Video summary
What do Business Continuity and Cybersecurity have in common? - Wolfgang Mahr
Main summary
Key takeaways
Business continuity & cybersecurity: shared business goals
- Preparation and management commitment are central to both disciplines.
- Common enterprise goals:
- Protect the enterprise
- Reduce business impact from incidents (cyber or physical)
Governance vs. compliance (management stance)
- The speaker frames the “million-dollar question” as: Is cybersecurity/continuity just regulatory compliance, or proactive governance?
- Emphasis is placed on being proactive—management should avoid only reacting after something happens.
- Leaders are described as “captains who can weather the storm”: capable of navigating incidents and disruptions.
Impact model: why cyber requires business continuity thinking
- Cyber threats can cause long, potentially unlimited downtime and large financial impact (described as thousands to hundreds of thousands of dollars/euros).
- Even if cyber incidents are invisible (“nobody notices anything”), the damage is real—similar to fires/explosions in operational terms.
Threat dimensions framework (cyber expands the model)
- The talk suggests companies traditionally consider “three dimensions,” but cybersecurity adds more.
- It introduces new threat dimensions beyond the usual model:
- Information domain
- [“W”] in the frequency domain (as stated)
- After expansion, the total is five threats/dimensions, implying cybersecurity changes how risks are conceptualized.
Standards and ISO-style guidance as a “playbook”
- Standards are positioned as a way to manage complexity (referencing ISO 27032 training).
- Practical elements needed to make the framework work:
- Human resources
- Management commitment
- Technical equipment
- Correct setup
- The standard provides guidelines on how to handle complex situations, helping organizations:
- Know where to start
- Identify who the key players are
Process view: “project” vs. ongoing program
- In business continuity, it’s explicitly said: “it’s not a project because it never ends.”
- The program must follow organizational evolution.
- In cybersecurity, the ongoing nature is even stronger because threats are more dynamic:
- Attackers are described as thinking about new threats 24/7
- Organizations must be prepared for threats they may not currently be able to imagine
Actionable recommendations (from the discussion)
- Start with standards-based guidance and use it to reduce complexity.
- Run training/awareness to build knowledge and readiness (e.g., ISO 27032 training / raising awareness).
- Establish ownership and roles (“who the players are”) to support execution during incidents.
- Treat continuity and cybersecurity as continuous governance cycles, not one-time projects.
Key metrics / targets
- No explicit numeric KPIs (e.g., CAC/LTV/churn) were provided.
- Only qualitative impact was mentioned:
- Thousands to hundreds of thousands of dollars/euros per incident scenario
- Potentially unlimited length disruption
Presenter(s) / source(s)
- Wolfgang Mahr