Business Continuity Management, BCP and Crisis Leadership Training

A two-day programme on keeping an organisation running through disruption, and leading it when the disruption becomes a crisis. Day 1 builds the discipline: business impact analysis, recovery objectives, continuity strategy and a plan someone can actually pick up and execute. Day 2 puts participants in the crisis team, working a scenario that escalates while they run it. Aligned to ISO 22301.

Most continuity plans fail for the same reasons. They were written for an audit rather than for use, they assume the people who wrote them will be available, the recovery times were set by the plan owner rather than agreed with the business, and they have never been tested against anything harder than a walkthrough. The programme works through those failure points directly, and the Day 2 exercise is designed to surface them in participants' own arrangements rather than in a generic case study.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

Why Continuity Plans Fail

The recurring failure patterns: plans written to satisfy an auditor, untested assumptions about staff availability and supplier capacity, single points of failure nobody mapped, recovery times set without the business agreeing them, and contact lists two reorganisations out of date. Establishing what business continuity covers and how it differs from disaster recovery, incident response and crisis management, and why conflating them leaves gaps.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

The BCM Framework and ISO 22301

Policy, scope, governance and roles, and the plan-do-check-act cycle applied to a business continuity management system. How BCM connects to enterprise risk management, to cyber incident response, and to sector regulator expectations including Bank Negara's RMiT policy for financial institutions and operational resilience expectations more broadly.

05

Day 1, 11:30 AM - 12:45 PM

Business Impact Analysis

Identifying critical activities and separating them from the merely important. Mapping dependencies across people, systems, data, premises, suppliers and utilities. Setting maximum tolerable period of disruption, recovery time objective and recovery point objective, and validating them with the business rather than assuming them. Handling the department that declares everything critical, and using impact over time to force prioritisation.

06

Day 1, 12:45 PM - 1:45 PM

Lunch

07

Day 1, 1:45 PM - 2:45 PM

Threat and Risk Assessment

Working through the disruption scenarios that matter in the Malaysian operating context: flood, fire, prolonged power and telecommunications loss, cyber attack and ransomware, key supplier failure, loss of premises access, and workforce unavailability. Assessing likelihood and impact, and identifying the concentration risks that turn a single event into a multi-site outage.

08

Day 1, 2:45 PM - 3:00 PM

Break

09

Day 1, 3:00 PM - 4:00 PM

Continuity Strategy Selection

Options and their real costs: work area recovery, remote working, alternate sites, manual workarounds, cross-training, supplier redundancy and contractual continuity obligations, data backup and replication. Matching strategy to the recovery objectives set in the BIA, and being explicit when the affordable strategy cannot meet the stated RTO.

10

Day 1, 4:00 PM - 5:00 PM

Writing a Business Continuity Plan People Can Use

Plan structure, activation criteria and who holds the authority to activate. Task cards, call trees, and the discipline of writing for someone who was not in the planning workshop. Version control, distribution and offline availability, because a plan stored only on the system that just failed is not a plan. Day 1 wrap-up.

11

Day 2, 9:00 AM - 9:15 AM

Recap and Day 2 Objectives

Review of Day 1 and the structure of the exercise day.

12

Day 2, 9:15 AM - 10:30 AM

Incident and Crisis Management Structure

Standing up a crisis management team: roles, deputies and succession, escalation thresholds and who decides. The separation between operational response and executive decision-making, battle rhythm and situation reporting, decision logs and why they matter afterwards, and the handover discipline that keeps a multi-day response coherent.

13

Day 2, 10:30 AM - 10:45 AM

Break

14

Day 2, 10:45 AM - 12:00 PM

Crisis Communications

Stakeholder mapping and sequencing, holding statements and the first hour, keeping staff informed as a priority rather than an afterthought, and customer, supplier and regulator notification. Media and social media handling. Coordinating continuity communications with PDPA breach notification and, for entities within scope, cyber security incident notification to NACSA under the Cyber Security Act 2024.

15

Day 2, 12:00 PM - 12:45 PM

Crisis Leadership Under Pressure

Deciding with incomplete and contradictory information, resisting premature certainty, and recognising the cognitive traps that appear under stress. Managing team welfare, shift rotation and fatigue across a long response, and setting the tone that determines how people behave when the plan runs out.

16

Day 2, 12:45 PM - 1:45 PM

Lunch

17

Day 2, 1:45 PM - 3:15 PM

Facilitated Tabletop Exercise

A multi-stage scenario that escalates from a contained operational disruption into a full crisis with regulatory, customer and reputational dimensions. Participants form their own crisis team, activate a plan, allocate roles, communicate to stakeholders and log decisions under time pressure, with injects introduced as the scenario develops.

18

Day 2, 3:15 PM - 3:30 PM

Break

19

Day 2, 3:30 PM - 4:15 PM

Exercise Debrief and Lessons Learned

A structured hot debrief: what was decided, what was missed, where the plan failed to help and where it did. Capturing findings as owned actions rather than observations, and the discipline of closing them before the next exercise.

20

Day 2, 4:15 PM - 5:00 PM

Exercising, Maintenance and Embedding

Building an exercise programme that escalates from walkthrough to functional to full simulation, choosing frequency, and setting the triggers that force a plan review outside the annual cycle. Awareness and training, internal audit of the BCMS, and management review. Key takeaways, next steps, and close.

Key Outcomes

  • Distinguish business continuity, disaster recovery, incident response and crisis management, and know which applies when
  • Run a business impact analysis and set MTPD, RTO and RPO values the business has actually agreed
  • Select continuity strategies proportionate to impact and cost, and say so when the budget cannot meet the objective
  • Write a business continuity plan someone outside the planning team could activate
  • Stand up and run a crisis management team, including communications, decision logging and handover
  • Coordinate crisis communications with PDPA and cyber security incident notification duties
  • Design an exercise programme that finds weaknesses before an incident does

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate, suitable for BCM coordinators, risk, operations, IT, HR and facilities managers, and senior management who would sit on a crisis management team

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   Knowledge assessment covering both days, plus participation in the facilitated tabletop exercise and structured debrief

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

No. The programme is aligned to ISO 22301 and covers its framework, but it is practitioner training rather than an accredited lead implementer or lead auditor certification.

Incident Response and Digital Forensics deals with a cyber event at technical level: containment, evidence and recovery of systems. This programme is business-wide. It covers disruption from any cause and focuses on keeping critical activities running and leading the organisation through the event. Organisations facing ransomware usually need both.

Yes. For in-house delivery the Day 2 scenario is normally built around the client's own operations, sites and dependencies, which makes the debrief considerably more useful.

Yes. It is HRD Corp SBL-Khas claimable for registered Malaysian employers.