Book Notes: James Crask’s Business Continuity Management

Essential book notes and key frameworks from James Crask’s Business Continuity Management, distilled for practitioners preparing for the CBCI and building a BCMS.

Paul O'Brien
9 min read
Dark-themed cover image featuring a protective shield with a glowing heartbeat pulse line symbolizing business continuity and resilience.
Book notes on James Crask's Business Continuity Management.

Key takeaways, frameworks, and practical insights from James Crask's guide to organisational resilience—distilled for beginners and studied alongside the CBCI course and BCI Good Practice Guidelines.

When preparing for the CBCI exam and refining our internal BCMS, the BCI Good Practice Guidelines provided an essential theoretical baseline—but standard guidelines only get you so far. To bridge the gap between GPG theory and real-world execution, I needed a practical operational field guide.

That search led me to James Crask’s Business Continuity Management: A Practical Guide to Organisational Resilience and ISO 22301. Reading Crask’s book alongside my CBCI preparation was a complete game-changer. He strips away the dry, standard-centric dogma and reframes continuity as a dynamic, human-centric strategy, making it my highest recommended read for anyone in the resilience space.

Dark-themed graphic featuring a stylised cover of James Crask's Business Continuity Management alongside a quote by Paul O’Brien recommending the book for resilience professionals.
Endorsement quote from my book review of James Crask's Business Continuity Management.

If you want to grab your own copy to study alongside your preparation or to build out your professional library, you can purchase it directly from the publisher on the Kogan Page website.

To help make this vital topic accessible to fellow practitioners and newcomers, I’ve distilled my favourite frameworks, key lessons, and real-world takeaways from the book into the notes below. Whether you are prepping for the CBCI, building your very first BCMS, or working to protect your organisation during a disruption, I hope this serves as a practical roadmap.

1. The Philosophy: From Static Plans to Adaptive Resilience

In today’s volatile landscape, Business Continuity (BC) is far more than a checklist or a manual on a shelf. It is a foundational pillar of Organisational Resilience. While BC represents the specific capability to resume operations after a hit, Resilience is the strategic outcome—a state of "Adaptive Capacity" that allows an organisation to not only absorb shocks but to evolve because of them.

The history of industry is a Darwinian struggle of adaptation. James Crask illustrates that survival belongs to the agile, citing brands that survived by treating disruption as a catalyst for evolution:

  • Nokia: Transformed from 19th-century paper mills into a global telecommunications titan.
  • Toyota: Successfully pivoted from manufacturing weaving machines to automotive leadership.
  • Peugeot: Evolved from a flour mill into engineering, bicycles, and eventually cars.
  • Wrigley’s: Originally a soap and baking soda vendor, they pivoted entirely to chewing gum after realising the "free gift" they offered was more popular than their main product.

The Two Modes of Operation

To build resilience, you must first recognise which "mode" your organisation is currently occupying.

Value-Creation Mode (Business as Usual) Value-Protection Mode (Disruption Response)
Focuses on executing the business plan, growth, and strategy. Focuses on maintaining or recovering only the most critical activities.
Operates under predicted, "normal" conditions. Triggered by a negative deviation from expected objectives.
Objective: Profitability and market expansion. Objective: Survival, capital protection, and returning to normalcy.

Key Insight: The "Immune System" Analogy

Crask invites us to view an organisation’s systemic health as an immune system. A healthy system—one with sound strategic foundations—can survive a "virus" (a crisis). However, a weakened system, burdened by poor strategic decisions or hidden vulnerabilities, may find that same crisis fatal. Effective BCM acts as your white blood cells, but your baseline "health" dictates your ultimate survival.

💡
Newbie Takeaway: Current Mode Assessment
Assessment 1: Is your team currently focused on long-term growth, strategic KPIs, and daily business-as-usual delivery? (If so, you are operating in Value Creation Mode).
Assessment 2: Has a sudden, unexpected event forced your team to abandon daily tasks to protect core services and safeguard life safety? (If so, you are operating in Value Protection Mode).

Understanding why resilience matters is the first step; building it requires a rigorous, repeatable process to systematically strengthen that "immune system".

2. The 5-Step BCM Lifecycle: A Practical Roadmap

BCM is not a one-off project; it is a continuous lifecycle. This five-step roadmap ensures your recovery arrangements remain relevant as the world changes around you.

