Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Risk

Business Impact Analysis (BIA)

A Business Impact Analysis (BIA) is the exercise that determines, for each business activity and the systems and suppliers it depends on, the consequences of its interruption or degradation over time, and derives from them the recovery objectives (maximum tolerable downtime, recovery time and recovery point objectives) and a criticality level. It is the bridge between the business and the risk register: the criticality it assigns is what a cyber risk scenario inherits when it hits that activity.

Activities first, systems second

A BIA that starts from the application inventory produces a criticality per server that no executive can arbitrate. A BIA that starts from the value chain, the activities that make and deliver the product, then maps each to its supporting systems, data and suppliers, produces a criticality the business recognizes as its own. The dependencies are the point: a low-profile ticketing system becomes critical the day the BIA shows that order intake stops without it.

The objectives it produces

For each activity, the maximum tolerable period of disruption, the recovery time objective the continuity plan must meet, the recovery point objective the backups must respect, and the minimum service level during degraded operation. These numbers set the requirements for continuity and disaster recovery, but they also calibrate impact in the risk analysis: an availability scenario on an activity with a four-hour tolerance is scored differently from one with a week.

In NIS2 and DORA

Business continuity, backup management and crisis management are among the NIS2 risk-management measures; DORA requires financial entities to identify and classify their ICT-supported business functions and to run a business impact analysis of their exposure to severe business disruptions, feeding the response and recovery plans. A BIA kept current, per activity and per entity, is what both frameworks assume exists, and what most groups only rebuild during an audit.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.