BCM
Business Continuity Management
Betriebliches Kontinuitätsmanagement / Notfallmanagement
BCM is the organised preparedness that ensures a company remains capable of acting during and after a serious disruption — such as a cyberattack — and can maintain or quickly restore critical processes. It answers the question „What do we do if it happens anyway?“. At the latest, ransomware has forced BCM from theory into lived practice.
History & facts. BCM encompasses more than technology: it begins with an impact analysis (which processes are how critical, how long may they be down?) and culminates in emergency plans, responsibilities, communication paths and technical restart planning (disaster recovery, DR). Closely connected is a well-thought-out backup strategy (such as the 3-2-1 principle) with separate, ideally non-overwritable backups — because modern ransomware specifically targets the backups in order to prevent recovery. Decisive but often neglected: plans must be practised, otherwise they fail in an emergency.
Outlook & recommendation. Security means not only preventing but also surviving. Regulation such as Network and Information Security Directive 2 (NIS2) explicitly requires precautions for business continuity and crisis management. Recommended are realistic restart objectives, regular recovery tests, backups kept offline or immutable and rehearsed procedures — including the question of how to communicate without one's own IT. NEOSEC combines technical incident response (DFIR) with restart planning so that an attack does not become an existential crisis.