← Certified Business Continuity Management Expert ( CBCME) · Lesson 8 of 9

Module Seven

📖 Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

html Certified Business Continuity Management Expert (CBCME) ¡ Course Outline

CBCME Certified Business Continuity Management Expert

2026 ¡ v3.0
Duration: 5 days (40 hours)
Modules: 8 core + 1 capstone
Level: Advanced / Expert
Format: In-person ¡ virtual ¡ hybrid
Course overview
The CBCME program equips professionals with the strategic mindset, frameworks, and practical skills to design, implement, and continuously improve business continuity management systems. Aligned with ISO 22301 and global best practices, this expert-level course goes beyond theory—focusing on resilience, crisis leadership, and integrated risk management.
Detailed syllabus
M1 Foundations of Business Continuity 4h
  • Core concepts: BCM lifecycle, resilience, and organizational context
  • Regulatory & standards: ISO 22301, NFPA 1600, local regulations
  • BCM program governance: policy, roles, and RACI
Business impact analysis (BIA) intro Risk appetite Maturity models
M2 Risk Assessment & Business Impact Analysis 6h
  • BIA methodology: identifying critical functions, dependencies, and RTO/RPO
  • Threat & vulnerability assessment: qualitative & quantitative approaches
  • Scenario analysis: plausible disruption scenarios and impact thresholds
Maximum Tolerable Downtime (MTD) Work recovery time supply chain mapping
M3 BCM Strategy & Design 5h
  • Strategy selection: recovery, alternate sites, cloud, mutual aid
  • Resource & budget planning: cost-benefit of continuity options
  • Integration with IT DR, crisis management, and operational resilience
Hot/warm/cold sites work area recovery crisis communication
M4 Plan Development & Documentation 5h
  • BCP structure: incident response, business recovery, and IT DR plans
  • Playbooks & checklists: actionable steps for different functions
  • Plan maintenance: version control, change management, and documentation standards
BCP templates crisis playbooks communication trees
M5 Testing, Exercising & Training 5h
  • Testing methodologies: tabletop, walkthrough, simulation, and full-scale
  • Designing effective exercises: objectives, injects, and evaluation
  • Training & awareness: building a continuity culture
Exercise design after-action reports competency matrix
M6 Incident Management & Crisis Response 4h
  • Incident response lifecycle: detection, escalation, and stabilization
  • Crisis leadership: decision-making under pressure, communications
  • Coordination with external parties: regulators, media, and suppliers
Crisis team structure media handling psychological first aid
M7 Performance Monitoring & Continuous Improvement 4h
  • KPIs & metrics: measuring BCM effectiveness and readiness
  • Audit & review: internal assessment, management review, and corrective actions
  • Maturity models & benchmarking: advancing the program
BCM dashboard lessons learned ISO 22301 audit readiness
M8 BCM in the Digital Era: Resilience & Emerging Risks 4h
  • Cyber resilience: ransomware, data breaches, and business continuity
  • Supply chain & third-party resilience: managing extended ecosystems
  • Climate risk, remote work, and new disruption vectors
Digital BCM tools AI in risk ESG & continuity
CAP Capstone: BCM Program Design & Presentation 3h + presentation
  • Practical project: design a complete BCM program for a case organization
  • Peer review & expert feedback: presentation of continuity strategy
  • Integration of all modules: from BIA to governance and monitoring
Case study executive summary roadmap

Learning methodology

  • Interactive lectures
  • Group workshops
  • Real‑world simulations
  • Case‑based assignments
  • Peer‑to‑peer exchange
40 CPE / CEU credits
Assessment: Quizzes, practical exercises, capstone project, final exam
Certification: CBCME credential upon successful completion
Recertification: 3-year cycle ¡ 20 CPEs
2

Module One

html Module 2 ¡ CBCME | Risk Assessment & Business Impact Analysis
MODULE 2 ¡ CORE

