
July 2024. Three days of torrential rain turn an industrial hub into one vast lake. Three companies operating in the same business park are flooded: an electronics manufacturer, a logistics firm and an IT service provider. Similar scale of damage, similar financial losses, similar insurance cover. Three weeks later, one of the companies is operating normally. The other two are still fighting for survival. What set them apart?
The electronics component manufacturer had no business continuity plan. Instead, it had insurance and the conviction that “we’ll manage somehow.”
When the water receded, it turned out that nobody knew what to do first. The COO tried to contact suppliers, the CEO negotiated with the insurer, the IT department rescued the servers, and production ground to a halt – because nobody knew whether the machines could be started up without a technical inspection. A key client rang after 72 hours to ask about the status of their order. The answer was: “We don’t know.”
The contract with that client – worth several million a year – was not renewed. The company resumed production after six weeks. By then, some clients already had new suppliers.
The logistics company took the matter more seriously. It had internal contingency procedures, trained staff and a list of alternative subcontractors. However, one thing was missing: regular testing of these procedures and an up-to-date BIA.
The procedures had been written three years earlier – when the company had half its current fleet and a completely different customer base. The key employee responsible for coordinating emergency operations had left the company a year earlier. No one had updated the documentation or trained a successor. The contacts for alternative carriers were out of date – some of the companies no longer existed. The company resumed operations after four weeks. The losses were less than those of the manufacturer, but several customers left anyway – because at a critical moment the company was unable to guarantee deliveries.

The IT service provider held ISO 22301 certification. What did this mean in practice?
As soon as the water began to threaten the facility, the business continuity plan was automatically triggered. The data had already been replicated to the backup data centre – in line with the RPO set at 4 hours. Key personnel knew exactly what to do and who was responsible for what. Customers were contacted within 6 hours of the incident – with information on the status of their services and the expected time of resumption.
After 48 hours, the company was operating at reduced capacity. After 72 hours – at full capacity. Not a single customer left. One of them – a large financial firm – expanded its partnership a month later, precisely because the provider had proven its resilience under real-world conditions.
The difference lay not in the scale of the damage or the budget for recovery. It lay in the fact that one company had spent several years building the system, testing it, updating it and involving the entire staff in it. When push came to shove – the system worked.
ISO 22301 is not a magic shield against floods, fires or cyberattacks. It is a system that ensures that, when an incident occurs, the company knows what to do, who makes the decisions, how to communicate with customers, and in what order to restore processes.
Three elements that determined the success of the third company:
→ Companies that hold ISO 22301 certification are not better than others simply because crises do not affect them. They are better because, when a crisis strikes, they are prepared for it. And it is precisely during a crisis that it becomes clear whether a customer will stay with you for years to come or switch to a competitor.