What Are the Benefits of a Business Continuity Management System?

5 people in a meeting room discussing a business continuity plan

By Miles Watt, Senior Advisor, Security and Resilience, Sicuro Group

Most organisations assume they would cope with a serious disruption until the day one actually arrives. A ransomware attack locks every file. A key supplier fails without warning. A flood makes the main office unusable for a fortnight. In those moments, the difference between a quick recovery and a damaging one usually comes down to whether continuity has been planned, resourced, managed and tested in advance, or simply hoped for.

The value of getting this right is substantial. A business continuity management system, or BCMS, reduces disruption to the operations that matter most, allocates resources, speeds up recovery, gives people clear roles when an incident hits, and reassures the customers, suppliers and regulators who increasingly want proof that an organisation can keep running under pressure. To understand those benefits properly, it helps to be clear on what a BCMS actually is and how it works, so this guide covers both: what a BCMS is, what it includes, how it relates to the international standard ISO 22301, and the practical value it delivers.

Understanding the Business Continuity Management System

What Is a Business Continuity Management System?

A business continuity management system, commonly shortened to BCMS, is the overall framework an organisation uses to prepare for, respond to and recover from disruptive incidents. 

In plain terms, a BCMS is the way business continuity (BC) risks are identified and continuity is organised, owned and kept up to date across a business. It brings together the policies, people, plans, resources, data, connectivity and interdependencies. The aim is to minimize the impact of a disruption to critical operations and services , or to resume within acceptable timeframes afterwards.

The purpose of a BCMS is straightforward. It is to identify and protect the activities that matter most, reduce the impact of disruptions when they occur, and give an organisation the confidence that it can keep serving its customers under pressure. It does this not through a single emergency document, but through an ongoing management process that identifies what could go wrong, decides what must keep running, and makes sure the right responses are ready and rehearsed.

This is the part that often gets missed. A BCMS is more than a plan sitting in a shared drive. A plan describes what to do in a given scenario. A management system surrounds that plan with governance, ownership, testing and continual improvement, so it stays relevant as the business and its risks change. A plan is a snapshot. A BCMS is the engine that keeps the whole approach alive.

A simple example helps. Imagine a logistics company whose operations depend on a single warehouse management platform. A continuity plan might set out what staff should do if that platform goes down. A BCMS goes further: it identifies the platform as a critical dependency in the first place, assesses how long the business could function without it, defines and resources a response plan, assigns someone to own the response, tests the arrangements once a year, and updates everything when the company switches systems. The plan is one output. The BCMS is the discipline that produced it and keeps it useful.

Why a BCMS Matters to Modern Organisations

Organisations today are exposed to a wider range of disruptions than ever before. Cyber incidents, supply chain failures, extreme weather, power and telecom outages. The loss of key sites, people, partners or key resources can all interrupt operations. As businesses become more connected and more dependent on technology and third parties, a single point of failure can ripple across an entire operation.

For most organisations, certain services simply cannot stop for long. A payment processor cannot go offline for days. A hospital cannot operate effectively if it loses access to patient records. A manufacturer cannot leave customers without deliveries indefinitely. Protecting these critical services is the central reason for a structured approach to continuity matters.

The thinking around this has shifted in recent years. Continuity used to be treated as reactive: write a plan, file it away, and pull it out in an emergency. In reality, this is a sure route to failure in the event of a disruption. The more effective approach is ongoing resilience, where continuity is built into how the business is run and improved over time. Similar to HSE, business continuity should be the responsibility of all people in an organization. It should be prepared for, resourced, understood and practiced. Importantly, everyone should know the part they are to play. A BCMS reflects that shift. It treats continuity as something to be managed, reviewed and strengthened, rather than a box ticked once and forgotten. Risks evolve, suppliers change, technology is replaced and teams move on. A managed system keeps pace with all of it.

BCMS vs Business Continuity Plan: What’s the Difference?

Business Continuity, Business Continuity Plan and BCMS Explained

Three terms are often used interchangeably, which causes a lot of confusion. They are related, but they are not the same thing.

