Institute for continuity and resilience
Continuity is not a plan.It is a capability.
Training, annotated standards, working templates and certifications across business continuity, operational resilience, operational risk, IT continuity and crisis management.
32
courses
99
annotated requirements
45
working templates
8
certifications
Tracks
Eight tracks, one discipline
Each track leads to a certification and rests on the standards that carry authority in its field.
Business Continuity
From your first BIA to a certifiable management system
Operational Resilience
Think in critical services and tolerances, not processes
Operational Risk
Identify, measure and arbitrate the risk you cannot hedge
IT Continuity & Disaster Recovery
Design, cost and prove a recovery capability
Crisis Management
Decide fast, under uncertainty, without losing trust
DORA Compliance
The five pillars, article by article, deliverable by deliverable
Cyber Resilience
Hold when the defences have already failed
Third-Party & Supply Chain Risk
Your resilience stops where your suppliers' begins
Standards
The standards library, clause by clause
For every requirement: its intent, the evidence an auditor will ask for, and the pitfalls seen in audit. Original editorial summaries — never the normative text, which remains its publishers’ property.
Business continuity management systems — Requirements
The global reference for building, running and certifying a business continuity management system (BCMS). It states what an organisation must have in place — not how — and is the only text in the 223xx family against which an accredited body can issue a certificate.
ISO
Crisis management — Guidelines
The international reference for crisis management since it superseded the UK PAS 200. It cleanly separates incident (known procedure) from crisis (novel, ambiguous, high-stakes) and focuses on decision-making capability rather than on the plan.
ISO
Guidelines for information and communication technology readiness for business continuity (IRBC)
The bridge between business continuity and IT. It introduces ICT readiness for business continuity (IRBC) and the metrics that are now common currency: RTO, RPO, and degraded service level objectives.
ISO/IEC
Digital operational resilience for the financial sector
In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.
Union européenne
Measures for a high common level of cybersecurity across the Union
NIS 2 substantially widens its predecessor's scope: eighteen sectors, essential and important entities, management liability and significant administrative fines. Article 21 explicitly requires business continuity and crisis management among the minimum measures.
Union européenne
Good Practice Guidelines for business continuity
The practitioner corpus, structured around the business continuity lifecycle: two management professional practices and four technical ones. Where ISO 22301 says what to do, the GPG says how to do it day to day, in practitioner language.
BCI
Principles for the Sound Management of Operational Risk
The twelve principles underpinning banking operational risk management worldwide. They structure the three lines of defence, the identification and assessment toolkit (RCSA, loss data collection, key risk indicators, scenario analysis), and the governance around them.
BCBS
Principles for Operational Resilience
The text that shifted the financial sector from process-based continuity to a logic of critical services and impact tolerance. Seven principles requiring identification of critical operations, mapping of the resources supporting them, and explicit tolerances.
BCBS
The texts presented here are original editorial summaries of each requirement’s intent. They do not reproduce the normative text, which must be obtained from its publisher.
Method
How we work
Durations, not opinions
Every method taught produces a number that stands up in an audit: MTPD, RTO, impact tolerance, measured gap. A course that does not lead to a decision has no place in the catalogue.
Pitfalls before procedures
For every requirement we document the error that fails it in an audit. Confusing 6.1 with 8.2.3, aligning an RTO with the MTPD, calling a documentation review a “test”: those are the gaps that cost.
Files, not slides
Forty-five working templates, generated in the format you need and shipped with their instructions. You leave with the deliverable, not with a picture of it.
Toolkit
Working files, not examples
Forty-five templates generated in the format you need, with the instructions and the mistakes to avoid.
Where do you actually stand?
Twenty questions, a score per dimension, and the three gaps that cost most in an audit. Immediate result, shareable by link.
Run a diagnostic- ISO 22301 diagnostic — 20 questions, 6 dimensions
- DORA readiness diagnostic — 15 questions, 5 pillars
- Operational resilience diagnostic — 12 questions
Insights
What we observe in the field
The RTO nobody had tested
A declared four-hour RTO, an exercise measured at four hours forty-seven, and three time items almost no plan counts.
7 min read
The register of information, DORA's most underestimated deliverable
Not a supplier list but a set of linked tables with dozens of fields, contract-level granularity and mandatory annual submission.
6 min read
Why your BIA bogs down, and how to unblock it
A hundred and twenty questionnaires, six months, and a table where every activity is four-hour critical. The cause is a sequencing error.
6 min read