Business Continuity Plan (BCP)
A Business Continuity Plan is a documented framework defining how an organization will maintain or rapidly resume critical operations during and after a disruption, such as a cyberattack, natural disaster, or vendor failure. In third-party cyber risk management, evaluating a vendor's business continuity plan is a standard component of due diligence, as vendor failures can directly disrupt first-party operations. Also referenced as Business Continuity Planning.
What Does a Business Continuity Plan Actually Contain?
A complete BCP identifies which functions matter most, how fast each needs to come back online, and who's responsible for making that happen. A document missing any of these pieces isn't really a continuity plan, whatever it's labeled as.
- Business impact analysis, ranking which functions and systems are most critical and what a disruption to each would cost.
- Recovery strategies, the specific steps and alternate resources used to restore each critical function.
- Roles and responsibilities, naming who acts during a disruption instead of leaving it to whoever's available that day.
- Communication plan, covering how staff, customers, and partners get updated while the disruption is underway.
- Testing schedule, documenting how often the plan gets rehearsed rather than just filed away.
How Does a Business Continuity Plan Differ From a Disaster Recovery Plan?
A business continuity plan covers the whole organization. A disaster recovery plan is the narrower piece of it focused specifically on restoring IT systems and data. Disaster recovery is usually a component nested inside a broader business continuity plan, not a separate document covering different ground.
A BCP Covers the Whole Organization
A business continuity plan asks how the business keeps serving customers when a facility, a process, or a key function goes down, whether or not a single computer is involved. A manufacturing plant losing power, a key supplier missing a shipment, or a regional office becoming inaccessible all fall inside a BCP's scope.
A DRP Focuses Specifically on IT Systems
A disaster recovery plan asks a narrower question: how does a specific data center, application, or backup system come back online after an outage. It's the technical execution layer that a broader continuity plan depends on whenever the disruption happens to involve technology, which today is most of the time.
Why Does a Vendor's Business Continuity Plan Matter to the Organizations That Depend on It?
A vendor's outage becomes the downstream organization's outage the moment that vendor supports a critical function, which is why a vendor's BCP is a direct risk to the businesses relying on it, not just an internal matter for the vendor. Black Kite's 2026 Ransomware Report found manufacturing led all sectors with 1,660 disclosed victims, 22.0% of the total, exactly the kind of operational disruption a business continuity plan exists to survive.
Concentration Multiplies the Exposure Fast
This risk concentrates fastest when several critical functions run through the same vendor, or when several vendors quietly depend on the same underlying provider. For more on that specific pattern, see the Concentration Risk Knowledge Center.
Not every vendor's continuity plan deserves the same scrutiny. A few signals tend to justify a closer look:
- High criticality tier, where an outage would stop a core business process rather than a minor convenience.
- Single points of failure, where no alternate vendor could realistically cover the gap on short notice.
- A history of past disruptions, whether from outages, breaches, or missed service commitments.
A vendor inventory that tracks criticality, paired with vendor tiering, is what makes it possible to know which vendors' continuity plans warrant that closer look before a disruption forces the question.
How Often Should a Business Continuity Plan Be Tested?
An untested plan is a hypothesis, not a guarantee, so testing cadence matters as much as the plan's content. Most mature programs run at least one tabletop exercise or simulated failover annually, with more frequent testing for functions ranked highest in the business impact analysis.
Untested Plans Drift From Reality
A plan that hasn't been tested since it was written has had every opportunity to drift out of sync with how the organization actually operates today. Systems get replaced, staff who knew the plan by heart move on, and an incident response process built around an outdated plan can lose critical time during the exact moment speed matters most.
What Can't a Business Continuity Plan Document Guarantee?
Having a BCP on file doesn't mean the organization can actually execute it, since a plan is only as good as the last time it was tested against something resembling a real disruption. Plans go stale as the business changes. New systems get adopted, critical vendors change, staff who knew the plan by heart move on, and none of that shows up in a document that was accurate the day it was written but hasn't been revisited since.
What Should a Risk Team Look for When Reviewing a Vendor's BCP?
The document itself proves less than the evidence that it's actually been exercised, so a review should ask for both.
- Request test results, not just the plan. A tabletop exercise report or a failover test result shows whether the plan works, not just whether it exists.
- Check for defined recovery objectives. A credible plan states specific recovery time and recovery point targets, not vague assurances.
- Confirm the plan covers the actual service provided. A vendor's generic corporate continuity plan may not address the specific product or service this relationship depends on.
- Ask when it was last updated, since a plan older than the vendor's current infrastructure is describing a business that no longer exists.
How Does Black Kite Factor Business Continuity Into Vendor Risk Assessments?
Vendors document their continuity commitments in questionnaires and policies, and Black Kite factors that evidence into vendor risk assessments through AI Questionnaire Management, where the UniQuE™ Parser reads documents in their original format and maps their contents to the controls in 14 compliance frameworks, flagging where a claim is supported only by a policy statement rather than a technical control finding. A vendor's continuity commitments are only as reliable as the underlying dependencies behind them, which is why extending visibility to a vendor's own critical suppliers through Black Kite Extend matters as much as reviewing the vendor's own plan.
See also: How to Solve Vendor Outreach During Security Crisis Events