Risk Assessment & Business Impact Analysis

6 hours (in‑class + workshop)
Focus: BIA ¡ threat assessment ¡ scenario analysis
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
  • Apply a structured BIA methodology to identify critical functions and dependencies
  • Determine RTO, RPO, and MTD for essential business processes
  • Conduct qualitative & quantitative threat and vulnerability assessments
  • Build plausible disruption scenarios and evaluate impact thresholds
  • Translate risk findings into actionable continuity requirements
Module content
2.1 Business Impact Analysis (BIA) framework 2h
  • BIA purpose & scope: aligning with organizational strategy
  • Identifying critical functions: process mapping and dependency analysis
  • Recovery Time Objective (RTO) & Recovery Point Objective (RPO) – calculation methods
  • Maximum Tolerable Downtime (MTD) and work recovery time
  • workshop BIA interview simulation & data collection template
2.2 Threat & Vulnerability Assessment 1.5h
  • Threat landscape: natural, human‑caused, technological, and geopolitical
  • Qualitative vs. quantitative approaches: risk matrices, scoring, and financial exposure
  • Vulnerability identification: internal weaknesses and external dependencies
  • exercise Risk register development (ISO 22301 aligned)
2.3 Scenario Analysis & Impact Evaluation 1.5h
  • Plausible disruption scenarios: building realistic and relevant cases
  • Impact assessment: financial, operational, reputational, and regulatory consequences
  • Interdependency mapping: supply chain, IT, and third‑party services
  • case study Analysing a multi‑site disruption scenario
2.4 Reporting & Integration 1h
  • BIA & risk reports: structure, executive summary, and actionable recommendations
  • Linking to strategy: translating findings into continuity requirements
  • Stakeholder communication: presenting risk to leadership and business units
  • group work Draft BIA summary for a simulated organisation
Key takeaway: A robust BIA and risk assessment provide the evidence‑based foundation for all continuity strategies and investments. RTO · RPO · MTD
Resources: BIA template ¡ risk matrix ¡ scenario library
Pre‑work: watch “BIA fundamentals” (20 min)
Case pack: ManufacturingCo disruption data
3

Module Two

html Module 2 ¡ CBCME | Risk Assessment & Business Impact Analysis
MODULE 2 ¡ CORE

Risk Assessment & Business Impact Analysis

6 hours (in‑class + workshop)
Focus: BIA ¡ threat assessment ¡ scenario analysis
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
  • Apply a structured BIA methodology to identify critical functions and dependencies
  • Determine RTO, RPO, and MTD for essential business processes
  • Conduct qualitative & quantitative threat and vulnerability assessments
  • Build plausible disruption scenarios and evaluate impact thresholds
  • Translate risk findings into actionable continuity requirements
Module content
2.1 Business Impact Analysis (BIA) framework 2h
  • BIA purpose & scope: aligning with organizational strategy
  • Identifying critical functions: process mapping and dependency analysis
  • Recovery Time Objective (RTO) & Recovery Point Objective (RPO) – calculation methods
  • Maximum Tolerable Downtime (MTD) and work recovery time
  • workshop BIA interview simulation & data collection template
2.2 Threat & Vulnerability Assessment 1.5h
  • Threat landscape: natural, human‑caused, technological, and geopolitical
  • Qualitative vs. quantitative approaches: risk matrices, scoring, and financial exposure
  • Vulnerability identification: internal weaknesses and external dependencies
  • exercise Risk register development (ISO 22301 aligned)
2.3 Scenario Analysis & Impact Evaluation 1.5h
  • Plausible disruption scenarios: building realistic and relevant cases
  • Impact assessment: financial, operational, reputational, and regulatory consequences
  • Interdependency mapping: supply chain, IT, and third‑party services
  • case study Analysing a multi‑site disruption scenario
2.4 Reporting & Integration 1h
  • BIA & risk reports: structure, executive summary, and actionable recommendations
  • Linking to strategy: translating findings into continuity requirements
  • Stakeholder communication: presenting risk to leadership and business units
  • group work Draft BIA summary for a simulated organisation
Key takeaway: A robust BIA and risk assessment provide the evidence‑based foundation for all continuity strategies and investments. RTO · RPO · MTD
Resources: BIA template ¡ risk matrix ¡ scenario library
Pre‑work: watch “BIA fundamentals” (20 min)
Case pack: ManufacturingCo disruption data
4