  1. Analyse: The foundational phase. You conduct a Business Impact Analysis (BIA) to determine which activities are truly "critical" and must be prioritised.
  2. Design: Here, you develop the recovery strategies. You identify exactly what you need (staff, IT, locations) to keep those critical activities alive.
  3. Implement: Only after the analysis is complete do you write the plans. This step formalises your strategies into actionable, documented procedures.
  4. Improve: A cycle of management reviews, audits, and exercises to validate that your plans actually work under pressure.
  5. Embed: This is the "glue" that holds the entire system together. Without a resilient culture, the best plans are useless.
    • Awareness: The essential bond; ensuring every staff member knows their specific role during a disruption.
    • Culture: Transitioning the organisation from a "compliance" box-ticking exercise to a state of genuine readiness.

Deep Dive: The Dangers of Skipping the "Analyse" Phase The "Analyse" phase is the only place to start. Many newcomers are tempted to skip straight to "Implement" because writing a plan feels like progress. However, a plan created without a BIA is a house built on sand; it will likely miss critical dependencies and fail exactly when you need it most.

💡
Newbie Takeaway: Actionable First Step The Conversation Box:
Schedule a 15-minute meeting with the head of Operations or Risk. Ask: "What are the three activities we do that, if stopped for 24 hours, would cause intolerable damage to our reputation or capital?" Their answer is the start of your "Analyse" phase.

While the lifecycle provides the roadmap, your daily operational success depends on how accurately you categorise the threats coming over the horizon.

3. Operational Mechanics: Incidents, Crises, and Disruptions

Precise language is vital. In the heat of a response, ambiguity regarding the severity of an event leads to a breakdown in command.

Category Definition Nature of Response
Incident An event that could lead to a crisis (e.g., a localised IT glitch). Fast-paced, operational, focused on containment.
Crisis An extraordinary situation threatening the organisation’s viability. Strategic, board-level, high-stakes decision-making.
Disruption The actual negative deviation from objectives (the "down-time"). Recovery-focused; using plans to restore services.

The "Management Effort vs. Time" Logic An Incident requires immediate, high-intensity operational work to stop the bleeding. A Crisis requires strategic, long-term input from the Board. Business Recovery is the sustained, often slower effort to return the organisation to its pre-event state.

Synthesis: 3 Questions to Spot a Crisis

  1. Management Input: Does this require the CEO to stop their "day job" to focus on this single event?
  2. Viability Threat: Does this threaten our very ability to stay in business?
  3. Ordinary vs. Extraordinary: Does this require decisions that fall entirely outside our standard operating procedures?
💡
Newbie Takeaway: Trigger Checklist Escalate to the Board immediately if:
The event involves a threat to life or a major environmental hazard.
We have no pre-existing plan for this specific category of event.
The media is calling, and a standard response will not suffice.

Once an event is escalated, the board will demand to know exactly how much time we have to recover—a question answered only by a rigorous BIA. (Note: updated "Board" to lowercase "board" to match standard UK editorial style, unless referring to a specific entity like "The Board of Directors").

4. The Blueprint for the Business Impact Analysis (BIA)

The BIA identifies your Critical Activities. It moves beyond guesswork to establish the exact point at which a disruption becomes fatal.

Analogy Corner

  • MTPD (Maximum Tolerable Period of Disruption): If you are baking a cake, this is the moment the oven has been off so long that the batter is ruined. It is the absolute, "drop-dead" deadline.
  • RTO (Recovery Time Objective): This is your ambition. It is your target time to be back up. To allow for error and a safety buffer, your RTO must always be shorter than your MTPD.
  • RPO (Recovery Point Objective): Like saving a video game, this is about data. If the power cuts, how much "progress" are you willing to lose? If you save every 10 minutes, your RPO is 10 minutes.

Resource Mapping: The 5 Core Dependencies

  1. People: The "must-have" specialists for recovery.
  2. IT & Data: The most critical dependency. In 2019, the US Federal Reserve processed 15 trillion transactions. This statistic proves the "manual workaround" is a myth; modern volume makes manual recovery impossible.
  3. Property: Easy to visualize (fire/flood) but increasingly mitigated by remote work.
  4. Third Parties: Critical suppliers outside your direct control.
  5. Assets: Specialised machinery (e.g., a "rolling road") that represents a single point of failure.

Newbie Takeaway: BIA Quick-Start

Activity Dependency Impact of 24hr Outage
Payroll HR Data / Banking Software Critical: Staff stop working if not paid.
Customer Support VOIP / CRM Access High: Immediate loss of customer trust.

Once you have mapped the internal dependencies of your BIA, you must look outward to the supply chain partners that keep those processes alive.

5. Supply Chain Resilience: Efficiency vs. Security

Modern lean manufacturing relies on "Just-In-Time" (JIT) delivery. While efficient, it is dangerously fragile.

Agility over Rigidity: The Nissan Example Following the 2011 Japanese earthquake, Nissan recovered significantly faster than Toyota or Honda. Their advantage wasn't just a plan; it was Agility. Nissan maintained a more flexible supply chain, allowing them to pivot to alternative sources while competitors remained locked into rigid, single-source models.

Synthesis: Supplier Tiering Your greatest risk is often "invisible." You may know your Tier 1 supplier, but a failure three levels deep (Tier 3) can still stop your production. Resilience requires mapping the sub-suppliers who provide the raw materials.

💡
Newbie Takeaway: The Procurement Question Ask your Procurement lead today: "If our primary supplier went bankrupt tomorrow, do we have an alternative source pre-vetted, or are we starting a 6-month tender from scratch?"

Contract Checklist

  • [ ] Right to Audit: Can we legally inspect their BCM arrangements?
  • [ ] BCM Requirements: Are they contractually mandated to have a recovery plan?
  • [ ] Notification Period: Are they obligated to tell us immediately if they suffer an incident?

Even the most robust operational plans will fail without the political and financial air cover that only high-level governance can provide.

6. Governance & Leadership: Speaking the Board’s Language

To gain Board attention, you must shift the conversation from "compliance" to Capital Protection and Risk Management.

The Three Lines of Defence Model

  1. 1st Line (Operations): Owns the risk and does the daily work.
  2. 2nd Line (Risk/BCM): The specialists (you) who provide frameworks and oversight.
  3. 3rd Line (Internal Audit): The independent "checks and balances" layer.

CFO Language: Insurance Optimisation The Board cares about the bottom line. Frame BCM as Insurance Optimisation: by demonstrating a lower risk profile and robust recovery plans, the organisation can negotiate lower insurance premiums and reduce the overall cost of risk.

💡
Newbie Takeaway: The Elevator Pitch "I'm leading an initiative to ensure our most profitable services remain resilient. By protecting our capital through BCM, we aren't just following a standard—we’re optimising our insurance costs and ensuring [Competitor] can't steal our market share if the grid goes down."

This leadership logic was put to the ultimate test during the global pandemic of 2020.

7. Post-Pandemic Realities: Lessons from COVID-19

The pandemic was a "wake-up call" that proved many narrow, building-focused plans were obsolete.

Myth vs. Reality

  • Myth: "We have a plan for every scenario."
  • Reality: We don't need a "Virus Plan"; we need creative scenario stress-testing that assumes all physical access is denied simultaneously.

The Lesson of "Behavioural Fatigue" A major lesson from the UK government’s response was the danger of assuming "behavioural fatigue"—the idea that people would tire of safety measures. In reality, behavioural science shows that safety behaviours receive far greater uptake when the situation is perceived as urgent. Carrying on as normal undercuts that urgency and costs lives.

Human-Centric Risks The shift to remote work replaced "office risk" with new challenges:

  • Mental Health: Isolation and "bedroom offices" impacted productivity.
  • Technology Stress: Home Wi-Fi became a critical business dependency.
💡
Newbie Takeaway: Future-Proofing Checklist
Stress-Test Remote Access: Can 100% of the workforce log in simultaneously?
Diverse Scenarios: Have we exercised for "Loss of People" (mass illness) alongside "Loss of Building"?
Welfare Integration: Does our plan include specific triggers to check on staff mental wellbeing?

A Rewarding Path

Business Continuity Management is a career for the inquisitive. It offers the rare opportunity to bridge the gap between the "boiler room and the boardroom." For those who enjoy solving logical puzzles under pressure, there is no role more vital to an organisation’s long-term survival.

Wrapping Up: Resilience is a Journey, Not a Destination

Embarking on the journey to establish a Business Continuity Management System can feel like a massive mountain to climb, especially when you are parsing the Good Practice Guidelines or studying for your CBCI exam for the first time. But if James Crask’s book teaches us anything, it is that building resilience isn't about creating flawless, static documents—it is about building an adaptive capacity, training your people, and fostering a culture that knows how to pivot when the unexpected happens.

These summary notes are just the beginning of my own learning journey, and I am committed to sharing the practical insights, templates, and lessons I pick up along the way.

Get the Printable PDF Study Companion

I’ve compiled these comprehensive book notes into a beautifully designed, print-ready PDF companion guide. It includes all the matrices, checklists, and a high-resolution version of our Incident vs. Crisis Management Effort Chart so you can print it out, save it to your tablet, or use it to study alongside your CBCI and GPG coursework.

Your Turn: What is Your Biggest BCMS Hurdle?

Are you currently working on your own BCMS, or preparing for the CBCI? What has been your biggest hurdle so far? Let’s learn in public together—drop your thoughts in the comments below!