  • Business continuity (BC) is the overall capability. It is the organisation’s ability to keep delivering its products and services at an acceptable level during and after a disruption. It is the outcome you are aiming for.
  • A business continuity plan (BCP), is the documented set of actions and procedures used to respond to a specific type of disruption. It answers practical questions: who does what, in what order, using which resources, and how teams communicate. A plan is a tool.
  • A business continuity management system, or BCMS, is the wider framework that creates, maintains and improves those plans. It includes governance, risk assessment, business impact analysis, ownership, resourcing, training, testing and review. The BCMS is the management system that makes business continuity reliable and repeatable rather than ad hoc.
The table below sets out the distinction.
Business Continuity Business Continuity Plan (BCP) Business Continuity Management System (BCMS)
What it is The overall capability to keep operating through disruption A documented set of multidisciplinary response and recovery actions The complete framework that manages continuity
Scope A goal or outcome A specific tool or document An ongoing management process
Focus Staying operational What to do during an incident How continuity is owned, tested and improved
Lifespan A continuous objective Can quickly become outdated if not maintained Built around regular review and improvement
Example “We can keep serving customers during an outage” “If the data centre fails, follow these steps” “We assess risks, plan, test, review and refine continuously”

Businesses frequently confuse a plan with a management system because the plan is the visible, tangible part. It is the document people can hold up and point to. The management system is less obvious because much of it is process and governance. Yet a plan with no system behind it tends to drift out of date, which is exactly when it lets an organisation down.

A short example shows the difference clearly. Two companies each write a continuity plan for a cyber incident. The first files it away and never revisits it. Eighteen months later, the plan still names a contact who has left, references a backup system that has been decommissioned, and assumes office-based working that no longer reflects how the team operates. When an attack hits, the plan is close to useless. The second company embeds its plan in a BCMS. The same eighteen months sees the plan tested twice, contacts updated with vendors and external stakeholders contracted to support BC, a robust change management system that sees the backup approach revised after a system change, and lessons from a tabletop exercise folded back in. When an attack hits, the response is current and the team knows their roles. Same starting document, very different outcomes.

Why the Difference Matters in Practice

A plan on its own carries a hidden risk: it ages. Contacts change, systems are replaced, suppliers are swapped, and the organisation restructures. A document that is not maintained quietly becomes inaccurate, and an inaccurate plan can be worse than no plan at all because it creates false confidence.

A BCMS addresses this directly. It builds in maintenance, testing and clear ownership, so plans are kept current and someone is accountable for them. It supports continual improvement, meaning every exercise, incident and business change feeds back into stronger arrangements. Above all, it gives an organisation a structured, repeatable approach rather than a one-off effort that depends on whoever happened to write the original document. That repeatability is what turns continuity from a hopeful intention into a dependable capability.

A BCMS also coordinates BC across departments and internal and external stakeholders. A plan to recover internally after a cyber attack may be useless if it doesn’t detail how to coordinate recovery of data, systems and software from external providers. A disruption in supply chain may have a serious impact if vendors, transporters and warehouse operators are not coordinated with. Without robust plans to coordinate with banks payroll could be severely hampered.

What Does a Business Continuity Management System Include?

Core Components of a Business Continuity Management System

A BCMS is made up of several connected elements. The exact shape varies by organisation, but the main parts are consistent.

  • Policy and scope. A clear statement of what the BCMS is for, what it covers, and the commitment behind it. Scope defines which products, services, sites and activities are included.
  • Roles and responsibilities. Defined ownership at every level, from senior leadership accountability through to the people who carry out specific tasks during an incident.
  • Risk assessment. A structured look at the threats that could disrupt operations, how likely they are, and what they could affect.
  • Business impact analysis (BIA).Arguably more important than the risk assessment, this identifies the organisation’s critical products and services and establishes the impact a disruption could have over time. Rather than trying to identify the types of disruption, the BIA focuses on the impact regardless of why. The BIA helps to determine how long it takes for a disruption to become intolerable (maximum tolerable period of disruption – MTPD), how quickly the organization wants to recover (recovery time objective – RTO) and the level to which the organization wants to recover to as a minimum (minimum business continuity objective – MBCO. For payroll, that might mean recovering within three days (RTO), to the point where every employee receives the same pay as the previous month (MBCO), with expenses and adjustments corrected later. With the MBCO you may not be aiming for perfect, you may be aiming for enough to keep going.

