Why the Best Time to Build Resilience Based on ISO 22301 Standard Was Last Year. The Second Best Time Is Now.

A frustrated business man receiving a distressing evacuation notice on their phone

The Incident That Changes Everything And Why the ISO 22301 Standard Exists

In October 2024, we evacuated 60 people from Lebanon in under 24 hours.

By air. Shuttling a small jet between Beirut, Amman, Cyprus, and Athens because Istanbul, our “Plan A”, revoked our landing permits. Not once, but twice. After takeoff.

So we spun up Plan B, C, and then D. And we did it.

Relationships matter in times like this. With clients, obviously, to trust us and appreciate the situation. But also relationships with the people willing to step up: getting us permissions to land passengers with no visas, moving them from a military apron to commercial terminals on the fly. That’s what matters in crisis management iso 22301 was designed to support, structured decision-making under pressure, not chaos.

It wasn’t the first time. In 2020, during COVID, we negotiated with Iraqi, UK, UAE, and Croatian agencies to get airspace opened and permits granted, repatriating UK citizens from Iraq via Croatia to London and in return, flew 180 Iraqis home. In 2022, when European insurance markets stopped covering aircraft entering Russia and thousands were stranded, we hired a plane and had around 100 people safely in Dubai within 24 hours; at less than half the $1 million a competitor had quoted.

All examples of where there was no “Plan B.” In some cases there wasn’t even a “Plan A.”

Back to Lebanon. Six client organizations. Multiple nationalities with differing travel restrictions. Scattered across Beirut. The security situation had deteriorated beyond the point where staying was an option.

What made the difference was that we didn’t start planning when the crisis hit. We’d been conducting ongoing iso 22301 risk assessment processes for months, monitoring deterioration, mapping escalation triggers, communicating with clients before thresholds were crossed. Routes were pre-planned. Vehicles were pre-positioned. Communication channels were tested. Every person had been briefed on what to do and who to call.

When the call came, it was execution; not crisis response. That distinction is the difference between improvisation and a functioning business continuity management system iso 22301 was built to formalize.

Where Does Your Organization Stand?

Most business continuity plans look good on paper but fail under pressure. Our ISO 22301 maturity assessment identifies the gaps before a crisis does.

2 a.m. Call Nobody’s Ready For

We’ve taken too many of these calls over 20 years to count. The pattern is almost always the same.

Something happens overseas. A political crisis, civil unrest, a security incident, a natural disaster. Someone in the organization, usually not a security professional, realizes they have people in-country and no plan to get them out.

The next few hours are a scramble:

  • Who’s actually there? Where are they staying?
  • Do we have their phone numbers?
  • What does our insurance cover?
  • What does our duty of care policy say? Do we even have one?
  • How will we pay for an evacuation?

 

By the time those questions are answered, the window for a clean evacuation has usually closed.

This is exactly why an iso 22301 business continuity plan isn’t just a document; it’s supposed to be a living, operational capability. The iso 22301 requirements don’t assume you’ll figure things out in real time. They assume you’ve already identified critical activities, defined escalation paths, assigned decision authority, and tested communication channels before the 2 a.m. call ever happens.

The worst time to check your business continuity plan is when you need it. The second worst time is discovering you don’t have one, or that it exists somewhere on SharePoint but was never embedded into your iso 22301 framework in a way that actually works under pressure.

Why Every Serious Organization Got Serious Because of an Incident

Every organization that’s serious about resilience today got serious because of an incident. Or a near-miss. Or a board member who read about someone else’s incident and asked uncomfortable questions.

Nobody builds a crisis management framework because it sounds like fun. They build it because something happened that made the ad-hoc approach feel reckless. That turning point is often when leadership starts looking seriously at the iso 22301 standard, not as a badge, but as a structured way to prevent improvisation from becoming a liability.

The organizations that act after their first wake-up call are the ones that survive the second one. The ones that don’t act? They’re gambling that the next incident will be as manageable as the last. And the odds aren’t in their favor and nor are the judgments of regulators, or worse, should you suffer a loss.

The mature response isn’t panic. It’s building a business continuity framework iso 22301 aligned; one that translates lessons learned into governance, accountability, and capability. That usually starts with defining an iso 22301 business continuity policy that makes resilience a board-level commitment rather than an operational afterthought.

Incidents create awareness. Structured resilience ensures survival.

Why Most Business Continuity Plans Fail in a Real Crisis

Most business continuity plans we’ve reviewed aren’t worth the paper they’re printed on. Generic, templated word salad, documents created by consultants, approved by committees, and filed in a SharePoint folder nobody can find when it matters.

They technically “exist.” They might even pass an internal iso 22301 audit. But passing an audit and surviving a real-world crisis are two very different things.

They cover IT disaster recovery and office relocation. They don’t cover the messy, human, real-world scenarios that actually happen:

  • What happens when your people are in a country where the currency collapses overnight and ATMs stop working?
  • When communications infrastructure goes down and you can’t reach your team?
  • When civil unrest blocks the road to the airport and your pre-planned evacuation route is useless?

 

We’ve dealt with all of these in the last eighteen months. Spain from a power outage. Lebanon from conflict. Venezuela because nobody truly saw it coming, not to the point they planned for it.

The scenarios that test resilience are never the ones you planned for. That’s why genuine corporate resilience isn’t a document, it’s a capability. The ability to absorb information in real time, make decisions under pressure, and adapt when the plan stops working.

That’s also the intent behind the iso 22301 standard. Not paperwork. Not templated compliance. But a functioning business continuity management system iso 22301 aligned, one that embeds adaptability, leadership, and operational clarity into the organization itself.

It’s people, relationships, and judgment supported by process, not replaced by it.

