Beyond the Locked Gate: Why Your Business Continuity Strategy Needs an Early Warning Plan
From locked gates in 1989 to emergency mass SMS today, communication has changed. Discover why your organisation needs a structured Business Continuity Warning Plan aligned with ISO 22301 and BCI GPG 7.0 to eliminate hesitation and act before disruptions escalate.
I distinctly remember walking up to my school gates one morning in 1989, only to find them locked tightly shut.

A single piece of headed paper was taped to the iron bars, flapping in the wind. It read simply: "No school today. Boiler broke."
That was the first and only time my school ever closed its doors. Apart from the immediate excitement of an unplanned day off to roam the streets of London, I thought nothing more of it.
Back then, mobile phones were non-existent on ordinary streets. It was an era when walking 30 minutes to a friend's house just to see if they were in was preferable to calling their landline and risking a conversation with their mum or older sister.
Fast forward to today, and educational institutions have evolved alongside technology. With a few keystrokes on a laptop, a school can dispatch a mass SMS to thousands of parents and students simultaneously. During the height of the COVID-19 pandemic, SMS alerts were the lifeblood of communication between my children's schools and our household.
While email remains the default for daily administrative noise, SMS remains king when you need immediate, undeniable attention. It bypasses crowded inboxes, avoids spam filters, and gets read within minutes.
Which brings me to the core question: Has the corporate world kept pace with this shift, or is your organisation still relying on the digital equivalent of a note taped to a locked gate?
This is where the Business Continuity Warning Plan comes in.
The "Wait and See" Trap
In many organisations, business continuity plans fail not because the recovery strategy was flawed, but because the trigger was pulled too late.
Without a dedicated warning framework, incident response falls victim to fatal hesitation. Operational leads spot early threat indicators—severe weather warnings, facility flooding risks, critical IT infrastructure failures, or emerging public health emergencies—and choose to "wait and see." No one wants to sound a false alarm or prematurely mobilize executive leadership.
By the time the issue escalates, the window for proactive mitigation has slammed shut. You are no longer managing an incident; you are managing a full-blown crisis.
From a compliance and standards perspective, this capability is mandatory. Under ISO 22301:2019 (Clause 8.4.3: Warning and Communication), organisations are required to maintain documented procedures for alerting interested parties of an actual or impending disruption. Similarly, the BCI Good Practice Guidelines (GPG) Edition 7.0 places Warning Plans inside PP5: Enabling Solutions. Its purpose isn't just to announce that something has broken; it is to establish clear, objective triggers that allow teams to take action before impact becomes unacceptable.
What a Modern BC Warning Plan Must Contain
Whether you align your governance with ISO 22301 auditing standards or the BCI GPG 7.0 framework, a comprehensive warning framework must address four critical elements:
Clear Triggers and Operational Thresholds
A warning plan replaces subjective "gut feelings" with predefined operational boundaries. Define exact criteria for what moves an event from standard monitoring into a Warning State:
- Facilities: Complete loss of main power or site access exceeding 30 minutes.
- IT Infrastructure: Authentication failure rates spiking past 15%, or a primary cloud provider reporting Tier-1 service degradation.
- Supply Chain: Priority suppliers reporting a 24-hour delivery delay on raw materials with zero buffer stock remaining.
Segmented Recipient Groups
You cannot send a generic broadcast to the entire company and hope the right people react in time. ISO 22301 (8.4.3) and the BCI GPG 7.0 require mapping specific, urgent messages to distinct interested parties via the channels they actually monitor:
- On-Site Personnel: Instant instructions regarding immediate physical hazards or facility evacuations.
- Remote & Off-Site Staff: Clear directions not to travel to an inaccessible office, shifting them seamlessly to home-working protocols.
- Incident Response Teams: Mobilisation or standby alerts to key decision-makers.
- Key External Stakeholders: Timely notifications to priority customers, regulatory bodies, emergency services, or suppliers.
Redundant Delivery Channels
Just as a school doesn't rely solely on a note on the gate, your organisation shouldn't rely on a single communication channel. If your corporate network or identity provider is hit by a ransomware attack or core blackout, your warning mechanism must operate independently.
Utilise multi-channel Emergency Mass Notification Systems (EMNS) capable of pushing SMS, automated voice calls, and app notifications simultaneously. For executive leadership and key incident leads who need to coordinate securely during a total primary system lock-out, establish dedicated out-of-band channels—a strategy detailed in my guide on building a Zero-Access Command Hub using secure backup email accounts.
Pre-Approved Standby Actions & Stand-Down Signals
A warning plan should outline what teams need to do while evaluating the situation—such as securing offline backups, verifying alternate site availability, or placing backup vendors on standby. Equally important is the Stand-Down Protocol: clear criteria and signals for declaring an "all clear" to prevent alert fatigue.
Testing the Triggers: Don't Wait for the Boiler to Break
A warning plan on paper is useless if your contact lists are outdated or your broadcast tools are untested.
Under ISO 22301 Clause 8.5 and BCI GPG PP6 (Validation), warning and communication capabilities must be exercised at least annually. Don't just run tabletop exercises that start after the building has exploded. Start your scenarios at the early warning stage:
"It is 07:00 AM on a Tuesday. A major transport strike has disrupted access to your primary hub, and your main data centre is running on generator power following a grid spike. What does your warning plan dictate right now?"
Run unannounced call-out cascades and SMS broadcast tests out of hours. Verify delivery rates, check response times, and update stale contact details.
Final Thoughts
Back in 1989, a note on a locked gate was acceptable. Today, in an environment of zero-tolerance downtime, instant cyber threats, and distributed workforces, relying on slow, unstructured escalation is a strategy for failure.
A well-architected Business Continuity Warning Plan—built to ISO 22301 and BCI GPG standards—gives your organisation the one resource money can't buy in a crisis: time.