The reason why the BIA is arguably more important than the risk assessment is that the risk assessment requires that specific risks are identified. Doing so is incredibly difficult when the number of risks are virtually limitless. Add to their limitless nature that number of unprecedented (in recent history) events that have manifested in recent years and it becomes even more difficult. How many people planned seriously for the disruption of a pandemic prior to 2019, disruptions to the Suez Canal before 2021, the impact of the Ukraine war and resultant sanctions on Russian energy prior to 2020 or the massive disruption to the GCC and the Straits of Hormouz prior to 2026. A detailed BIA does not need to predict the cause of a disruption, only the impact should a disruption occur. A risk assessment can then be used to predict the likelihood, the impact from the BIA and likelihood combined then gives a risk score. 

  • Incident response procedures. The practical steps for recognising, escalating and managing a disruption as it unfolds.
  • Communication plans. How the organisation keeps staff, customers, suppliers, regulators and other stakeholders informed during an incident.
  • Continuity and recovery plans. The documented arrangements for keeping critical activities running and restoring normal operations.
  • Resource details. Where resources are stored or acquired, how quickly and who to contact to order or access them.
  • Training and exercising. Ensuring people understand their roles, and testing the arrangements through drills, tabletop exercises and simulations.
  • Monitoring, review and continual improvement. Regular checks on whether the system is working, with findings used to refine and strengthen it over time.

How These Elements Work Together

The components above are not a checklist of separate documents. They form a joined-up framework where each part informs the others. Risk assessment and business impact analysis tell you what to protect and how quickly it must recover. That understanding shapes the continuity and recovery plans. Those plans only work if roles are clear, people are trained, and resources are allocated;  These elements only stay reliable if they are tested and reviewed. Governance and ownership hold the whole thing together, while monitoring and improvement keep it relevant as the organisation changes.

One principle ties all of this together, and in our experience at Sicuro it is the single most useful idea in business continuity: plan for the loss of a capability, not for a specific scenario. A capability-based approach sidesteps this. Instead of asking “what if this particular thing happens?”, you ask “what if, for any reason, we cannot do the things this business depends on?” When a plan is built that way, the cause of the disruption stops mattering. You simply go to the plan for the affected capability and work through how to keep it running or restore it, whether the trigger was a flood, an outage, a strike or something no one saw coming.

A worked example shows how the pieces connect. Consider a professional services firm that suffers a cyber incident: ransomware encrypts its core case management system on a Monday morning, locking access to live client files.

The business impact analysis done months earlier has already flagged that system as critical, with a recovery time objective of one working day. It also identified that storing documents locally was a risk and led to the company using cloud based storage and robust backups for all case management data. These elements inform the BCP and drive and enable the response. Risk assessment had identified ransomware as a credible threat, so the firm had already arranged offline backups and a tested restore process. Incident response procedures kick in: the IT lead isolates affected systems and mobilizes pre-identified external cyber specialists to do penetration testing and patching. If hardware is impacted, back up hardware is configured and issued from storage. The incident manager is alerted, and the situation is escalated to senior leadership, all according to roles defined in advance. The communication plan governs what staff are told, how clients are kept informed without causing alarm, and when regulators must be notified. Continuity plans allow users to switch to read-only backup copies and manual workarounds so client work continues at the minimum acceptable level. Recovery plans guide the controlled restoration of the system from clean backups. Once normal service resumes, the review stage captures what worked and what did not, and those lessons feed back into stronger arrangements.

No single document saved the firm. The capability emerged from how the elements are prepared and worked together: the people who do the work, the processes they follow, the hardware and data they need, and the internal and external interdependencies that connect them to other departments, suppliers, clients and regulators. The same logic applies to other disruptions: a supplier failure that delays deliveries, a flood or fire that makes a site unavailable, or a telecoms outage that knocks out a customer service centre. In each case, the value lies in having understood the dependency, planned a response, assigned ownership and tested the arrangements before the disruption ever happened.

The Benefits of a Business Continuity Management System

Operational and Strategic Benefits of a BCMS

The most immediate benefit of a BCMS is less disruption to the operations that matter most. When critical activities are identified and protected in advance, an incident causes far less damage. Recovery is faster too, because the response is planned and rehearsed rather than improvised under pressure.

A BCMS also brings clarity during incidents. When ownership is defined and agreed ahead of time, people know who is leading, who is doing what, and who has the authority to make decisions. That clarity improves decision-making at exactly the moment when confusion is most costly. It comes from preparation: leaders working from agreed priorities and accurate information rather than guesswork.