ISO 22301 Standard: The Business Continuity Framework That Holds Under Pressure

The iso 22301 standard is the international benchmark for building a resilient organization through a structured Business Continuity Management System (BCMS). If ISO 31030 is about protecting your people when they travel, the iso 22301 framework is about ensuring your organization can continue operating when things go seriously wrong.

Done right, it’s the structure that turns “we’ll figure it out when it happens” into “we know exactly what to do.” The difference isn’t paperwork; it’s alignment with iso 22301 requirements that define accountability, leadership commitment, operational controls, and continual improvement.

In practice, implementing the iso 22301 standard means:

  • Conducting a structured iso 22301 risk assessment: identifying not only obvious threats, but cascading failures and second- or third-order impacts that can quietly escalate into a full crisis.
  • Building response capabilities: who does what, who calls whom, what resources are available, and what the fallback is when Plan A fails.
  • Testing under realistic conditions: not tabletop exercises where everyone agrees the plan works, but stress scenarios that expose weaknesses before a real incident does.
  • Creating governance that holds: clear decision-making authority, escalation paths, and communication protocols that function when people are stressed, tired, and under pressure.

 

The iso 22301 standard doesn’t eliminate uncertainty. It gives you a disciplined way to operate inside it.

The Leaders Who Hold Up in a Crisis

We’ve been doing this long enough to know what separates the organizations that handle crises well from the ones that don’t. It’s not a budget. It’s not technology. It’s not even an experience.

It’s whether the people in charge stay human.

The leaders who hold up in a crisis are consistent. They communicate clearly. They empower their people to make decisions. They don’t pretend to have all the answers, but they make sure the right questions are being asked.

And critically, they prepared before the crisis arrived. Not perfectly. Not for every scenario. But enough that when the 2 a.m. call comes, the response is execution, not panic.

That’s exactly why the iso 22301 standard places leadership and accountability at the center of organizational resilience. Because when systems are stressed, it’s not documents that respond; it’s people.

What We’d Tell You If We Were Having Coffee

If you’re reading this because something already happened, a near-miss, an incident, an uncomfortable board conversation, we get it. That’s how most of these relationships start.

The incident was the tuition. The question now is what you do with the lesson.

You don’t need to build a security department overnight. You don’t need bureaucracy. And you don’t need a 200-page document that no one can operationalize.

You need a partner who understands your operating environment, who has managed real-world evacuations and cross-border crises, and who can translate experience into structure aligning your organization with the iso 22301 standard in a way that actually works under pressure.

That’s where Securo Group comes in.

We support organizations with practical resilience architecture: gap assessments, maturity benchmarking, implementation of business continuity frameworks, leadership advisory, and real-world scenario testing. Not theory. Not template compliance. Operational capability.

We’ve been that partner for organizations across 140+ countries since 2005. We work from Washington DC and Dubai because the organizations that need this most are here. And we’re deliberately boutique because resilience isn’t a product you buy off the shelf.

Preparation over panic. Relationships over paperwork. Judgment over fear.

Frequently Asked Questions

The iso 22301 standard is the international benchmark for Business Continuity Management Systems (BCMS). It provides a structured iso 22301 framework that enables organizations to plan, implement, and continually improve their ability to continue operating during and after disruptive incidents from natural disasters and cyber attacks to political instability and supply chain failures.

An iso 22301 business continuity plan is only one component of a much broader management system. ISO 22301 goes beyond documentation, it defines governance structures, testing protocols, leadership accountability, and continuous improvement mechanisms.

Most traditional BCPs are static documents. A business continuity management system iso 22301 aligned is a living operational capability embedded across the organization.

A Business Impact Analysis (BIA) is a core element of iso 22301 risk assessment. It identifies your organization’s critical functions, the resources they depend on, and the operational and financial impact of disruption over time.

It also supports compliance with iso 22301 requirements by ensuring recovery priorities, maximum tolerable downtime, and resource dependencies are clearly defined; something regulators and insurers increasingly expect to see after an incident.

An initial maturity review or gap analysis can often be completed within 2–4 weeks. Designing and implementing a business continuity management system iso 22301 aligned typically takes 3–6 months, depending on organizational complexity, geographic footprint, and the maturity of existing resilience programs.

Organizations preparing for an iso 22301 audit may require additional time for documentation, internal testing, and management review cycles.

It also supports compliance with iso 22301 requirements by ensuring recovery priorities, maximum tolerable downtime, and resource dependencies are clearly defined; something regulators and insurers increasingly expect to see after an incident.

Not necessarily. Many organizations choose to align their governance and iso 22301 business continuity policy with the iso 22301 standard without pursuing formal certification.

The real value lies in meeting the iso 22301 requirements and building operational resilience not in the certificate itself. That said, certification can strengthen credibility with clients, regulators, and insurers where formal assurance is required.

Ready to Build Something That Actually Works?

The time to build resilience isn’t after the incident. It’s now — while you still have the luxury of choosing when and how. Drop us a message. Tell us where your operations are, and we’ll tell you where your gaps are.

Scott-Wilcox
Scott Wilcox
International Security Risk Advisor | Founder, Sicuro Group

Scott Wilcox is an international security risk advisor and the Founder and Senior Advisor of Sicuro Group, a private security and risk management firm headquartered in Dubai, United Arab Emirates. Based in Dubai, Scott Wilcox advises executives, family offices, and ultra high net worth individuals on global risk exposure, executive protection, travel risk management, and operating in complex and high risk environments. He is regularly consulted on emerging security threats and geopolitical risk and is frequently quoted by international media including Bloomberg, Financial Times, CNBC, and International Security Journal on security, travel safety, and global risk trends. Through Sicuro Group, Scott Wilcox supports clients across the Middle East, Europe, Africa, and Asia.