Relevant Contents
Need Tailored Business Continuity Insights?
Contact Us Now for Personalized Guidance!
Many continuity planners cling to the belief that their beautiful documentation amounts to a guarantee they will be able to recover swiftly from an outage. In fact, the only thing that provides real assurance of recoverability is effective performance in realistic exercises.
Related: Fooling Themselves: Why Most Companies Overestimate Their IT/DR Capabilities
Summary
- Strong business continuity documentation is important, but it does not prove that the organization can recover.
- Standards alignment shows that a foundation is in place. Realistic exercises show whether the program can perform.
- Organizations that stress test their plans can identify gaps, understand residual risk, and make better recovery decisions.
The Pleasures of Quality BC Documentation
I love business continuity documentation. When a client sends or hands me a stack of BC program documents, I devour them like a financial analyst reading an annual report.
I’ve certainly seen enough BC documentation over the years.
Whether it’s BIAs or strategy documents, policy statements or post-exercise reports, or any of the other artifacts that BC programs generate, I have read (and written) more of them than you can shake a stick at.
This experience has exposed me to a lot of very poor documentation. It’s also brought me into contact with a good deal of documentation of the highest quality.
When I come across clear, comprehensive, detailed, and beautifully laid out BC documents that demonstrate high compliance with the standards, I’m always appreciative and impressed.
I know how hard it is to meet those benchmarks and produce such material. I understand the effort and care the BC office demonstrated in implementing the necessary program elements and pulling the documentation together.
Great Documentation Is Not Enough
It’s because of the respect I have for quality BC documentation that I’m experiencing a slight feeling of regret as I write this week’s blog. I know it’s going to make some of the most dedicated BC practitioners out there wince.
However, the point must be made: having impressive documentation, even documentation that shows high compliance with the standards, is no guarantee that your program is capable of recovering the business.
You might say, why bother with the standards if aligning with them doesn’t guarantee recoverability?
Well, the standards are necessary but not sufficient, as they themselves state.
Standards tell you what a mature BC program should contain. Exercises tell you whether that program can actually deliver.
Good documentation and high alignment indicate the foundation is in place. But to be sure you can recover, you need to push things a little bit farther. You need to put your program to the test. You need to find out, by conducting realistic, demanding exercises, whether it can really perform the way you think it can.
Another tricky thing about great documentation is that it can give you a false sense of security.
We recently assessed an organization whose BC program had every document known to man. On paper, they looked unbeatable. Their compliance score was way up there. Then we took their program for a test drive. Could they do what they said they could? Not even close. They had a beautiful foundation, but they had never stress tested their program to the point that would prove if it would work or not.
Having a recovery plan, no matter how gorgeous, is not the same thing as being able to recover. And recovery is what it’s all about.
Why Companies Resist Stress Testing
We’ll take a closer look at the kind of testing that’s required in a minute. First I want to explore some attitudes we commonly see around the subject of testing, attitudes that make it very hard for some organizations to do it.
Even though BC stress testing is essential for validating recoverability, many organizations are allergic to it. They don’t want to go there.
A lot of times managers will tell us they don’t want to disrupt production.
However, I’ve been at this long enough, and seen enough companies navigate this issue just fine, to conclude this is generally more of an excuse than a reason.
I think most companies are worried about what they’ll find if they conduct a legitimate mock-disaster exercise.
Most management teams would rather live in the hope that they can recover than be confronted by the stark reality that they can’t. BC offices often feel the same way. And IT/DR teams usually strongly feel this way.
It’s natural enough that people worry about looking bad or being faced with new demands on their resources. But a head-in-the-sand attitude does no favors for the organization’s resilience.
Moving From Assumed Readiness to Proven Capability
That covers the problem. What about the solution?
The solution, in a word, is for companies to toughen up. They need to steel themselves to face the truth about their level of readiness. And they need to truly put their programs to the test.
This means, among other things, conducting exercises with their programs as found, rather than carefully preparing everything to ensure they pass.
It might also mean doing failovers in real time, having groups operate in alternate environments, if that’s what their recovery plans call for, and recovering apps in an integrated fashion rather than separately.
This is the only way to validate whether their plans work and identify the gaps and risks that remain, which is a prerequisite to eliminating them.
