONALISED RECOMMENDATIONSThe same argument lands differently depending on where you sit. For the CEO / General Manager Your role in BCP is not to manage the plan. Your role is to own the exposure. The BCP was probably built by a function that understands HSEQ well but may not have had access to your contract register, your financial model, or the commercial commitments that define what "recovery" means for your business. Before the next board cycle, ask whether the BIA was built with those inputs. If it wasn't, the plan is incomplete in the areas that carry the greatest financial consequences. For the COO / Operations Director Your role in a BCP activation is to execute the recovery sequence, but only if that sequence has been designed with operational reality in mind. The most common failure is an RTO that is technically achievable in isolation but commercially indefensible when mapped against supply commitments. Your responsibility is to address that gap before the event, rather than explaining it during one. Pull the BIA. Review the RTOs against the customer terms. If they don't align, that is the work. For the HSEQ Director Your role in BCP is defined and consequential, but it is only one contribution, not the whole plan. The decisions that BCP requires at scale involve contractual obligations, investor communications, regulatory notifications, and operational authorities that sit above the HSEQ function. If your organisation has positioned HSEQ as the primary BCP owner for all of these, you are taking on accountability for decisions that you do not have the authority to make. The right posture is to be the architect of the HSEQ processes within BCP and the bridge connecting the CEO and GM to the plan, not the person expected to run it alone. NEXT MONTHJuly's edition follows the arc directly. The business continuity plan handles the recovery. The incident investigation handles the learning. When a serious event occurs in an industrial operation, the investigation that follows determines whether the organisation understands what actually happened or produces a finding that is legally defensible, operationally comfortable, and structurally wrong. Most industrial incident investigations stop the moment they reach a human action. "Operator failed to follow procedure" and "Supervisor didn't notice in time" are not root causes. They are the point at which the investigation became uncomfortable and stopped. The organisations that stop there will repeat the incident. The organisations that go deeper, to the systemic conditions that made the human failure predictable, stop it. July's argument: you stopped at human error. The investigation was not finished. TECHNIQUE WORKS INSIGHTSEach edition of Technique Works HSEQ Insights is published monthly at insights.techniqueworks.com. If this edition is useful, subscribe to receive it directly. The full archive, including the May edition on emergency preparedness and the complete series from November 2025, is there now. Subscribe → insights.techniqueworks.com If you require more information about how to build your BCP, contact us at info@techniqueworks.com or book a meeting on https://calendly.com/techniqueworks-info/30min?month=2026-06 Amador Brinkman · Technique Works Technique Works · HSEQ Insights Newsletter · Edition 10 · June 2026 |