How long would it take your organization to get back to work if the systems failed to start tomorrow? Most governance teams have that answer written down in a business continuity plan, approved by the committee and reviewed in the last audit. What few of them have is any certainty that the people who are supposed to execute that document will know, at the moment of the incident, which part is theirs.
The scenario stopped being hypothetical a while ago. Verizon’s 2026 Data Breach Investigations Report finds that 48% of breaches now involve ransomware, and the ENISA threat landscape places threats against availability at the top of the ranking, ahead of ransomware and threats against data. When what gets interrupted is the operation itself, the business continuity plan stops being an audit requirement and becomes a procedure someone has to apply with no time left to read it.
In my experience reviewing continuity frameworks, the document is almost never the problem. The problem shows up one layer down, in the question of who knows what, and since when.
What does ISO 22301 require about people, and why does it get implemented last?
ISO 22301 is the international standard that specifies the requirements for a business continuity management system. Like the other management system standards, it groups its support requirements under clause 7, and two of them point directly at people. They are competence (7.2) and awareness (7.3).
Competence requires determining which capabilities each person with an assigned continuity role needs, and making sure they have them. Awareness has a wider reach and extends to the whole organization, not just the crisis committee. It asks that every person know the continuity policy, understand their contribution to the system, and know what departing from the procedures implies.
Those two clauses tend to be left for last. Documenting the business impact analysis, the recovery strategies and the target times produces deliverables an auditor can review in a folder. Competence and awareness produce something less convenient to show, because they live in people’s heads on the day they are needed.
It is the same displacement that happens with control 6.3 of ISO/IEC 27001, where staff training gets documented late and with less precision than the technical controls surrounding it.
The distance between having a plan and being able to activate it
An approved continuity plan proves the organization analyzed its critical processes and decided how to recover them. It does not prove it can actually do so.
Between one thing and the other there is a gap, and it almost always shows up in the same three ways:
- The plan describes roles by job title, and whoever holds that title changed eight months ago without anyone updating the annex.
- The procedure assumes a communication channel that depends on the system currently down.
- Activation requires a decision nobody has delegated in writing for three in the morning on a Sunday.
None of the three is detectable by reading the document. They are detectable when someone tries to use it.
Who needs to know what, and when?
Continuity awareness does not mean all 800 people in an organization know the full plan. It means each group knows the part that falls to them. The segmentation that works has three layers.
The crisis committee needs the activation criteria, the order of precedence among critical processes, and its authority to decide without escalating.
The teams with an assigned technical role need the recovery procedure for their own scope and the target times the organization committed to for it.
Everyone else needs to know three things, and only three: how they will find out there is an incident, which alternate channel the organization will use while it lasts, and what they are authorized to do with information and devices in the meantime.
That third layer is the one skipped most often, and it is by far the largest. Someone in administration who does not know which alternate channel the organization uses will improvise one. That improvised channel tends to be the one that opens the next problem.
Why isn’t rehearsing the plan the same as preparing people?
ISO 22301 asks for continuity procedures to be exercised and tested, and the crisis exercise is hard to replace. It puts the committee in the position of deciding with partial information and exposes the assumptions the document treated as settled.
What an annual exercise cannot do is sustain behavior for the rest of the year. A drill convenes a limited group for a few hours, with advance notice, in a setting where everyone knows they are being observed. The behavior that matters on the day of the real incident belongs to someone who was never convened to any exercise and who has to recognize, unaided, that what they are seeing on their screen is not an ordinary IT failure.
That is where continuity rests on the same ground as awareness. Observing how the organization responds to a simulated ransomware attack produces a signal the committee exercise does not, because that observation reaches the entire population on a normal working day rather than the ten names in the crisis room. That signal reads as behavior sustained over time.
How much of the trigger depends on a person?
It pays to be precise here, because this figure often gets stretched. The 2026 DBIR does not claim all ransomware arrives through a click. It reports that 31% of breaches start in software vulnerabilities, a path that now exceeds stolen credentials. What the report does maintain is that the most frequent causes continue to heavily involve the human element, with social engineering, phishing and stolen credentials among them.
For a governance framework what matters is that the trigger of a continuity event has a stable, measurable human component, and that this component is managed with instruments different from the ones that handle patching and backups. Treating human risk as a variable you watch before the click is what allows you to anticipate it instead of reconstructing it afterwards.
What should you record to make continuity auditable?
A competence and awareness requirement is demonstrated with records, like any other. The difference is that here the record has to answer per person and per date, not per event.
Four questions organize what is worth having on hand:
- Who holds an assigned role in the continuity plan today, according to the current directory rather than the latest version of the annex?
- What training did each of those people receive, when did they receive it, and when does it expire?
- What does the rest of the organization know about the alternate communication procedure, and since when?
- Where is the evidence that the continuity policy was communicated and accepted?
Those questions look a lot like the ones that come up when you have to notify a breach with a clock running, for a simple reason. In both cases the organization has to prove, with little margin, something it decided long before.
SMARTFENSE’s management of regulations, policies and procedures covers that layer for the continuity policy, and the program audit records make it possible to reconstruct who read what, when they accepted it and with what validity period, without depending on a spreadsheet somebody maintains by hand.
What turns a business continuity plan into a capability
A business continuity plan that exists only as an approved document transfers all the risk to the day of the incident. The organization ends up depending on the right people improvising well, and in time.
When the incident also carries criminal implications, that improvisation gets expensive fast, because the decisions of the first few hours are documented and reviewed later. That is where continuity becomes part of risk governance and stops being an annex belonging to the technical team.
The alternative lies in treating competence and awareness as two requirements with an owner, a record and an expiry date, the same way the business impact analysis and the recovery time objectives already are. Once that is settled, the plan stops being reviewed once a year and starts being a capability the organization actually has.
Frequently asked questions
What does ISO 22301 require regarding staff awareness?
ISO 22301 includes awareness as a support requirement under clause 7.3. It asks that people in the organization know the business continuity policy, understand their contribution to the management system, and know what departing from the established procedures implies.
What is the difference between competence and awareness in business continuity?
Competence (7.2) applies to those with an assigned continuity role and requires ensuring they have the capabilities to perform it. Awareness (7.3) applies to the whole organization and operates at a more basic level, that of knowing the plan exists, what is expected of each person, and how the organization will communicate during a disruption.
Is an annual crisis exercise enough to satisfy the requirement about people?
The exercise covers the obligation to test procedures, but it involves a limited group for a few hours and with advance notice. It does not sustain the behavior of the rest of the organization over the year, which is what the response rests on the day of an unannounced incident.
Who inside the organization needs to know the continuity plan?
It is worth segmenting into three layers. The crisis committee needs the activation criteria and its decision authority; the teams with a technical role need the recovery procedure for their scope and the target times; everyone else needs to know how they will find out about the incident, which alternate channel will be used, and what they are authorized to do while it lasts.
What evidence does an auditor ask for about people’s preparedness in continuity?
Records per person and per date, not per event. Who holds an assigned role according to the current directory, what training each one received with completion and expiry dates, what was communicated to the rest of the organization and since when, and where the acceptance of the continuity policy is recorded.
Leave a Reply