Relevant Contents
Need Tailored Business Continuity Insights?
Contact Us Now for Personalized Guidance!
Many business leaders are under the impression that they can protect their organizations by investing in either risk management or business continuity.
True resilience can only be achieved through the thoughtful implementation of both disciplines. This article is focused on operational risk, such as loss of technology, business function outages, and emergency response, rather than strategic business risk, such as changes in market conditions or insurance risk.
Related: Risk Assessment: The Best Way to Identify Your Biggest Threats
Summary
- Risk management and business continuity are related, but they are not interchangeable.
- Risk management focuses on reducing the likelihood or impact of disruption. Business continuity prepares the organization to operate when prevention fails.
- Resilient organizations use both disciplines in a proportionate, informed way rather than trying to protect everything equally.
A Common Misunderstanding About Resilience
A common misconception among business leaders is that if their organization is diligent in practicing risk management, it does not need to bother with business continuity (BC).
An almost equally common misconception is that if their company excels at BC, it can get by without worrying about risk management.
These misunderstandings reflect a larger confusion about exactly what risk management and business continuity are and what role each plays in protecting organizations from threats and disruptions.
What Risk Management Does
Risk management and business continuity are supportive and related, but they are two very different disciplines.
Risk management is about reducing the likelihood that disruptive events will occur or reducing their potential impact if they do occur. Organizations accomplish this by identifying significant risks, assessing their likelihood and consequences, and implementing measures to address them.
The first step in managing risk is conducting a threat and risk assessment (TRA) to identify potential sources of disruption and assess them based on likelihood and potential impact. Such assessments typically involve input from a range of sources, such as facility personnel, business leaders, security and safety teams, government agencies, and historical incident data.
Here are some potential risks that might be identified through a TRA:
- That a fire or flood could damage a facility
- That a prolonged utility outage could interrupt operations
- That a critical supplier could become unavailable
- That an explosion at a nearby industrial facility could affect company operations
- That a cybersecurity incident could disrupt business processes
- Technology gaps or potential failure points
- That the loss of key personnel could affect operations
- Countless other internal or external conditions that could prevent the organization from achieving its objectives
What happens once an organization identifies the threats it faces? It must evaluate them based on two key factors: likelihood and potential impact. These are typically assessed through a combination of expert judgment, business knowledge, and analysis of potential effects on people, facilities, operations, customers, and other critical areas.
After identifying its risks and assessing how likely each is to occur and what the damage might be if it did, the organization should take steps to address them.
Organizations typically respond to risks through four primary strategies:
Risk Avoidance
Risk avoidance means eliminating the activity that creates the risk.
Risk Limitation
Risk limitation means reducing the risk by implementing controls that lower its likelihood or impact.
Risk Transfer
Risk transfer means shifting some or all of the financial or operational consequences to another party, such as through insurance or outsourcing.
Risk Acceptance
Risk acceptance means accepting the risk, usually because the likelihood and potential impact are low enough that additional protective measures are not justified.
Most organizations employ a combination of all four approaches. For example, a company might perform risk avoidance by choosing not to open a facility in a floodplain, risk limitation by installing a fire suppression system in a warehouse, risk transfer by outsourcing payroll administration to a third-party provider under terms that assign certain liabilities to the provider, and risk acceptance by deciding not to install backup power for a small storage building because the consequences of an outage would be minimal.
That is risk management in a nutshell. It is about preventing bad things from happening, with a special focus on preventing the things that, if they did occur, would cause the most damage to the organization.
What Business Continuity Does
Business continuity is a different discipline. If risk management is about prevention, BC is about what we do when prevention fails. Because sometimes, despite our best efforts, things will go wrong.
Risk management asks, “How can we reduce the chance that something bad will happen?” BC asks, “If something bad does happen, how will we continue operating?”
It is good to brush and floss. But if you develop a cavity or chip a tooth, you still want to be able to go to the dentist and get it fixed.
Business continuity focuses on preparing the organization to respond to and recover from disruptions regardless of their cause.
Where risk management starts with the threat and risk assessment, BC begins with the Business Impact Analysis (BIA), the study that identifies the organization’s critical business processes and determines how quickly they must be restored following a disruption to avoid unacceptable business impacts.
Using the results of the BIA, organizations develop recovery strategies and continuity plans designed to keep critical activities operating, or restore them within their required recovery timeframes.
BC strategies might include:
- Setting up alternate worksites where operations can continue if a facility is unusable
- Devising manual workarounds for carrying out critical tasks without the usual technologies
- Cross-training personnel so they can fill essential roles during staffing shortages
- Creating technology recovery solutions that restore systems after an outage
- Lining up alternate suppliers that can step in if a critical vendor is unavailable
- Developing crisis management procedures for directing the organization’s response
- Many other measures that enable the business to continue operating despite disruption
It is commonly thought that a business continuity program consists primarily of a collection of documents. In fact, documentation is only one output of the BC lifecycle. Business continuity is an ongoing process of planning, training, exercising, maintaining, reviewing, and improving the organization’s recovery capabilities so they remain effective as the business and its risks evolve.
The goal of BC is to ensure that critical business processes can continue, or be restored within acceptable timeframes, even when preventive measures fail or an unexpected event occurs.
Where risk management seeks to prevent or lessen disruptions, business continuity prepares the organization to operate through them and recover when they occur.
