Skip to content
CISO Marketplace Services

Business Continuity Assessment

Comprehensive evaluation of your organization's business continuity planning, capabilities, and readiness to maintain critical operations during disruptions. We assess operational resilience, recovery strategies, and provide actionable recommendations to enhance your continuity posture.

In scope

  • Business impact analysis review
  • Critical function identification
  • Recovery strategy assessment
  • BC documentation evaluation
  • Crisis management procedures
  • BC governance framework
  • Alternate site capabilities
  • Supply chain resilience

You receive

  • Business continuity capability report
  • Gap analysis and recommendations
  • Business impact analysis update
  • BC program development roadmap
  • Crisis management improvement plan
  • BC policy and procedure enhancements

Tiers

Choose the depth.

Core Business Continuity Assessment

$32K

Up to 250 employees and 1 site. Review of the existing BIA, BC documentation, recovery strategies and crisis procedures, identifying up to 10 critical functions. Capability report, gap analysis and BC program roadmap.

employees
250
Sites
1
  • Review of existing BIA and BC documentation
  • Critical function identification (up to 10)
  • Recovery strategy and crisis procedure assessment
  • Gap analysis and recommendations
  • BC program development roadmap
  • — Conducting a new BIA
  • — Writing recovery strategies or BC plans
  • — Supply chain resilience review
  • — Exercises and testing
Scope Core Business Continuity Assessment

Standard BC Program Development

$55K

Up to 1,000 employees and up to 3 sites. We run a new BIA for up to 25 critical functions with RTO/RPO targets, develop recovery strategies per function, review alternate site capability and BC governance, and update BC policies and procedures.

employees
1000
Sites
3
  • Everything in the core assessment
  • New BIA for up to 25 critical functions
  • Recovery strategy development per function
  • Alternate site and BC governance review
  • BC policy and procedure enhancements
  • — Integrated IT disaster recovery planning
  • — Supply chain resilience program
  • — Crisis management exercise
  • — Live testing
Scope Standard BC Program Development

Enterprise Resilience Program

$90K

Up to 2,500 employees and up to 10 sites. BIA for up to 50 critical functions, integrated BC/DR planning with IT, crisis management improvement plan with 1 facilitated crisis exercise, and supply chain resilience review of up to 15 critical suppliers.

employees
2500
Sites
10
Objectives
1
vendors
15
  • Everything in the standard tier
  • BIA for up to 50 critical functions
  • Integrated BC/DR planning with IT recovery owners
  • One facilitated crisis management exercise
  • Supply chain resilience review (up to 15 suppliers)
  • — Technical DR failover testing
  • — BC software platform licences
  • — Ongoing program management
  • — Organizations above 2,500 employees (scoped separately)
Scope Enterprise Resilience Program

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a incident response readiness engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Current-state review

    Plans, playbooks, contacts, logging and insurance requirements reviewed.

    You see · Your IR plan and insurance policy.

  2. 02Scenario design

    Scenarios chosen for your threat profile: ransomware, BEC, insider, cloud compromise.

    You see · Participant list and scenario sign-off.

  3. 03Exercise / readiness work

    Tabletop facilitation or readiness build-out, depending on the service.

    You see · Your team's time in the room.

  4. 04After-action report

    Gaps found, decisions that stalled, and an improvement plan with owners.

    You see · A report your board and insurer can read.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor