Reactive structures

From disruption to crisis

Organisations face a wide range of threats, and for economic or other reasons not all of them can be prevented in advance. Depending on the potential severity of the event, disruption, emergency and crisis management together with business continuity management (BCM) serve to handle events reactively and to mitigate their impact.

This lesson covers Sections 9 and 10 of DIN SPEC 14027 and shows how organisations build resilient response structures, from the everyday incident to the existence-threatening crisis.

Your learning objectives

After this lesson you will be able to:

  • draw a clean line between disruption, emergency and crisis.
  • explain the difference between the standing organisation and a special response organisation (BAO).
  • name the obligations of crisis team work in crisis management.
  • describe the role of the BIA and the BCP in business continuity management.

The escalation logic: three levels of response

A precise distinction between disruptions, emergencies and crises is not always possible, yet it is decisive for the right response. Incidents can develop dynamically over time: an escalating emergency can turn into a crisis that the standing organisation can no longer handle.

The extent of damage usually rises in step with the incident category: while damage from relatively frequent disruptions is low, very rare crises can reach existence-threatening proportions.

Basic principle: whereas disruptions are handled within the standing organisation through predefined procedures, emergencies and crises require a special response organisation in the form of dedicated emergency or crisis teams.

Key terms from practice:

Disruption
An incident that causes unplanned, negative deviations in achieving the objectives of business processes. The response takes place within the standing organisation through predefined procedures. Frequent, with a low extent of damage.
Emergency
An event with an anticipatable course whose handling requires plannable measures (emergency plans) that go beyond regular operational routines. It takes over the tactical and operational management of a damaging event.
Crisis
An exceptional, cross-cutting damaging incident with serious and possibly existence-threatening effects on employees, processes, resources and reputation. Handled with the help of a crisis team organisation. Rare, with a very high extent of damage.
Special response organisation (BAO)
A time-limited organisational form for extensive and complex tasks, particularly on special occasions that cannot be handled within the standing organisation. (Source: BBK)
BIA – business impact analysis
An analysis focusing on the consequences of a failure of resources (personnel, infrastructure, IT, OT) for the organisation's ability to deliver. The basis for prioritising time-critical processes.
BCP – business continuity plan
A plan drawn up on the basis of the BIA and the risk analysis to secure the functioning and operability of prioritised processes. An important support for disruption, emergency and crisis management.

Disruption, emergency and crisis management (Section 9)

Despite all preventive measures, damaging events can occur and impair an organisation's ability to function. To mitigate and control the effects, an organisation needs reactive structures. Beyond that, regulatory requirements may exist that call for such structures.

The organisation must implement, document and communicate measures that at least secure the following areas:

  • responsibilities of the organisation's top management
  • preparation
  • response
  • follow-up and assurance of effectiveness
  • education and training

The requirements of DIN SPEC 14027 are operational minimum standards for crisis management and are consistent with DIN EN ISO 22361 (crisis management – guidelines).

Deep dive

The following sections explore the essential building blocks of reactive structures in more depth.

Disruption management (Annex A.9.1)
Disruption management handles incidents within the standing organisation. Its central components are: a list of potentially relevant disruptions (derived from protection needs and risk analyses) and standardised disruption plans for each scenario. A disruption plan covers at least the scope and objectives, the responsible person, the immediate measures to be implemented, the resources required, a reporting matrix and escalation to emergency and crisis management. In addition, reporting and escalation processes with thresholds are to be defined. All disruptions should be documented centrally in the incident and damage database.
Emergency management (Annex A.9.2)
Emergency management focuses on the immediate response to an incident through which individual processes or resources do not function as intended, life and limb are at risk and/or business operations are impaired. The course of the event can be anticipated, so the steps for handling it can be planned (emergency plans). Core elements: emergency plans for every relevant scenario, an emergency manual, defined emergency teams with clear powers to act (including technical and financial ones), reporting, escalation and alerting processes, and suitable infrastructure. Important: the safety of employees in the sense of occupational health and safety is governed not by this document but by the rules of the state and the statutory accident insurers.
Crisis management and crisis team work (Annex A.9.3)
A crisis is more complex than an emergency, because its course and the steps required to handle it are difficult or impossible to anticipate and therefore call for a flexible, strategic response. The central instruments are the crisis management plan (CMP) and the crisis management organisation (CMO) including the crisis team or BAO. The CMP must be updated at least once per financial year and governs, among other things, the tasks and responsibilities of the crisis team, the appointment of competent members and deputies (functionally, not hierarchically), activation and alerting channels, the course of crisis team work and audit-proof documentation. Decision-making processes should follow a predefined command scheme (situation / measures / decisions / review of effectiveness / documentation, for example). The alerting process for crisis teams must be assured at all times (24/7).
Crisis team infrastructure
Suitable physical and digital infrastructure (a crisis room) must be established for all crisis teams, including decentralised ones. Spatial shielding, technical protection against eavesdropping and access control are to be taken into account. Minimum requirements include redundant means of communication (several telephone lines, Wi-Fi, video conferencing equipment), laptops with security and encryption software, access to a secured server, means of visualisation (projector, whiteboard, magnetic boards), voice recording and appropriate equipment for longer deployments. Crisis teams should be able to work in multiple shifts.

