đ Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1
Course Outline
html
Certified Business Continuity Management Expert (CBCME) ¡ Course Outline
CBCME
Certified Business Continuity Management Expert
2026 ¡ v3.0
Duration: 5 days (40 hours)
Modules: 8 core + 1 capstone
Level: Advanced / Expert
Format: In-person ¡ virtual ¡ hybrid
Course overview
The CBCME program equips professionals with the strategic mindset, frameworks, and practical skills to design, implement, and continuously improve business continuity management systems. Aligned with ISO 22301 and global best practices, this expert-level course goes beyond theoryâfocusing on resilience, crisis leadership, and integrated risk management.
Detailed syllabus
M1Foundations of Business Continuity 4h
Core concepts: BCM lifecycle, resilience, and organizational context
Regulatory & standards: ISO 22301, NFPA 1600, local regulations
BCM program governance: policy, roles, and RACI
Business impact analysis (BIA) introRisk appetiteMaturity models
M2Risk Assessment & Business Impact Analysis 6h
BIA methodology: identifying critical functions, dependencies, and RTO/RPO
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
Apply a structured BIA methodology to identify critical functions and dependencies
Determine RTO, RPO, and MTD for essential business processes
Conduct qualitative & quantitative threat and vulnerability assessments
Build plausible disruption scenarios and evaluate impact thresholds
Translate risk findings into actionable continuity requirements
Module content
2.1 Business Impact Analysis (BIA) framework
2h
BIA purpose & scope: aligning with organizational strategy
Identifying critical functions: process mapping and dependency analysis
Recovery Time Objective (RTO) & Recovery Point Objective (RPO) â calculation methods
Maximum Tolerable Downtime (MTD) and work recovery time
workshop BIA interview simulation & data collection template
2.2 Threat & Vulnerability Assessment
1.5h
Threat landscape: natural, humanâcaused, technological, and geopolitical
Qualitative vs. quantitative approaches: risk matrices, scoring, and financial exposure
Vulnerability identification: internal weaknesses and external dependencies
exercise Risk register development (ISO 22301 aligned)
2.3 Scenario Analysis & Impact Evaluation
1.5h
Plausible disruption scenarios: building realistic and relevant cases
Impact assessment: financial, operational, reputational, and regulatory consequences
Interdependency mapping: supply chain, IT, and thirdâparty services
case study Analysing a multiâsite disruption scenario
2.4 Reporting & Integration
1h
BIA & risk reports: structure, executive summary, and actionable recommendations
Linking to strategy: translating findings into continuity requirements
Stakeholder communication: presenting risk to leadership and business units
group work Draft BIA summary for a simulated organisation
Key takeaway: A robust BIA and risk assessment provide the evidenceâbased foundation for all continuity strategies and investments.
RTO ¡ RPO ¡ MTD
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
Apply a structured BIA methodology to identify critical functions and dependencies
Determine RTO, RPO, and MTD for essential business processes
Conduct qualitative & quantitative threat and vulnerability assessments
Build plausible disruption scenarios and evaluate impact thresholds
Translate risk findings into actionable continuity requirements
Module content
2.1 Business Impact Analysis (BIA) framework
2h
BIA purpose & scope: aligning with organizational strategy
Identifying critical functions: process mapping and dependency analysis
Recovery Time Objective (RTO) & Recovery Point Objective (RPO) â calculation methods
Maximum Tolerable Downtime (MTD) and work recovery time
workshop BIA interview simulation & data collection template
2.2 Threat & Vulnerability Assessment
1.5h
Threat landscape: natural, humanâcaused, technological, and geopolitical
Qualitative vs. quantitative approaches: risk matrices, scoring, and financial exposure
Vulnerability identification: internal weaknesses and external dependencies
exercise Risk register development (ISO 22301 aligned)
2.3 Scenario Analysis & Impact Evaluation
1.5h
Plausible disruption scenarios: building realistic and relevant cases
Impact assessment: financial, operational, reputational, and regulatory consequences
Interdependency mapping: supply chain, IT, and thirdâparty services
case study Analysing a multiâsite disruption scenario
2.4 Reporting & Integration
1h
BIA & risk reports: structure, executive summary, and actionable recommendations
Linking to strategy: translating findings into continuity requirements
Stakeholder communication: presenting risk to leadership and business units
group work Draft BIA summary for a simulated organisation
Key takeaway: A robust BIA and risk assessment provide the evidenceâbased foundation for all continuity strategies and investments.
RTO ¡ RPO ¡ MTD
Resource requirements: technology, facilities, personnel, and vendors
Budgeting for BCM: capital vs. operational expenditure
ROI of resilience: quantifying the value of continuity
exercise Build a BCM budget for a mid-sized enterprise
3.3 Integration with IT Disaster Recovery & Crisis Management
1.5h
BCM vs. IT DR vs. Crisis Management: roles and interdependencies
Unified response framework: aligning plans and escalation procedures
Technology dependencies: ensuring IT recovery supports business recovery
Governance integration: single point of accountability and reporting
case study Integrating BCM and IT DR at a financial institution
3.4 Designing the Continuity Strategy
0.5h + workshop
Strategic alignment: linking BCM to business objectives and risk appetite
Strategy documentation: presenting the continuity strategy to stakeholders
Implementation roadmap: prioritising initiatives and milestones
workshop Design a continuity strategy for a simulated organisation
Key takeaway: A well-designed BCM strategy balances resilience with cost-effectiveness, ensuring the organisation can recover critical functions within acceptable timeframes.