Module Three

html Module 3 ¡ CBCME | BCM Strategy & Design
MODULE 3 ¡ CORE

BCM Strategy & Design

5 hours (in‑class + workshop)
Focus: Recovery strategies ¡ resource planning ¡ integration
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
  • Select appropriate recovery strategies for different business functions
  • Evaluate recovery site options (hot/warm/cold) and alternative work arrangements
  • Develop resource and budget plans that balance cost and resilience
  • Integrate BCM strategy with IT disaster recovery and crisis management
  • Design a comprehensive continuity strategy aligned with organizational objectives
Module content
3.1 Recovery Strategy Selection 1.5h
  • Strategy framework: balancing speed, cost, and complexity
  • Recovery options: alternate sites, work-from-home, mutual aid agreements
  • IT recovery strategies: cloud vs. on-premise, data replication, and backup
  • People & process recovery: workforce strategies and manual workarounds
  • workshop Strategy selection matrix for a case organisation
3.2 Resource & Budget Planning 1.5h
  • Cost-benefit analysis: evaluating continuity investments
  • Resource requirements: technology, facilities, personnel, and vendors
  • Budgeting for BCM: capital vs. operational expenditure
  • ROI of resilience: quantifying the value of continuity
  • exercise Build a BCM budget for a mid-sized enterprise
3.3 Integration with IT Disaster Recovery & Crisis Management 1.5h
  • BCM vs. IT DR vs. Crisis Management: roles and interdependencies
  • Unified response framework: aligning plans and escalation procedures
  • Technology dependencies: ensuring IT recovery supports business recovery
  • Governance integration: single point of accountability and reporting
  • case study Integrating BCM and IT DR at a financial institution
3.4 Designing the Continuity Strategy 0.5h + workshop
  • Strategic alignment: linking BCM to business objectives and risk appetite
  • Strategy documentation: presenting the continuity strategy to stakeholders
  • Implementation roadmap: prioritising initiatives and milestones
  • workshop Design a continuity strategy for a simulated organisation
Key takeaway: A well-designed BCM strategy balances resilience with cost-effectiveness, ensuring the organisation can recover critical functions within acceptable timeframes. RTO ¡ RPO ¡ Cost-Benefit
Resources: Strategy selection matrix ¡ budget templates ¡ integration checklists
Pre‑work: watch “BCM Strategy Fundamentals” (25 min)
Case pack: FinancialCo strategy development scenario
5

Module Four

html Module 4 ¡ CBCME | Plan Development & Documentation
MODULE 4 ¡ CORE

Plan Development & Documentation

5 hours (in‑class + workshop)
Focus: BCP structure ¡ playbooks ¡ documentation standards
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 15% of final grade
Learning objectives
  • Structure a comprehensive Business Continuity Plan (BCP) following industry standards
  • Develop incident response, business recovery, and IT DR plan components
  • Create actionable playbooks and checklists for different business functions
  • Implement documentation standards, version control, and change management
  • Design communication trees and escalation procedures for effective response
Module content
4.1 BCP Structure & Framework 1.5h
  • BCP architecture: core components and supporting documentation
  • Plan hierarchy: corporate-level, business unit, and function-specific plans
  • Alignment with ISO 22301: documentation requirements and best practices
  • Plan distribution: accessibility, confidentiality, and stakeholder access
  • workshop Review and critique a sample BCP structure
4.2 Incident Response & Business Recovery Plans 1.5h
  • Incident response plan: detection, triage, and initial containment
  • Business recovery plan: step-by-step recovery procedures for critical functions
  • IT Disaster Recovery plan: technical recovery procedures and data restoration
  • Integration of plans: ensuring seamless transition between response and recovery
  • exercise Develop recovery procedures for a critical business function
4.3 Playbooks, Checklists & Supporting Tools 1h
  • Playbook design: actionable, role-specific guidance for responders
  • Checklist development: ensuring critical steps are not missed during an incident
  • Communication trees: contact lists, escalation paths, and notification protocols
  • Toolkits & templates: standardised forms, logs, and reporting templates
  • workshop Build a communication tree and playbook for a case scenario
4.4 Documentation Standards & Change Management 1h
  • Documentation standards: formatting, terminology, and style guides
  • Version control: managing revisions, approvals, and document history
  • Change management process: reviewing, updating, and communicating changes
  • Plan maintenance: scheduling reviews, updates, and stakeholder feedback
  • group work Establish a change management process for BCP documentation
Key takeaway: Well-documented, accessible plans with clear playbooks and checklists enable rapid, coordinated response and recovery, minimising confusion during high-stress incidents. BCP ¡ Playbooks ¡ Checklists
Resources: BCP template ¡ playbook examples ¡ communication tree templates
Pre‑work: watch “BCP Documentation Best Practices” (20 min)
Case pack: HealthcareCo BCP development scenario
6