Alternatively, the organization can accept them if it’s determined that the cost of mitigating them is too high. BC does not ask companies to close every last gap. It asks them to be realistic and make conscious decisions and mindful trade-offs.
As organizations mature, they need to move beyond asking, “Have we built the right things?” and begin asking, “Can we execute when it matters?”
A company can have excellent recovery plans and still discover gaps when those plans are put under pressure. Far from being a sign of organizational failure, this is an essential step on the road to improving the program.
Really, there are two things to do: accept reality and figure out how much residual risk you have. For example, if you had planned to be down two days and it took you five to recover, you have a mystery to solve: why did it take so long?
Here’s one thing not to do: get hung up on how beautiful your plans are.
There’s a difference between planning and execution.
What really counts is your ability to execute; that is, your ability to implement a strategy, say what you’re going to do, and do it.
Everything else is window dressing.
From Documentation to Demonstration
Business continuity documentation remains an essential part of every mature BC program. But documentation alone cannot prove that an organization is capable of recovering from a real disruption.
The only way to gain that confidence is to put recovery strategies, technology, and people to the test. Organizations willing to confront reality through demanding exercises are the ones best positioned to identify their remaining risks and continually strengthen their resilience.
MHA Consulting helps organizations assess their true recovery capabilities through independent assessments, realistic exercises, and practical improvement programs. Contact MHA to learn how we can help your organization move beyond compliance and build confidence based on proven performance.
Further Reading
- Fooling Themselves: Why Most Companies Overestimate Their IT/DR Capabilities
- Crisis Event Documentation: The Documents You Need to Weather the Storm
- The Benefits of Stressing Out: Why You Should Stress Test Your Recovery Plans
- When Everything Clicks: Lessons from an Outstanding Mock-Disaster Exercise
- How to Create and Maintain Business Continuity Documentation
Frequently Asked Questions
Does having great documentation and being aligned with standards guarantee that my organization can recover from a disruption?
No. Comprehensive documentation and strong alignment with recognized business continuity standards are important indicators of a mature program, but they do not prove that the organization can actually recover from a real disruption. Documentation shows that the foundation is in place. Only realistic exercises and other forms of validation demonstrate whether recovery strategies, plans, and teams can perform as expected.
Why should organizations bother with standards if being aligned with them doesn’t guarantee recoverability?
Business continuity standards remain essential because they define the elements a mature BC program should contain, including governance, policies, business impact analyses, recovery strategies, and plans. However, the standards themselves recognize that documentation must be complemented by testing and continual improvement. Standards establish the framework; exercises demonstrate whether that framework works in practice.
Why do so many organizations avoid realistic business continuity testing?
Many organizations worry that demanding exercises will disrupt operations or expose weaknesses in their preparedness. In reality, these concerns often stem from a reluctance to confront uncomfortable truths about the program's actual capabilities. While discovering gaps can be difficult, identifying them during an exercise is far preferable to discovering them during a real crisis.
How can organizations move from assumed readiness to proven recovery capability?
Organizations need to validate their recovery strategies through realistic exercises rather than relying solely on documentation. This can include testing recovery procedures under realistic conditions, performing failovers, exercising alternate work arrangements, and validating end-to-end business processes instead of isolated components. The goal is to understand what works, identify remaining risks, and make informed decisions about how those risks should be addressed.
What is the difference between having a business continuity plan and having the ability to recover?
There is a fundamental difference between planning and execution. Well-written recovery plans are valuable, but they are not the same as the ability to recover. True resilience comes from demonstrating that people, processes, and technology can perform successfully under realistic conditions, not simply from having impressive documentation.
Michael Herrera
Michael Herrera is the Chief Executive Officer (CEO) of MHA. In his role, Michael provides global leadership to the entire set of industry practices and horizontal capabilities within MHA. Under his leadership, MHA has become a leading provider of Business Continuity and Disaster Recovery services to organizations on a global level. He is also the founder of BCMMETRICS, a leading cloud based tool designed to assess business continuity compliance and residual risk. Michael is a well-known and sought after speaker on Business Continuity issues at local and national contingency planner chapter meetings and conferences. Prior to founding MHA, he was a Regional VP for Bank of America, where he was responsible for Business Continuity across the southwest region.