Skip to content
atlas

Business impact analysis (BIA)

Also known as: BIA

A study of what an outage or incident would do to the business, and how long each activity can be down.

Draft - this entry has not been reviewed yet.

Formal

A structured review of each business activity that estimates the harm of its disruption over time and sets how quickly it and the systems it depends on must be restored.

In plain English

Like a restaurant asking which hurts more if it breaks, the oven or the coffee machine, and how many hours it could cope without each.

In practice

At a shipping company, the risk manager interviews each department and learns that payroll can wait three days, but the freight booking system starts losing customers after one hour.

Why it matters

Without it, recovery plans guess at what to restore first; with it, money and effort go to the activities whose loss hurts most, and every continuity plan has a clear basis.

Technical deep dive

A business impact analysis is deliberately cause-agnostic: it does not ask what might go wrong or how likely it is, only what happens to each activity when it stops and how that damage grows over time. That is the line between a BIA and a risk assessment, which pairs threats and vulnerabilities with likelihood. ISO 22301:2019 clause 8.2.2 requires the organisation to define impact types and criteria, identify the activities that deliver its products and services, assess impacts over time, set prioritised time frames for resuming each activity, and identify the dependencies and resources behind them, including suppliers. ISO/TS 22317:2021 gives detailed guidance; NIST SP 800-34 Rev. 1 describes a system-level BIA for contingency planning.

The core outputs are time parameters. The maximum tolerable period of disruption (MTPD in ISO terms, MTD in NIST SP 800-34) is the point after which impact becomes unacceptable. The recovery time objective (RTO) is the target for resuming an activity or restoring a system and must sit inside the MTPD with margin; the recovery point objective (RPO) is the maximum acceptable data loss expressed as time, which drives backup and replication frequency. ISO also uses the minimum business continuity objective (MBCO), the reduced service level acceptable during disruption. The chain must be consistent: an activity with a four-hour RTO cannot rest on a system restored in 24 hours or a supplier with next-business-day support.

BIAs are usually run as interviews or questionnaires with process owners, scoring impact categories (financial, customer, legal and regulatory, reputational, health and safety) at time points such as 1 hour, 4 hours, 1 day, 3 days and 1 week. Impact curves are rarely linear: payroll is harmless for days and then critical just before pay day, so peak periods must be captured. Dependency mapping then walks from activities to applications, data, infrastructure, people, sites and third parties, which is where hidden single points of failure such as a shared identity provider surface.

Typical failure modes are owners declaring every process critical with an RTO of zero, IT-led BIAs that list systems instead of business activities, RTOs never compared with actual recovery capability, and analyses not refreshed after reorganisations or SaaS migrations. Regulation now names the BIA explicitly: DORA (Regulation (EU) 2022/2554) Art. 11(5) requires financial entities to conduct a BIA of their exposure to severe business disruptions, and NIS2 Art. 21(2)(c) requires business continuity and disaster recovery measures for which a BIA is the practical basis.

What to learn first

Everything this builds on, foundations first.

  1. Asset inventory
  2. →Availability
  3. →CIA triad
  4. →Asset
  5. →Critical assets
  6. →Impact
  7. →Business impact analysis (BIA)

Relationships

Sources & further reading

Standards & official texts

  • ISO 22301:2019

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.