Module Five

html Module 5 ¡ CBCME | Testing, Exercising & Training
MODULE 5 ¡ CORE

Testing, Exercising & Training

5 hours (in‑class + workshop)
Focus: Testing methodologies ¡ exercise design ¡ training & awareness
Delivery: Lecture ¡ group exercises ¡ simulation workshop
Weight: 15% of final grade
Learning objectives
  • Distinguish between different testing and exercising methodologies
  • Design and facilitate effective tabletop, walkthrough, and simulation exercises
  • Develop exercise objectives, injects, and evaluation criteria
  • Create after-action reports and implement improvement plans
  • Design training and awareness programs to build a continuity culture
Module content
5.1 Testing & Exercise Methodologies 1.5h
  • Exercise continuum: from tabletop to full-scale simulations
  • Walkthroughs & orientation: familiarisation and plan review
  • Tabletop exercises: discussion-based scenario analysis
  • Functional & full-scale exercises: operational testing and validation
  • workshop Compare and select appropriate exercise types for different scenarios
5.2 Exercise Design & Facilitation 1.5h
  • Exercise objectives: defining clear, measurable goals
  • Scenario development: creating realistic injects and storylines
  • Facilitation techniques: managing group dynamics and maintaining engagement
  • Evaluation criteria: measuring success and identifying gaps
  • workshop Design a tabletop exercise for a simulated organisation
5.3 After-Action Reviews & Improvement Planning 1h
  • After-action report structure: documenting observations and lessons learned
  • Root cause analysis: identifying underlying issues and gaps
  • Corrective action plans: prioritising and tracking improvements
  • Continuous improvement cycle: integrating feedback into the BCM program
  • exercise Develop an after-action report from a sample exercise
5.4 Training & Awareness Programs 1h
  • Training needs analysis: identifying competency gaps
  • Training program design: role-based and function-specific content
  • Awareness campaigns: building a continuity culture across the organisation
  • Competency assessment: evaluating and maintaining skills
  • group work Design a training and awareness plan for a case organisation
Key takeaway: Regular testing, exercising, and training transform plans into capability, building confidence and competence across the organisation while identifying areas for continuous improvement. Tabletop ¡ Simulation ¡ AAR
Resources: Exercise design templates ¡ after-action report templates ¡ training materials
Pre‑work: watch “Designing Effective BCM Exercises” (25 min)
Case pack: RetailCo exercise design and facilitation scenario
7