There is a wider organisational benefit as well. Building a BCMS forces a business to map its dependencies across people, systems, sites and suppliers. That visibility is valuable in its own right, often revealing single points of failure and concentration risks that were not obvious before. Because a well-built system plans for the loss of capabilities rather than for a fixed list of scenarios, it also offers protection against the disruptions no one anticipated, which are precisely the ones that tend to do the most harm. A well built system also builds resilience against the most common but often overlooked disruption, key staff leaving. A BCMS can act as a form of job notes or instructions. Over time, a well-run BCMS helps build a culture where resilience is part of how the organisation thinks, rather than an afterthought.

Commercial Value and Organisational Confidence

The benefits extend well beyond incident response. A mature approach to continuity supports customer confidence, because clients increasingly want assurance that their providers can keep delivering when conditions are difficult. It helps protect reputation, since a calm, capable response to a disruption tends to reinforce trust rather than erode it.

A BCMS also strengthens assurance across the supply chain and among stakeholders. Suppliers, partners and investors all take comfort from evidence that an organisation has thought seriously about resilience. It supports governance and compliance obligations, and it is frequently an advantage, sometimes a requirement, when bidding for contracts. Many tenders now ask explicitly about business continuity arrangements, and a structured BCMS makes those questions far easier to answer convincingly. In short, it demonstrates a mature approach to resilience, which is increasingly something organisations are expected to show, not just claim.

ISO 22301 Business Continuity Management System: How They Relate

What Is ISO 22301?

ISO 22301 is the international standard for business continuity management systems. Its full title is “Security and resilience: Business continuity management systems: Requirements”, and the current version is ISO 22301:2019, which replaced the original 2012 edition.

The standard sets out a recognised framework for establishing, implementing, maintaining and continually improving a BCMS. It describes what a competent management system should contain, organised around ten clauses that cover the context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. It follows the familiar Plan, Do, Check, Act cycle and shares a common high-level structure with other ISO management standards such as ISO 27001 for information security, which makes the two straightforward to integrate.

Businesses researching what a BCMS is, very often come across ISO 22301, and the reason is simple: the standard is the most widely accepted definition of what good looks like in business continuity. It gives the concept a recognised, internationally agreed shape. Alongside the standard, many practitioners also work to the Business Continuity Institute’s Good Practice Guidelines, which set out the professional practices that underpin a sound continuity programme. At Sicuro, our methodology is built to align with both, so that the framework an organisation ends up integrating, with the help of Sicuro, is consistent with the international standard and grounded in established professional practice.

Why Businesses Align Their BCMS with ISO 22301

Aligning a BCMS with ISO 22301 brings several practical advantages. It provides a more structured and credible framework, built on internationally agreed good practice rather than internal assumptions. It supports consistent governance, giving leadership a clear basis for oversight and a common language across teams and sites. It also helps formalise continuity arrangements, turning informal habits into documented, repeatable processes.

For some organisations, the path leads to formal certification, where an accredited body assesses the BCMS against the standard. Certification can be valuable, particularly where clients or regulators expect it, and it is typically valid for three years subject to annual surveillance audits. That said, certification is not the only reason to align with ISO 22301. Many organisations use the standard purely as a benchmark, adopting its structure and discipline to build a stronger BCMS without pursuing certification at all. The framework is useful whether or not the certificate is the goal.

Business Continuity Management Systems Requirements and Implementation Basics

What Are the Basic Requirements of a BCMS?

At a high level, the requirements of a BCMS are consistent regardless of which framework an organisation follows. They centre on a logical sequence.

The starting point is understanding the organisation’s critical products, services and activities: what the business genuinely cannot do without. From there, the requirements involve assessing the potential business impact, and risks of a disruption. Next is to  define recovery priorities and times so that effort goes where it matters most. The arrangements are documented through clear roles, plans and procedures, and they are tested and exercised so that they work in practice rather than only on paper. Finally, the system is maintained and improved over time, keeping it aligned with the organisation as it changes.

A useful part of this is recognising that impact usually grows the longer a disruption lasts. A practical way to capture this is to look at how the consequences of losing a critical activity change across different periods, for example after one day, after three days, and after a week, and to score that impact against the organisation’s own enterprise risk management and HSE impact criteria. A short payroll delay might be tolerated for a couple of days, then escalate quickly into a serious staff and reputational problem. Mapping how risk climbs over time shows exactly where the recovery time objective needs to sit. 

