Standards
ISO 22301 Business Continuity Consultancy
Every organisation will face disruption at some point: a cyber incident, a supplier failure, a site outage, extreme weather, loss of key people or a failure in critical systems. What separates organisations that recover quickly from those that struggle is usually preparation. ISO 22301 is the international standard for business continuity management, setting out how to understand what matters most, plan how to protect it, and prove those plans work.
Customers in regulated and critical sectors increasingly want evidence that their suppliers can keep delivering under pressure. For many organisations, ISO 22301 certification is the clearest way to provide it.
What ISO 22301 requires
The current edition is ISO 22301:2019, which follows the same Harmonized Structure as ISO 9001, ISO 14001 and ISO 27001. Its specific requirements focus on a clear sequence of activities:
Business impact analysis. Identifying your prioritised activities, the resources they depend on, and how quickly they need to be restored before the impact becomes unacceptable. This sets recovery time objectives and minimum acceptable service levels.
Risk assessment. Identifying the risks of disruption to those prioritised activities and deciding how to treat them.
Business continuity strategies and solutions. Deciding how each prioritised activity will be protected or recovered, covering people, premises, technology, information, suppliers and partners.
Plans and procedures. Documented, usable plans that set out who does what when disruption occurs, including incident response, communication and recovery.
Exercising and testing. A programme of exercises that tests plans against realistic scenarios, with findings fed back into improvement. Untested plans rarely survive contact with a live incident.
Evaluation and improvement. Internal audit, management review and continual improvement to keep continuity arrangements current as the business changes.
How Hillscom supports ISO 22301
First-time certification. Implementation starts with the business impact analysis, because everything else flows from understanding what matters most and how fast it needs to come back. From there, strategies, plans and an exercise programme are built to fit your organisation, whether that is a single-site business or a distributed operation with complex supply chains.
Plans that work under pressure. Business continuity plans are only useful if people can follow them in a stressful situation. Hillscom focuses on clear, short, role-based plans rather than lengthy documents that sit on a shelf.
Exercising. Designing and facilitating exercises, from desktop walkthroughs to more realistic scenario tests, and turning the lessons into practical improvements.
Integration with information security. ISO 22301 and ISO 27001 overlap significantly, particularly around incident management, risk assessment and ICT readiness. Implementing them together, or adding one to an existing system, avoids duplication and gives a more joined-up view of resilience. See integrated management systems.
Resilience as a commercial advantage
Business continuity is often treated as insurance: something to have in the background. In practice, organisations that can show credible, tested continuity arrangements win the confidence of customers who cannot afford supply interruptions. Hillscom helps build that capability in a way that is proportionate, practical and ready for use.
Get in touch to discuss ISO 22301 and business continuity planning.
Start a conversation
Talk to Hillscom
Tell us a little about your organisation and what you are trying to achieve. The first conversation is free and straightforward.