Business Continuity Planning
At 2Oaks Consulting, we provide comprehensive Business Continuity Management System (BCMS) Strategy and Adoption services that enable your organization to build resilience and maintain critical operations through any disruption. Our approach ensures that continuity planning becomes embedded in your organization's culture and aligns with your strategic objectives and regulatory requirements.
Key Components of Our Service
-
Successful BCMS implementation requires clear executive sponsorship and strategic direction. Our team will:
Align BCMS strategy with corporate objectives and risk appetite
Develop phased implementation roadmaps tailored to your operational complexity
Establish governance structures and executive sponsorship for program sustainability
-
Understanding your current capabilities establishes a clear baseline for improvement. We help:
Conduct thorough assessments against ISO 22301 and industry best practices
Identify gaps in current policies, procedures, and technical capabilities
Develop prioritized remediation plans with measurable milestones
-
Robust frameworks and comprehensive policies drive effective continuity planning. Our experts will:
Design BCMS frameworks aligned with ISO 22301 and regulatory requirements
Develop comprehensive policy suites covering business continuity, crisis management, and disaster recovery
Create scalable documentation structures that adapt to organizational growth
-
Thorough analysis identifies and prioritizes your critical business functions. Our methodology:
Maps dependencies across people, processes, technology, and third parties
Quantifies financial and operational impacts of disruption scenarios
Establishes recovery time objectives (RTO) and recovery point objectives (RPO) aligned with business tolerance
-
Effective risk identification forms the cornerstone of resilient operations. We help:
Identify threats and vulnerabilities specific to your industry and operating environment
Evaluate likelihood and impact to prioritize risk treatment strategies
Develop risk registers integrated with enterprise risk management frameworks
-
Practical recovery approaches protect your critical operations across disruption scenarios. Our strategies:
Define technology and operational recovery approaches for various disruption types
Establish alternate site strategies, workforce continuity, and communication protocols
Balance cost-effectiveness with risk reduction to optimize resilience investments
-
Comprehensive, actionable plans ensure effective response when disruption occurs. Our team will:
Develop business continuity, disaster recovery, and crisis management plans
Create role-specific procedures and playbooks for response teams
Implement document management systems for version control and accessibility
-
Rigorous testing validates your plans and builds organizational muscle memory. Our approach:
Designs multi-year exercise calendars covering tabletop, functional, and full-scale exercises
Facilitates scenario-based exercises tailored to your threat landscape
Captures lessons learned and drives continuous improvement through after-action reviews
-
Strong governance ensures sustained BCMS success and regulatory alignment. We help:
Establish steering committees and reporting structures for ongoing oversight
Implement management review processes aligned with ISO 22301 requirements
Develop audit-ready evidence and compliance monitoring frameworks
Partner with 2Oaks to build operational resilience capabilities that protect enterprise value, demonstrate regulatory compliance, and enable confident growth through any disruption.
FAQs
We already have a business continuity plan. Isn't that enough?
Most disruptions seem to start with our vendors. How do we cover third-party resilience?
Having a plan and being able to prove it works are two different things, and that gap is exactly what regulators now test. Operational resilience asks you to show that you can keep delivering critical operations through a severe disruption, with those operations mapped, tolerances set, dependencies traced, and scenarios actually exercised. A binder of documents that has not been tested rarely survives that scrutiny. The fastest way to find out where you stand is our free Business Resilience Assessment, which takes about 20 minutes and surfaces the gaps a supervisor would likely raise first.
What is OSFI E-21, and what does it require us to do by when?
OSFI's Guideline E-21 sets operational resilience expectations for federally regulated financial institutions, and it moves the bar from having a business continuity plan to running a tested program. Full adherence is required by September 1, 2026, and scenario testing across all critical operations is expected by September 1, 2027 (the Section 4 milestone passed in September 2025). In practice it asks four things: identify your critical operations end to end, set a tolerance for disruption for each one, map the dependencies that hold them up (including third parties), and scenario-test against those tolerances. We break down the questions institutions are asking, and the ones they tend to avoid, in OSFI E-21: The Questions Most Canadian Banks and Credit Unions Are Asking.
We operate in the US. What's the equivalent, and when is it due?
There's no deadline, and that's the problem. The expectation went live in 2019, when the FFIEC replaced its Business Continuity Planning booklet with the Business Continuity Management booklet. The rename was the point: from having a plan to running a tested program. Credit unions add NCUA Parts 748 and 749 on top.
It asks the same four things E-21 does. Identify your critical operations and vital member services. Set recovery objectives you can defend. Map the dependencies behind them, third parties included. Then exercise and test, which FFIEC treats as two separate activities and most institutions report as one.
What the US has instead of a deadline is clocks already running. Banks report a notification incident within 36 hours. Credit unions report a cyber incident within 72, including one a vendor reports to you. Take our free Business Resilience Assessment to see where you stand.
We've always used the FFIEC CAT. Is that still valid?
No. The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025 and didn't name a successor, pointing institutions to NIST CSF 2.0, the CRI Profile, the CIS Controls, and CISA's performance goals instead. If your last documented maturity baseline was a CAT self-assessment, you're reporting to your board against a framework that no longer exists
Do we need ISO 22301 certification?
Our plan is a few years old and our core system has changed. Do we rewrite it?
Not necessarily. We use ISO 22301 as the framework to structure your business continuity management system, because it organizes the program well, but formal certification is a separate and optional step. What a regulator actually wants to see is evidence that the program works: critical operations identified, tolerances set, dependencies mapped, and tests run with the results acted on. We align the management system to the standard and to your regulatory obligations, then help you decide whether certification is worth pursuing for your situation. Our partners have run operations and resilience inside financial institutions, so the framework is applied to how your organization actually works, which you can see on Meet Our Team.
Re-baseline it rather than rewrite it. A fresh document that does not reflect your current critical operations, dependencies, and tolerances is just a new version of the same problem. The practical sequence is to confirm what your critical operations are today, map what they actually depend on now (including the systems added since the plan was written), set tolerances against current business reality, and only then update the response procedures. This matters most right after a core go-live, when the plan is often stale at exactly the moment the risk is highest, which Derrick explains in this short video.
How often should we test our plans, and what actually counts as a test?
Testing is where the evidence gets created, so it is the part regulators most want to see. Start with tabletop exercises on a real critical operation, with the right people in the room and an action list that gets tracked afterward, then build up to simulations and live-systems testing as the program matures. Under E-21, scenario testing needs to reach all critical operations by September 2027, and a test that surfaces nothing to fix usually means the scenario was not hard enough. As Chris puts it, real readiness comes from plans embedded in daily operations rather than a document on a shelf, which he covers in this video.
Your third-party resilience is now part of your own resilience, because most disruptions to critical operations originate at third parties and their supply chains. That means pressing your critical vendors for their own continuity plans, their test results, and their concentration risk on major cloud providers, and treating those as regulatory expectations rather than procurement niceties. It also means having a credible exit plan for critical vendors, even one that acknowledges a multi-year transition, since the absence of a plan is itself a finding. We walk through the third-party angle, and how E-21 works alongside OSFI B-10 and B-13, in our E-21 readiness piece.
Explore Other Services