These requirements are deliberately generic so they apply to organisations of any size or sector. The depth of application scales with the complexity of the business. A small firm can meet them with a lean, practical system, while a large multinational will need something more detailed across many sites and dependencies.

A Simple Approach to Business Continuity Management Systems Implementation

Implementing a BCMS can feel daunting, but the early steps are approachable. A sensible starting point is the business impact assessment and a risk assessment. Together they tell you what has the highest impact over time and therefore where to focus the BCP and how quickly the BCP needs to be enacted. This is the foundation everything else rests on.

The next step is mapping dependencies across people, sites, systems and suppliers, so the organisation can see clearly what resources are required to recover from a disruption and where vulnerabilities and single points of failure lie. With that picture in place, the focus moves to creating practical, realistic plans that people will actually be able to follow under pressure, rather than lengthy documents that look thorough but prove unusable in a real incident.

In our experience, the most effective way to build these plans is from the inside out, with the people who actually run each function. We call these representatives “champions”. A facilitator coordinates and equips them, but the detail comes from the department itself.The HR manager, for example, understands payroll dependencies far better than any outside consultant could. This approach does two things at once: it produces more accurate plans, and it builds ownership and internal capability that outlasts the project.

It helps to start small rather than trying to map the entire organisation in one go. A practical route is to triage the two or three most critical departments, identify roughly three priority activities within each, and build a workable plan quickly, often within weeks. Later cycles then expand the coverage. This keeps the effort manageable, avoids overwhelming people who still have day jobs to do. It steadily builds a continuity culture across the business with experienced champions who can support other champions in departments that are added at later stages.

When creating the BCP, mitigation measures / plans work by either reducing the likelihood of a disruption or by reducing its impact. Some risks cannot be made less likely. You cannot stop a protest closing a high street, for example, but you can reduce the impact with an alternative location and a messaging service that redirects regular customers. Others can be made less likely, such as fitting a standby generator that cuts in automatically when mains power fails. Working through each priority risk in these terms turns a vague worry into a concrete, costed and resourced plan.

From there, continuity is embedded into governance and review cycles. It becomes part of how the organisation runs rather than a separate exercise. The most important mindset shift is to treat implementation as an ongoing process, not a one-off project with an end date. A BCMS is never truly finished; it matures as the organisation learns and changes.

Common Mistakes in Business Continuity Management

Common Weak Spots in Business Continuity Management

Even well-intentioned organisations make recurring mistakes. Recognising them is often the quickest route to a stronger approach.

The most common is treating continuity as a one-off exercise: writing a plan once, then assuming the job is done as the plan gathers dust on a shelf. Closely related is relying on outdated documents. Plans drift out of date as people, systems and suppliers change, leaving an organisation with arrangements that no longer reflect reality.

Other frequent errors are focusing only on IT disruption. Technology recovery matters, but continuity is far broader, covering people, data, premises, suppliers and processes;Planning only for a handful of specific scenarios, which leaves an organisation exposed to the disruptions it failed to imagine; Failing to assign clear ownership, so when an incident strikes, no one is sure who is responsible for what; Plans that are never tested. A plan that has not been exercised is really just an untested assumption; Finally, ignoring suppliers and third-party dependencies. Some of the most damaging disruptions originate outside the organisation entirely.

Business continuity plans tend to fail for these reasons rather than because the original thinking was poor. They fail because they are not kept current, not owned, not tested, or too narrow in scope.

How Organisations Can Build a More Effective Business Continuity Solution

Avoiding those weak spots points the way to a stronger business continuity solution. The first principle is to keep plans realistic and easy to use, written for people who will be stressed and short of time, not for an audit shelf. The second is to review arrangements after any significant change or disruption, so the system learns and adapts rather than ossifying. The third is to ensure that the plan is accessible and know by those who are charged with enacting it. Plans should be stored digitally and in hard copy to ensure that they are available in the event of a disruption that denies the use of, or access to digital systems.

Above all, the goal is resilience rather than documentation. A folder full of polished plans is not the objective; the ability to keep operating through disruption is.

When to Seek Specialist Support

Many organisations build a capable BCMS with internal resources, but there are moments when specialist support adds real value. It often makes sense when internal teams need help structuring a BCMS from the ground up and would benefit from experience of what works. It is also useful when a business wants to align with ISO 22301 and needs guidance through the standard’s requirements.

