A Business Impact Analysis (BIA) is a structured process for identifying an organization's critical functions, assessing the consequences of disruptions, and prioritizing recovery efforts to guide contingency planning. It helps organizations allocate resources where they matter most by defining impact categories, tolerance thresholds, and recovery requirements for essential systems.
Business Impact Analysis
To create a contingency plan there's quite a bit of investment into it. What I mean by that is there's quite a bit of time invested into that, and planning and testing to make sure that you get it right. We had better make sure that we're putting all of our time and effort into the right areas, and one of the ways we do that is through a business impact analysis.
There's a lot of things that could happen to our business: anything from an earthquake, which causes physical damage, or perhaps it's an attacker, maybe it's malware, maybe it's ransomware that encrypts all of our data, maybe it's a fire in the data center. There's a lot of things that could happen to our business, but to plan for all of those could be very costly. So which ones do we plan for? Which ones do we need to make sure that we invest the most amount of time into? A business impact analysis will allow us to determine what are some of the most important processes within our business, and which are the ones that we should really focus on.
With a business impact analysis, what we do is start out by defining what the impact categories are, and also the impact levels. We would define that as a company based off of how much risk we're willing to take on. Then we'll identify critical processes within the company, we'll determine the outage impacts that those could have, we'll estimate downtime, and we'll also identify resource requirements that we have within the business and within our organisation. Then we identify recovery priorities for those system resources. So that's all that goes into a business impact analysis.
The first step is to define impact categories. This is going to be specific to whatever business that you have, and here are some examples. I described this as the impact that cyber crime could have on the business, but these are examples of impact categories as well: things like loss of revenue, loss of assets, fines in relation to some sort of compliance, or judgments, cost for notifications, maybe loss of competitive advantage, loss of reputation. So here are just some examples of those impact categories.
The next step is to associate some sort of level with each one of these categories. So here is loss of revenue, and we could consider a loss of revenue maybe under 75,000 is minimal, versus moderate would be 75,000 to a million, and severe would be over a million. So we take a look at what the levels of revenue are and associate some sort of level of the impact to the business.
The next step is to identify essential functions to the business. Here we're identifying mission critical processes. So just as an example, maybe invoicing customers, because invoicing means that we're getting paid; we're asking the customers for money, we're asking them, "hey, you owe this amount of money to us", so that's pretty important. Maybe paying vendors is also a mission critical process. Also shipping products — we want to ship products to our customers so they can get the product in time.
Then, with each one of our categories — one of our categories was loss of revenue, one of them was loss of reputation — what would we have happen if these processes couldn't be carried out? So for instance, invoicing customers: we wouldn't get paid for the services that we're delivering, so that would be pretty severe. Same thing if we're not shipping product to them; they're going to get mad at us, so that's going to be pretty severe. Versus paying our vendors: maybe the loss of revenue is pretty minimal in that case right there, but we might have a moderate in loss of reputation, because now our vendors are not going to be happy with us.
If these processes went down — so invoicing customers and we couldn't invoice customers, or we couldn't pay our vendors, or shipping our products to our customers — if that were to happen, then what we need to do is figure out how long is acceptable with each one of these. So for instance, we've got an MTD, or maximum tolerable downtime: how long can this process be down? So invoicing customers, maybe we say we don't want to go more than 24 hours without this capability, because that could really hurt our business.
We also have a recovery point objective and recovery time objective that we'd associate with each one of these. I'm not going to get into those right now, I'll do that in another lesson, but we're going to essentially set some boundaries as to what's acceptable for these processes to be down, where we couldn't actually do these processes.
Then, for each one of those processes or functions that we've identified that are critical functions for the business, next we have to identify resources that are required to carry out those functions. So for instance, if we're talking about payment processing, we need to bill our customers, so we are going to make sure that the invoicing system is up — that's a system that might be necessary to send them a bill. Then they're going to go to our web server and process the billing; they're going to go onto the web server and then enter in maybe their credit card information, so we need some sort of payment processing system up and running. These may be three separate systems that have to be up and running for us to get paid for the services that we're delivering to our customers.
Then we can start analysing these different resources and figuring out how long these resources can be down. If we want to get paid, maybe we have the recovery time objective — how long this can be down — for the web server maybe is just 2 hours, maybe the payment processing can be 3 hours and the invoicing 4 hours. So we've set this bar now of how long these resources can be unavailable.
As you can see here, we might have different services have different recovery levels as well. There might be more critical services that we get up and running sooner, and some other functionality that maybe we don't need right away, we just need to have it sometime soon. So we can determine individually for each one of these services different levels of recovery that we're going to have.
One other thing that we really need to assess with all of this is the impact from these events on privacy. Privacy is a hot topic right now, and making sure that we keep customer data.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →