Business Impact Analysis
Structured BIA with criticality scoring, recovery priority ranking, and RTO/RPO definitions for every critical service. Linked directly to your asset register and service dependencies.
Connect recovery plans, critical services, dependencies and test evidence so continuity planning reflects the real operating environment.

Business continuity plans live in Word documents that nobody reads. Impact analyses are done once and never updated. DR exercises are either skipped or produce findings that go untracked.
Structured BIA with criticality scoring, recovery priority ranking, and RTO/RPO definitions for every critical service. Linked directly to your asset register and service dependencies.
Visualise recorded service, supplier and infrastructure dependencies. Review the graph for missing links and possible single points of failure before using it for DR planning.
Plan, execute and document tabletop or technical recovery exercises. Track failed tests and findings through remediation; assess the evidence against your applicable ISO 22301, NIS2 or DORA obligations.
ICT continuity strategies documented and linked to critical services. Backup and restore validation with RTO/RPO compliance checking. Management review integration.
Fig Group connects business impact analysis, service dependencies, continuity plans and recovery exercises. Begin with the activities the business needs to sustain, then agree recovery priorities and test whether the people, suppliers and technology can meet them.
Identify critical services, their owners and how disruption affects customers, staff and obligations over time. Record dependencies on people, premises, information, systems and suppliers. Use these impacts to agree recovery priorities and the minimum acceptable service during disruption.
The recovery time objective sets the target time to restore an activity or service. The recovery point objective sets the acceptable data-loss window. Agree both with service owners and check whether dependencies, backups and recovery arrangements can support them. Document a gap when an exercise misses the target; a target is not proof of recovery capability.
Choose a credible disruption, name participants and success criteria, and record what actually happens. A tabletop checks decisions and coordination; a controlled technical recovery test checks a different part of readiness. Assign owners and due dates to findings, retest material fixes and review the plan after significant service or supplier changes.
A fictional order-processing exercise assumes a fallback supplier can operate during a cloud outage. Participants discover that the fallback uses the same unavailable identity service. Record the failed dependency assumption, assign an alternative access arrangement and retest it before treating the recovery target as demonstrated.
Ask to trace a service from impact analysis and dependencies to its recovery plan, exercise result and outstanding improvement actions. Confirm where technical restore execution takes place.
Discuss this workflow with FigThis asset mind map view shows the wider Fig environment. Ask us to demonstrate business continuity & dr against your own requirements.
A tailored walkthrough lets you review the relevant workflows, supported connections and reporting before deciding whether Fig is right for your team.
See it in a demo

Bring delivery, oversight and assurance together without losing sight of who owns the next action.

Standardised BCDR across client portfolios. Exercise scheduling, finding management, and service dependency views for every client.
Explore Fig for MSPs
Board-ready continuity reporting. Service dependency graphs show real exposure. DR exercise results feed directly into compliance evidence.
Explore Fig for organisations
Link BIA, strategy, exercise results, findings and management review. Confirm dependency coverage and whether a failed recovery test has been resolved before assessing applicable ISO 22301, NIS2 Article 21 or DORA requirements.
Discuss your requirementsStart with the outcomes you need. We will discuss scope, delivery and commercial terms with you before you commit.
Bring its current plan, service owner, impact assessment and key dependencies. Agree recovery objectives and fallback responsibilities.
Define the disruption, participants, safety constraints, expected decisions and evidence to retain. Confirm who can authorise a live recovery test.
Compare observed results with the objectives. Assign improvements, update the plan and verify the significant fixes in a follow-up exercise.
Platform functionality and automation depend on the agreed scope, configuration and connected systems. Software supports your compliance programme; it does not replace an independent assessment or guarantee certification.
Need to discuss a specific requirement or client scenario?
Speak to FigRecorded DR exercise failures can create follow-up work and affect mapped control assessments. Dependency views can link to available asset and supplier records; review missing links and verify a failed recovery test after remediation.
Fig Group structures your continuity planning in the platform with version control, review cycles, and evidence linking. You can import existing plans and add governance workflows on top.
Use the continuity workflow to organise evidence relevant to requirements such as ISO 22301 and, where applicable, NIS2 or DORA. Agree the applicable obligations and assessment scope with your advisers. Cyber Essentials certification covers its own technical controls and does not certify your business continuity plan.
Yes. Plan tabletop or live exercises with defined scenarios, assign roles, track actions during execution, and document findings. Remediation actions are tracked through to closure with full audit trails.
Fig Group builds dependency views from connected asset records, integrations and manual input. Potential single points and cascade effects depend on the completeness of those links; service owners should validate the graph and recovery assumptions.
A business-continuity plan describes how to maintain priority activities during disruption and restore normal operation safely. Start with service impact and dependencies, agree recovery objectives and test the fallback with the people who will use it.
Use the guide and templateTell us what you would like to achieve. We will arrange a relevant conversation about the platform, your requirements and the right next step.
Continue exploring the protect capabilities, or return to the full platform overview.