Specialist input is particularly worthwhile when existing continuity plans need reviewing or formalising, especially where they have grown piecemeal and lack a coherent system behind them. The point about untested plans is worth repeating here, because it is the mistake organisations regret most: the plan that named a departed contact, referenced a decommissioned system and assumed a way of working that no longer existed. Outside support frequently catches exactly these gaps before a real incident does. Finally, support helps when continuity needs to be embedded consistently across multiple sites, teams or suppliers, where the coordination challenge alone can overwhelm an internal team.

The right kind of support is the kind that leaves you stronger and more self-sufficient, not permanently dependent. A good partner coordinates the work, provides the framework and resources, and coaches your own people to run and maintain the system, ideally using familiar tools your teams already know rather than locking you into proprietary software you have to keep paying for and that need to be learnt. The measure of success is an organisation that can carry its own continuity capability forward long after the engagement ends.

Strengthen Your Approach to Business Continuity

A business continuity management system is not about predicting every disruption. It is about being ready for the ones that matter, and recovering from them with as little damage as possible. For most organisations, the value lies not in any single document, but in the discipline of identifying what is critical, planning for its protection, assigning ownership and keeping the whole approach current.

If your organisation is looking to build, review or align its business continuity management system with ISO 22301, Sicuro’s business continuity consulting team can support you with practical guidance tailored to your operational risks and continuity objectives.

Frequently Asked Questions

A business continuity management system (BCMS) is the overall framework an organisation uses to prepare for, respond to and recover from disruptions. It brings together the policies, people, plans, processes and reviews that keep critical operations running during an incident and restore normal service afterwards. It is broader than a single plan, because it includes ownership, testing and continual improvement.

Business continuity planning is commonly built around four core stages: analysis (understanding critical activities and their impact through a business impact analysis and risk assessment), design (deciding the continuity and recovery strategies), implementation (putting plans, resources and responses in place) and validation (testing, exercising and reviewing the arrangements). Together these stages ensure a plan is grounded in real priorities and proven to work.

Note: The Business Continuity Institute states there are six practices, adding Establishing a BCMS and Embracing Business Continuity to the above list.

The single most important goal is to keep critical products and services running, or to recover them within acceptable timeframes, so that the organisation can continue to meet its obligations during and after a disruption. Everything else in business continuity supports that aim.

A business continuity plan is a documented set of actions for responding to a disruption. A BCMS is the wider management system that creates, maintains, tests and improves those plans, with governance and ownership around them. In short, a plan is a tool, while a BCMS is the framework that keeps the tool reliable and up to date.

The main benefits include greater client confidence in an organizations ability to operate, reduced disruption to critical operations, faster response and recovery, clearer ownership during incidents, better decision-making under pressure, and greater visibility of organisational dependencies. Because a well-built BCMS plans for the loss of capabilities rather than for a fixed list of scenarios, it also protects against disruptions no one anticipated. Beyond incident response, it protects reputation, strengthens supplier and stakeholder assurance, and helps with governance, compliance and tender readiness.

The international standard is ISO 22301. The current version, ISO 22301:2019, sets out the requirements for establishing, implementing, maintaining and continually improving a BCMS, and provides the recognised benchmark for good practice in business continuity. Many practitioners also work to the Business Continuity Institute’s Good Practice Guidelines alongside the standard.

A BCMS typically includes a policy and defined scope, clear roles and responsibilities, risk assessment, business impact analysis, incident response procedures, communication plans, continuity and recovery plans, training and exercising, and ongoing monitoring, review and improvement. These elements work together as a single framework rather than as separate documents.

Implementation usually starts with a business impact analysis and risk assessment to identify critical activities and the risks to them being disrupted. Following this, champions decide how quickly and to what extent the organization needs to recover to. The next steps involve mapping dependencies across people, sites, systems and suppliers, defining recovery priorities, documenting practical plans and procedures, training people and testing the arrangements. A practical way to begin is to focus on the two or three most critical departments, build workable plans with the people who run them, and expand in later cycles. The system is then embedded into governance and treated as an ongoing process that is reviewed and improved over time rather than a one-off project.

Miles-Watt
Miles Watt

Senior Advisor, Security & Resilience

Miles has well over a decade of experience designing, implementing, scaling and leading resilience programs across the Middle East, Africa and Asia. He has supported commercial entities, government contracts, NGOs and the extractive industries for security providers. Most recently he has worked in house for an oil and gas services company. Miles has a wealth of experience in security, crisis management and business continuity.