Module Six

html Module 6 ¡ CBCME | Incident Management & Crisis Response
MODULE 6 ¡ CORE

Incident Management & Crisis Response

4 hours (in‑class + workshop)
Focus: Incident response lifecycle ¡ crisis leadership ¡ stakeholder coordination
Delivery: Lecture ¡ group exercises ¡ crisis simulation
Weight: 12% of final grade
Learning objectives
  • Describe the incident response lifecycle from detection to stabilisation
  • Apply crisis leadership principles and decision-making under pressure
  • Structure and activate crisis management teams effectively
  • Develop crisis communication strategies for internal and external stakeholders
  • Coordinate response efforts with external parties, regulators, and media
Module content
6.1 Incident Response Lifecycle 1h
  • Detection & notification: identifying and reporting incidents
  • Assessment & triage: evaluating severity and impact
  • Containment & stabilisation: preventing further damage
  • Eradication & recovery: removing threats and restoring operations
  • workshop Analyse an incident timeline and identify response gaps
6.2 Crisis Team Structure & Activation 1h
  • Crisis management team (CMT): roles, responsibilities, and authority
  • Crisis command centre: physical and virtual activation procedures
  • Escalation protocols: triggers for activating the CMT
  • Team dynamics: decision-making, collaboration, and information flow
  • exercise Role-play a crisis team activation scenario
6.3 Crisis Leadership & Decision-Making 0.5h + workshop
  • Leadership principles: composure, clarity, and adaptability
  • Decision-making frameworks: structured approaches under pressure
  • Managing uncertainty: dealing with incomplete information
  • Psychological aspects: stress management and team resilience
  • workshop Crisis decision-making simulation with time pressure
6.4 Crisis Communication & Stakeholder Coordination 1h
  • Communication strategy: internal, external, and media engagement
  • Message development: clarity, consistency, and empathy
  • Stakeholder mapping: regulators, suppliers, customers, and media
  • Coordination with external parties: emergency services, government, and industry bodies
  • case study Analyse a real-world crisis communication response
6.5 Post-Incident Review & Recovery 0.5h
  • Post-incident review: capturing lessons learned and best practices
  • Recovery transition: moving from crisis mode to business-as-usual
  • Impact assessment: evaluating financial, operational, and reputational consequences
  • Improvement planning: updating plans and procedures based on experience
Key takeaway: Effective incident management and crisis response require clear structures, decisive leadership, and transparent communication to minimise impact and accelerate recovery. CMT ¡ Communication ¡ Leadership
Resources: Crisis management templates ¡ communication protocols ¡ decision-making frameworks
Pre‑work: watch “Crisis Leadership: Lessons from Real Incidents” (30 min)
Case pack: CrisisCo incident management and response scenario
8

Module Seven

html Module 7 ¡ CBCME | Performance Monitoring & Continuous Improvement
MODULE 7 ¡ CORE

Performance Monitoring & Continuous Improvement

4 hours (in‑class + workshop)
Focus: KPIs & metrics ¡ audit & review ¡ maturity models
Delivery: Lecture ¡ group exercises ¡ case study
Weight: 12% of final grade
Learning objectives
  • Define and measure KPIs and metrics for BCM effectiveness and readiness
  • Conduct internal audits and management reviews of the BCM program
  • Identify and implement corrective actions and improvement opportunities
  • Apply maturity models to assess and advance the BCM program
  • Prepare for ISO 22301 certification audits and ongoing compliance
Module content
7.1 BCM KPIs & Metrics 1h
  • Performance metrics: plan completeness, exercise success rates, and recovery capability
  • Readiness metrics: training completion, plan review frequency, and resource availability
  • Dashboard design: visualising BCM performance for leadership
  • Benchmarking: comparing performance against industry standards
  • workshop Design a BCM dashboard with key performance indicators
7.2 Internal Audit & Management Review 1h
  • Audit methodology: planning, conducting, and reporting internal audits
  • Audit criteria: ISO 22301 requirements and organisational standards
  • Management review: agenda, inputs, and outputs for effective reviews
  • Non-conformity management: identifying, documenting, and addressing findings
  • exercise Conduct a mock internal audit of a BCM program
7.3 Corrective Actions & Improvement Planning 1h
  • Root cause analysis: identifying underlying issues and their causes
  • Corrective action process: developing, implementing, and tracking actions
  • Preventive actions: proactively addressing potential issues
  • Continuous improvement cycle: PDCA (Plan-Do-Check-Act) methodology
  • workshop Develop corrective action plans for audit findings
7.4 Maturity Models & Benchmarking 0.5h + workshop
  • BCM maturity models: CMMI, ISO 22301 maturity levels, and custom models
  • Assessing maturity: evaluating people, process, and technology dimensions
  • Benchmarking practices: comparing maturity against peer organisations
  • Roadmap development: prioritising investments for maturity advancement
  • workshop Assess maturity of a case organisation and develop improvement roadmap
7.5 ISO 22301 Audit Readiness 0.5h
  • Certification process: stages of ISO 22301 certification audits
  • Documentation requirements: preparing for auditor review
  • Audit preparation: internal readiness checks and pre-audit activities
  • Maintaining certification: surveillance audits and ongoing compliance
  • case study Analyse an ISO 22301 certification success story
Key takeaway: Performance monitoring and continuous improvement ensure the BCM program remains effective, relevant, and aligned with organisational needs, driving maturity and resilience over time. KPIs ¡ Audits ¡ Maturity
Resources: Audit checklists ¡ KPI dashboards ¡ maturity assessment templates
Pre‑work: watch “Building a BCM Performance Dashboard” (20 min)
Case pack: TechCo BCM program review and improvement scenario
9