Why You Need Both
It should now be clear that organizations need both risk management and business continuity. They provide different kinds of protection and together amount to a defense in depth against organizational threats, risks, and disruptions.
A possible additional misconception about these two disciplines is that applying both will require a bottomless budget.
In fact, a central tenet of both risk management and BC is that of proportionality. The risks that are the likeliest to occur and have the potential to cause the most damage require the most vigorous treatment. Similarly, the business processes that are the most critically time sensitive are the ones that need to be recoverable in the shortest amount of time. Other risks and processes do not require the same heightened degree of response.
Another key principle shared by both risk management and BC is the importance of making conscious, informed choices. Neither discipline calls for protecting everything to the highest possible standard. Instead, both emphasize understanding the risks, weighing the potential consequences, investing in prevention and preparedness where they will have the greatest impact, and consciously accepting the risks and recovery gaps that remain rather than pretending they don’t exist.
A simple example might drive the point home.
Think about two common machines: the dishwasher and the car.
It is not very likely your dishwasher will break tomorrow, and if it did, the consequences would be pretty mild. You might have to wash the dishes by hand for a few days. So keep a sponge and some dish liquid on hand. Beyond that, it does not make sense to worry about it too much.
A car is very different. Here again, the likelihood of your having car trouble is probably low. But if you did get a flat or break down, the consequences could be significant. You could be stranded, miss an important appointment, or find yourself in an unsafe situation. Here it would make sense to try to prevent problems and be equipped to deal with them if they occur, such as by making sure you have a viable spare and know how to put it on or making sure auto club membership is up to date.
Organizations should approach resilience the same way. They should not try to eliminate every possible risk or build elaborate continuity capabilities for every conceivable disruption. They should assess the likelihood and potential impact of the threats they face, invest where the consequences justify it, and consciously accept the remaining risks.
A Complete Approach to Resilience
Risk management and business continuity are complementary disciplines, not competing alternatives. Risk management seeks to prevent or reduce disruptions. BC prepares the organization to continue operating when prevention is unsuccessful.
Organizations do not become resilient by relying exclusively on either discipline. They become resilient by thoughtfully combining prevention with preparedness and by making informed, proportionate decisions about where to invest, where to plan, and which remaining risks they are prepared to accept.
If your organization wants to strengthen its resilience by integrating risk management and business continuity into a coordinated strategy, MHA Consulting can help. Contact us to learn how our consultants can help you identify your most significant risks, develop practical continuity capabilities, and build a program that is both effective and proportionate.
Further Reading
- Weighing the Danger: The Continuing Value of the Threat and Risk Assessment
- Risk Assessment: The Best Way to Identify Your Biggest Threats
- Mitigating Insider Threats: 7 Steps to Keeping Your Company Safe
- Don’t Just Hope: Choosing Strategies to Mitigate Risk
Frequently Asked Questions
What is the difference between risk management and business continuity?
Risk management focuses on reducing the likelihood that disruptive events will occur or reducing their potential impact if they do occur. It involves identifying significant risks, assessing their likelihood and consequences, and implementing measures to address them.
Business continuity focuses on preparing the organization to continue operating and recover when disruptions occur. While risk management aims to prevent or lessen disruptions, business continuity ensures the organization has plans, strategies, and capabilities in place when prevention is unsuccessful.
What are the main ways organizations address risk?
Organizations typically address risks through four primary approaches: avoidance, limitation, transfer, and acceptance.
Risk avoidance eliminates an activity that creates a risk. Risk limitation reduces the likelihood or impact of a risk through safeguards. Risk transfer shifts some or all consequences of a risk to another party, such as through insurance arrangements. Risk acceptance involves consciously deciding that the potential consequences of a risk do not justify additional protective measures.
Most organizations use a combination of these approaches based on the likelihood and potential impact of the risks they face.
If an organization has strong risk management measures, does it still need business continuity?
Yes. Effective risk management can reduce the likelihood and severity of disruptions, but it cannot eliminate all uncertainty. Even if an organization has measures in place to prevent a disruption, there is still a possibility that something unexpected will occur or that those measures will not be sufficient. Business continuity prepares the organization to respond and recover when those situations arise.
What does a business continuity program include?
Business continuity begins with a business impact analysis (BIA), an assessment that identifies the most critical business processes. Organizations then develop recovery strategies and continuity plans, establish procedures for responding to disruptions, train personnel, conduct exercises, maintain documentation, and regularly review and improve their capabilities. The goal is to ensure critical activities can continue or be restored within acceptable timeframes.
Do organizations need to invest equally in every risk and every recovery capability?
No. Effective resilience is based on proportionality, not trying to protect everything to the highest possible standard. Organizations should evaluate risks based on their likelihood and potential impact and focus resources where they will provide the greatest benefit. Similarly, recovery capabilities should be designed around the importance and time sensitivity of business processes.
Richard Long
Richard Long is one of MHA’s practice team leaders for Technology and Disaster Recovery related engagements. He has been responsible for the successful execution of MHA business continuity and disaster recovery engagements in industries such as Energy & Utilities, Government Services, Healthcare, Insurance, Risk Management, Travel & Entertainment, Consumer Products, and Education. Prior to joining MHA, Richard held Senior IT Director positions at PetSmart (NASDAQ: PETM) and Avnet, Inc. (NYSE: AVT) and has been a senior leader across all disciplines of IT. He has successfully led international and domestic disaster recovery, technology assessment, crisis management and risk mitigation engagements.