RTO ¡ RPO ¡ Cost-Benefit
After-action report structure: documenting observations and lessons learned
Root cause analysis: identifying underlying issues and gaps
Corrective action plans: prioritising and tracking improvements
Continuous improvement cycle: integrating feedback into the BCM program
exercise Develop an after-action report from a sample exercise
5.4 Training & Awareness Programs
1h
Training needs analysis: identifying competency gaps
Training program design: role-based and function-specific content
Awareness campaigns: building a continuity culture across the organisation
Competency assessment: evaluating and maintaining skills
group work Design a training and awareness plan for a case organisation
Key takeaway: Regular testing, exercising, and training transform plans into capability, building confidence and competence across the organisation while identifying areas for continuous improvement.
Tabletop ¡ Simulation ¡ AAR
Leadership principles: composure, clarity, and adaptability
Decision-making frameworks: structured approaches under pressure
Managing uncertainty: dealing with incomplete information
Psychological aspects: stress management and team resilience
workshop Crisis decision-making simulation with time pressure
6.4 Crisis Communication & Stakeholder Coordination
1h
Communication strategy: internal, external, and media engagement
Message development: clarity, consistency, and empathy
Stakeholder mapping: regulators, suppliers, customers, and media
Coordination with external parties: emergency services, government, and industry bodies
case study Analyse a real-world crisis communication response
6.5 Post-Incident Review & Recovery
0.5h
Post-incident review: capturing lessons learned and best practices
Recovery transition: moving from crisis mode to business-as-usual
Impact assessment: evaluating financial, operational, and reputational consequences
Improvement planning: updating plans and procedures based on experience
Key takeaway: Effective incident management and crisis response require clear structures, decisive leadership, and transparent communication to minimise impact and accelerate recovery.
CMT ¡ Communication ¡ Leadership
Resources: Crisis management templates ¡ communication protocols ¡ decision-making frameworks
Preâwork: watch âCrisis Leadership: Lessons from Real Incidentsâ (30 min)
Case pack: CrisisCo incident management and response scenario
BCM maturity models: CMMI, ISO 22301 maturity levels, and custom models
Assessing maturity: evaluating people, process, and technology dimensions
Benchmarking practices: comparing maturity against peer organisations
Roadmap development: prioritising investments for maturity advancement
workshop Assess maturity of a case organisation and develop improvement roadmap
7.5 ISO 22301 Audit Readiness
0.5h
Certification process: stages of ISO 22301 certification audits
Documentation requirements: preparing for auditor review
Audit preparation: internal readiness checks and pre-audit activities
Maintaining certification: surveillance audits and ongoing compliance
case study Analyse an ISO 22301 certification success story
Key takeaway: Performance monitoring and continuous improvement ensure the BCM program remains effective, relevant, and aligned with organisational needs, driving maturity and resilience over time.
KPIs ¡ Audits ¡ Maturity
Module: 2 â Risk Assessment & Business Impact Analysis
Format: Individual or small group (3â4 participants)
Weight: 10% of module grade
Exercise objective
Apply the Business Impact Analysis (BIA) methodology and risk assessment techniques to a realistic business scenario.
Identify critical functions, determine recovery requirements, assess threats, and recommend continuity strategies.
Scenario
MedSupplyCo â Regional Medical Distributor
MedSupplyCo is a mid-sized medical supplies distributor serving hospitals and clinics across three states.
The company operates from a central warehouse and distribution centre, with a small corporate office on the same campus.
Key operations include:
Order processing & customer service â 12 staff, 8amâ8pm, 6 days/week
Warehouse & inventory management â 25 staff, 24/7 operations for urgent medical supplies
Logistics & distribution â 15 delivery vehicles, routing and dispatch
IT infrastructure â servers, network, and ERP system supporting all operations
Finance & administration â 8 staff, payroll, billing, and procurement
Recent disruption: A severe storm caused a 48-hour power outage at the distribution centre.
The backup generator failed after 6 hours, and the IT systems were offline for 36 hours.
The organisation is now reviewing its continuity capabilities.
Tasks
Business Impact Analysis
Complete the following BIA tasks for MedSupplyCo:
a) Identify the three most critical business functions and justify your selection.
b) For each critical function, determine:
Recovery Time Objective (RTO) â maximum acceptable downtime
Recovery Point Objective (RPO) â maximum acceptable data loss
Maximum Tolerable Downtime (MTD) â point of unacceptable impact
c) Identify critical dependencies (people, technology, suppliers, facilities) for each function.
Threat & Risk Assessment
Conduct a risk assessment focusing on the distribution centre:
a) Identify five key threats facing the distribution centre (including natural, human-caused, and technological).
b) For each threat, assess likelihood (high/medium/low) and impact (high/medium/low) on critical functions.
c) Identify vulnerabilities that were exposed during the recent power outage.
Recommendations
Based on your analysis, provide recommendations:
a) Propose three recovery strategies to address the identified risks.
b) For each strategy, estimate the approximate cost (low/medium/high) and benefit (reduction in risk).
c) Recommend priority actions for the next 3 months and next 12 months.
Submission
Prepare a 2â3 page summary covering all tasks (a, b, c for each section).
Use the BIA template provided in the resources section below.
Group submissions: include all participant names and contributions.
Due: Before the next session (submit via learning platform).
Tips for success:
Consider the financial, operational, and reputational impact of each function
Think about interdependencies â what does each function rely on?
Be realistic about cost and implementation time for recommendations
Reference ISO 22301 terminology and best practices where possible
BIA template (Excel)
Risk assessment matrix (PDF)
Reference: ISO 22301:2019, Section 8 â Operation
Hint: Watch âBIA in Practiceâ (10 min) in the course library
đ Get Certified
đ
Proven Proficiency Certificate
Your Name Here
Certified Business Continuity Management Expert ( CBCME)
Final Assessment Score: 100%
CRMNuggets • Issued October 1, 2026
đ
Earn this certificate
Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it â âŚ4,000/month.