Practice Exercise

html Practice Exercise ¡ CBCME | Risk Assessment & BIA
PRACTICE EXERCISE

BIA & Risk Assessment Workshop

60 minutes ¡ individual or group
Module: 2 – Risk Assessment & Business Impact Analysis
Format: Individual or small group (3–4 participants)
Weight: 10% of module grade
Exercise objective

Apply the Business Impact Analysis (BIA) methodology and risk assessment techniques to a realistic business scenario. Identify critical functions, determine recovery requirements, assess threats, and recommend continuity strategies.

Scenario

MedSupplyCo – Regional Medical Distributor

MedSupplyCo is a mid-sized medical supplies distributor serving hospitals and clinics across three states. The company operates from a central warehouse and distribution centre, with a small corporate office on the same campus. Key operations include:

  • Order processing & customer service – 12 staff, 8am–8pm, 6 days/week
  • Warehouse & inventory management – 25 staff, 24/7 operations for urgent medical supplies
  • Logistics & distribution – 15 delivery vehicles, routing and dispatch
  • IT infrastructure – servers, network, and ERP system supporting all operations
  • Finance & administration – 8 staff, payroll, billing, and procurement

Recent disruption: A severe storm caused a 48-hour power outage at the distribution centre. The backup generator failed after 6 hours, and the IT systems were offline for 36 hours. The organisation is now reviewing its continuity capabilities.

Tasks

Business Impact Analysis

Complete the following BIA tasks for MedSupplyCo:

  • a) Identify the three most critical business functions and justify your selection.
  • b) For each critical function, determine:
    • Recovery Time Objective (RTO) – maximum acceptable downtime
    • Recovery Point Objective (RPO) – maximum acceptable data loss
    • Maximum Tolerable Downtime (MTD) – point of unacceptable impact
  • c) Identify critical dependencies (people, technology, suppliers, facilities) for each function.

Threat & Risk Assessment

Conduct a risk assessment focusing on the distribution centre:

  • a) Identify five key threats facing the distribution centre (including natural, human-caused, and technological).
  • b) For each threat, assess likelihood (high/medium/low) and impact (high/medium/low) on critical functions.
  • c) Identify vulnerabilities that were exposed during the recent power outage.

Recommendations

Based on your analysis, provide recommendations:

  • a) Propose three recovery strategies to address the identified risks.
  • b) For each strategy, estimate the approximate cost (low/medium/high) and benefit (reduction in risk).
  • c) Recommend priority actions for the next 3 months and next 12 months.
Submission
  • Prepare a 2–3 page summary covering all tasks (a, b, c for each section).
  • Use the BIA template provided in the resources section below.
  • Group submissions: include all participant names and contributions.
  • Due: Before the next session (submit via learning platform).
Tips for success:
  • Consider the financial, operational, and reputational impact of each function
  • Think about interdependencies – what does each function rely on?
  • Be realistic about cost and implementation time for recommendations
  • Reference ISO 22301 terminology and best practices where possible
BIA template (Excel)
Risk assessment matrix (PDF)
Reference: ISO 22301:2019, Section 8 – Operation
Hint: Watch “BIA in Practice” (10 min) in the course library

🏆 Get Certified

🔒

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it — ₦4,000/month.

🎓 Sign Up & Unlock for ₦4,000/month
🛠️ Practice Tools
Hands-on simulators & labs - subscription required.
→
🎯 Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
→