Video summary

What do Business Continuity and Cybersecurity have in common? - Wolfgang Mahr

Main summary

Key takeaways

Business

Business continuity & cybersecurity: shared business goals

  • Preparation and management commitment are central to both disciplines.
  • Common enterprise goals:
    • Protect the enterprise
    • Reduce business impact from incidents (cyber or physical)

Governance vs. compliance (management stance)

  • The speaker frames the “million-dollar question” as: Is cybersecurity/continuity just regulatory compliance, or proactive governance?
  • Emphasis is placed on being proactive—management should avoid only reacting after something happens.
  • Leaders are described as “captains who can weather the storm”: capable of navigating incidents and disruptions.

Impact model: why cyber requires business continuity thinking

  • Cyber threats can cause long, potentially unlimited downtime and large financial impact (described as thousands to hundreds of thousands of dollars/euros).
  • Even if cyber incidents are invisible (“nobody notices anything”), the damage is real—similar to fires/explosions in operational terms.

Threat dimensions framework (cyber expands the model)

  • The talk suggests companies traditionally consider “three dimensions,” but cybersecurity adds more.
  • It introduces new threat dimensions beyond the usual model:
    • Information domain
    • [“W”] in the frequency domain (as stated)
  • After expansion, the total is five threats/dimensions, implying cybersecurity changes how risks are conceptualized.

Standards and ISO-style guidance as a “playbook”

  • Standards are positioned as a way to manage complexity (referencing ISO 27032 training).
  • Practical elements needed to make the framework work:
    • Human resources
    • Management commitment
    • Technical equipment
    • Correct setup
  • The standard provides guidelines on how to handle complex situations, helping organizations:
    • Know where to start
    • Identify who the key players are

Process view: “project” vs. ongoing program

  • In business continuity, it’s explicitly said: “it’s not a project because it never ends.”
  • The program must follow organizational evolution.
  • In cybersecurity, the ongoing nature is even stronger because threats are more dynamic:
    • Attackers are described as thinking about new threats 24/7
    • Organizations must be prepared for threats they may not currently be able to imagine

Actionable recommendations (from the discussion)

  • Start with standards-based guidance and use it to reduce complexity.
  • Run training/awareness to build knowledge and readiness (e.g., ISO 27032 training / raising awareness).
  • Establish ownership and roles (“who the players are”) to support execution during incidents.
  • Treat continuity and cybersecurity as continuous governance cycles, not one-time projects.

Key metrics / targets

  • No explicit numeric KPIs (e.g., CAC/LTV/churn) were provided.
  • Only qualitative impact was mentioned:
    • Thousands to hundreds of thousands of dollars/euros per incident scenario
    • Potentially unlimited length disruption

Presenter(s) / source(s)

  • Wolfgang Mahr

Original video