What belongs in the analysis
A practical scenario
Consider a simple scenario: staff cannot access scheduling, payment, inventory, or shared records because a cloud service or internal account is unavailable.
Use the scenario to answer two concrete questions: Which activity fails first when this service is unavailable? How long can the organization operate manually? The record becomes useful when those answers are supported by evidence and tied to a named decision owner.
Evidence worth gathering
Evidence should be proportionate to the importance of the decision. The following records commonly make the discussion more reliable:
- Business impact analysis and service maps
- Tested workarounds and recovery procedures
- Actual outage and recovery performance
- Dependency and concentration records
- Staffing and communication plans for degraded operations
A practical review sequence
- Clarify critical activity: The customer, production, finance, safety, communications, or administrative work that must continue.
- Describe digital dependency: Applications, identities, networks, devices, data, suppliers, and integrations required for that activity.
- Evaluate disruption tolerance: How long or how much degradation the activity can withstand.
- Test workaround and recovery: Manual alternatives, alternate providers, restore capability, staffing, and decision paths.
- Confirm cascading effect: How one unavailable service affects other processes, customers, or obligations.
- Close the review by answering: Who prioritizes competing recovery needs?
Common failure modes
- Assuming backup existence equals recoverability
- Measuring only system uptime and not business service delivery
- Ignoring shared identity, network, or supplier dependencies
- Planning recovery without testing people and decisions
Questions for management
- Which activity fails first when this service is unavailable?
- How long can the organization operate manually?
- What hidden dependency could block recovery?
- Who prioritizes competing recovery needs?
Frequently asked questions
What should be documented first for operational cyber risk?
Start with critical activity: The customer, production, finance, safety, communications, or administrative work that must continue.
Which evidence should receive early attention?
Begin with business impact analysis and service maps and tested workarounds and recovery procedures. The right evidence is the evidence capable of changing confidence or the treatment decision.
What commonly weakens this analysis?
One frequent problem is assuming backup existence equals recoverability. The review should make that weakness visible instead of hiding it behind a score or dashboard.
When should it be revisited?
Review it on the scheduled date and whenever the conditions behind this question change: Which activity fails first when this service is unavailable?