Business continuity management (Section 10)

Organisations can be affected by events that have far-reaching effects on tangible and intangible assets and consequently interrupt value creation or the fulfilment of their tasks. During such events, the preparations made by business continuity management (BCM) can secure the stability of the organisation and its time-critical processes and speed up the restart of the parts of the organisation affected.

BCM aims at a cultural change: embedding resilience towards such events in the organisational culture. When emergencies or existence-threatening risks (crises) occur, the organisation then meets them in a prepared state.

The continuous BCM cycle

The organisation should run its BCM as a continuously improving cycle. This consists of the phases:

  • framework conditions and organisation
  • implementation of a BCMS
  • validation and further development

The requirements of DIN SPEC 14027 are operational minimum standards and are consistent with DIN EN ISO 22301. Organisations should attach great importance to their suppliers and service providers implementing effective BCM measures too, in order to secure the stability of supply chains and services in times of crisis as well.

Deep dive

Business impact analysis (BIA)
Within BCM, a business impact analysis is carried out, focusing on the consequences of a failure of resources for the delivery of the organisation's services. Common examples of resources to be considered are personnel, infrastructure, information technology (IT) and operational technology (OT). The BIA identifies time-critical processes and supplies key figures such as the RTO (recovery time objective), the MTPD (maximum tolerable period of disruption), the RPO (recovery point objective) and the minimum service level in contingency operation.
Risk analysis and solution development
On the basis of the BIA results, a risk analysis is carried out for the time-critical processes identified, capturing internal and external threats. Solutions for continuity and restart are then planned. Solutions must be examined for at least the following failure scenarios: building and infrastructure failure, IT and OT failure, loss of personnel, service provider failure and production failure. The aim is to develop a suitable solution for every time-critical process in every failure scenario.
Business continuity plans (BCP)
The business continuity plans drawn up on the basis of the BIA and the risk analysis secure the functioning and operability of prioritised processes and provide important support for disruption, emergency and crisis management. A BCP includes, among other things: defined failure scenarios, key figures (RTO, MTPD, RPO, planned restart time), rules for activation, clear roles and responsibilities, business continuity measures, information on the resources required, escalation processes, measures for returning to normal operation and important contacts.
Interlocking BCM and risk management
BCM and disruption, emergency and crisis management are closely linked and work hand in hand to strengthen the organisation's resilience. The interlocking with risk management is just as close: risk management identifies, analyses, evaluates and treats risks that could affect the organisation. This information is decisive for BCM in developing and implementing solutions and BC plans.

The key points in brief

  • Three escalation levels: disruption (standing organisation), emergency (plannable, emergency teams) and crisis (not anticipatable, crisis team organisation) – the extent of damage rises in step with the incident category.
  • Standing organisation vs. BAO: disruptions are handled in regular operations, while emergencies and crises require a special response organisation with dedicated crisis teams.
  • Crisis team work: crisis management rests on a crisis management plan (CMP), 24/7 alerting capability, a structured command scheme and audit-proof documentation.
  • BCM as the foundation: the business impact analysis (BIA) identifies time-critical processes, and the business continuity plans (BCP) secure their continuity and restart.
  • Standards referenced: crisis management follows DIN EN ISO 22361, BCM follows DIN EN ISO 22301.

A look ahead to the next lesson

In Lesson 6 – Specific protection we go deeper into individual topic-specific fields of action: know-how, product and prototype protection, personal protection for exposed individuals, event security, travel security and the risk-based protection of the supply chain.