practice

Business Impact Analysis

Determining which business processes must be restored, how quickly, and what the consequence of not doing so is — the input from which recovery targets are derived.

Recovery targets are frequently set by engineering judgement, which means they are set without knowing what the business actually needs. The impact analysis supplies that, and it is a business exercise with technical participation rather than the reverse.

For each business process it establishes: the impact of unavailability over time — often non-linear, with a threshold beyond which consequences escalate sharply; the maximum tolerable outage; the maximum tolerable data loss; dependencies, including third parties and people; and any regulatory requirement for recovery capability.

From that, RTO and RPO fall out per process rather than being invented, and they are properly tiered: payments and checkout differ from internal reporting by orders of magnitude, and a uniform target is therefore either ruinously expensive or inadequate.

Three findings this exercise reliably produces:

Dependency chains nobody had mapped, where a "tier 3" system turns out to be required by a tier 1 process.

Manual and people dependencies — a recovery procedure that requires a specific individual, or a supplier with no contractual recovery commitment.

Stated targets that have never been tested, and whose real values are therefore unknown and reliably worse than documented.

Continuity is broader than technical recovery: it includes people, premises, suppliers and communication, and an architecture-only plan is a partial one.