Security Management

Business Continuity Planning for Physical Security Disruptions

Builds ISO 22301-aligned business continuity plans that address physical security disruptions such as facility denial, civil unrest and protest, from impact analysis through recovery strategy and exercising.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

A cyberattack rarely closes a building, but a protest blocking site access, a fire denying entry to a facility or civil unrest around a regional office can stop operations just as completely, and continuity plans written only for IT outages often leave physical security scenarios untested. This course builds business continuity plans specifically for physical security disruptions, following ISO 22301 structure: running a business impact analysis that quantifies the cost of facility denial, designing recovery strategies including alternate sites and remote work activation, writing plans that assign clear roles to security, facilities and business unit leaders, and exercising the plan against realistic disruption scenarios. Sessions include a business impact analysis workshop scored against sample facilities, an alternate site activation exercise, and a full-scale tabletop covering a multi-day access denial scenario. Participants leave with a business impact analysis template, a recovery strategy comparison tool and an exercise programme calendar aligned to ISO 22301 requirements.

Expected Learning Outcomes

01

Run a business impact analysis that quantifies the cost of losing physical facility access.

02

Prioritise recovery time objectives for critical activities disrupted by a security incident.

03

Design recovery strategies including alternate sites, remote work and vendor support arrangements.

04

Write continuity plans that assign clear activation authority and role ownership.

05

Align the continuity programme structure with ISO 22301 planning and review requirements.

06

Design and run exercises that test the plan against realistic physical disruption scenarios.

07

Update continuity plans and strategies based on exercise findings and real incident lessons.

Who Should Attend

01

Business continuity managers who plan for physical security disruption scenarios.

02

Corporate security leaders coordinating continuity planning with facilities and IT.

03

Facilities managers responsible for alternate site and access recovery arrangements.

04

Risk managers assessing the operational impact of facility denial or civil unrest.

05

Business unit leaders who own recovery time objectives for their critical activities.

06

Emergency management coordinators who design and run continuity exercises.

Course Modules

Select any module to see its sessions and points.

01

Business Impact Analysis for Physical Disruption

2 sessions · 8 points

Session 1Quantifying the Cost of Facility Denial

  • Identify critical activities that stop or degrade when a facility becomes inaccessible.
  • Quantify financial, contractual and reputational impact for each hour of facility denial.
  • Set recovery time and recovery point objectives for critical activities and supporting systems.
  • Rank activities by combined impact and dependency to focus recovery planning effort.

Session 2Mapping Dependencies and Single Points of Failure

  • Map dependencies between critical activities, facilities, staff and third-party providers.
  • Identify single points of failure such as one access route or one control room.
  • Assess concentration risk where multiple critical functions share one physical location.
  • Feed dependency findings into recovery strategy and mitigation prioritisation.
02

Recovery Strategy Design

2 sessions · 8 points

Session 1Selecting Recovery Strategies

  • Compare alternate site, remote work and vendor-supported recovery strategies by cost and speed.
  • Match recovery strategy choice to the recovery time objective of each critical activity.
  • Plan for partial facility loss scenarios distinct from total site denial.
  • Document underlying assumptions and constraints behind each selected recovery strategy.

Session 2Preparing Alternate Sites and Remote Access

  • Prepare alternate sites with pre-positioned equipment, access credentials and security arrangements.
  • Test remote access and communication tools intended for use during a facility disruption.
  • Agree service terms with vendors providing surge space or equipment during recovery.
  • Review alternate site and remote access readiness on a scheduled maintenance cycle.
03

Plan Development and Governance

2 sessions · 8 points

Session 1Writing Actionable Continuity Plans

  • Assign activation authority and named role owners for each continuity plan action.
  • Write plan steps as concrete actions rather than general statements of intent.
  • Cross-reference the continuity plan with security incident and crisis management procedures.
  • Store plans where they remain accessible even if primary systems are unavailable.

Session 2Aligning with ISO 22301 Programme Structure

  • Structure the continuity programme around ISO 22301 planning, implementation and review stages.
  • Set a management review cycle that evaluates programme performance against objectives.
  • Maintain documented evidence of planning decisions for internal or external audit.
  • Integrate continuity programme governance with wider enterprise risk management reporting.
04

Exercising and Continual Improvement

2 sessions · 8 points

Session 1Designing Realistic Disruption Exercises

  • Design tabletop and functional exercises around plausible physical disruption scenarios.
  • Set exercise objectives that test both plan content and participant decision-making.
  • Introduce realistic complications during the exercise to test plan flexibility.
  • Schedule exercises to cover different disruption types across the annual programme.

Session 2Capturing and Applying Lessons

  • Facilitate a structured debrief that captures gaps between the plan and exercise performance.
  • Assign owners and deadlines for corrective actions identified during the exercise.
  • Update the business impact analysis when exercise findings reveal new dependencies.
  • Report exercise outcomes and improvement progress to continuity programme governance.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course