Legal & compliance centre

HLD Group

Business continuity plan

Continuity during and after operational disruption.

Last updated: 24 July 2026

Version 1.9 · Review cycle: 365 days · View all frameworks

1. Purpose

This Business Continuity Policy establishes HLD Group’s framework for maintaining and restoring the delivery of critical products and services at acceptable predefined levels following a disruptive incident. It sets the requirements for business impact analysis, continuity strategy, crisis management, and exercising.

The objective is organisational resilience: the ability to anticipate, prepare for, respond to, and adapt to incremental change and sudden disruption in order to survive and prosper. This policy gives effect to that objective and to our obligations to customers who depend on the continuity of our services.

2. Scope

This policy applies to all HLD Group business functions, services, personnel, facilities, technology, and third-party dependencies whose disruption would materially affect the delivery of products and services or our legal and contractual obligations. It operates together with the Backup and Recovery Policy and the Disaster Recovery Policy, which provide the technical recovery capability this policy relies on.

3. Definitions

  • Business continuity — the capability to continue delivery of products and services within acceptable time frames at predefined capacity during a disruption
  • Business impact analysis (BIA) — the process of analysing the impact over time of a disruption on the organisation
  • Maximum tolerable period of disruption (MTPD) — the time after which the impact of not resuming an activity becomes unacceptable
  • Recovery time objective (RTO) — the target time within which a service is resumed after disruption
  • Recovery point objective (RPO) — the maximum tolerable period in which data might be lost
  • Minimum business continuity objective (MBCO) — the minimum level of service acceptable during disruption
  • Crisis management team — the group that directs the organisation’s response to a major disruption

4. Policy statement

HLD Group maintains a business continuity management system proportionate to the nature and scale of our operations and the needs of our customers. We identify our critical activities, understand the impact of their disruption, put strategies and plans in place to continue or recover them, and validate those plans through exercising. Business continuity is owned at executive level and is not delegated away as a purely technical concern.

5. Business impact analysis

A business impact analysis is conducted and maintained to identify critical activities, their dependencies, and the impact of their disruption over time. The BIA sets the recovery objectives that drive continuity strategy and technical recovery design.

  • Critical services are identified and prioritised into recovery tiers
  • For each, the MTPD, RTO, and RPO are defined and agreed with the business and reflected in customer commitments
  • Dependencies — cloud providers, telecommunications, key vendors, people with rare skills, and facilities — are documented
  • Tier 1 services: RTO 4 hours, RPO 1 hour where feasible
  • Tier 2 services: RTO 24 hours
  • Tier 3 services: best effort within 72 hours

6. Continuity strategies

Continuity strategies are selected to meet the recovery objectives set by the BIA, balancing cost against risk reduction.

  • Multi-region and multi-zone architecture for Tier 1 services, with tested failover
  • Geographically separated, immutable backups as described in the Backup and Recovery Policy
  • Redundant DNS and network paths, and independent alternate communication channels for the response team
  • Remote-work capability so essential staff can operate without access to a specific office
  • Cross-training and documented runbooks to reduce single points of human failure
  • Contractual continuity and exit assurances from critical vendors

7. Crisis management and incident response structure

A crisis management team comprising executive leadership, the CISO, operations, and communications is activated on declaration by the CEO or CISO. The team directs the response, allocates resources, authorises deviations from normal process, and owns internal and external communications.

  • Clear activation criteria and an on-call escalation path are maintained
  • Roles, delegations, and succession are defined so the response does not depend on any one individual
  • Decision logs are kept during an event to support later review and any regulatory reporting
  • Customer and regulator communications follow pre-approved playbooks and contractual timeframes

8. Continuity plans

Documented continuity and recovery plans are maintained for critical activities. Plans are concise, actionable under stress, and stored so they remain accessible when primary systems are unavailable, including in an offline form.

  • Activation triggers and authority to invoke
  • Roles, contact details, and succession
  • Step-by-step recovery actions and validation criteria
  • Internal and external communication templates
  • Dependencies and vendor escalation contacts

9. Exercising and testing

Plans are validated through a programme of exercises. An untested plan is treated as an assumption, not a capability.

  • Tabletop exercises at least annually, covering realistic scenarios
  • Technical failover tests for Tier 1 services at least every 18 months
  • Post-exercise reviews capturing findings, which feed the risk register and drive plan updates
  • Exercise evidence retained for audit and customer assurance

10. Framework alignment

  • ISO 22301:2019 (business continuity management systems)
  • ISO/IEC 27031 (ICT readiness for business continuity)
  • ISO/IEC 27001:2022 Annex A control 5.29 (information security during disruption) and 5.30 (ICT readiness for business continuity)
  • NIST SP 800-34 Rev. 1 (contingency planning)
  • SOC 2 Trust Services Criteria availability category (A1.2, A1.3)

11. Roles and responsibilities

Executive sponsor

Owns organisational resilience, approves this policy and recovery objectives, and can declare a crisis.

Business continuity coordinator

Maintains the BIA, plans, and exercise programme, and reports readiness to leadership.

Service and function owners

Define recovery objectives for their services, maintain runbooks, and participate in exercises.

All personnel

Know how to raise an incident and follow continuity instructions during a disruption.

12. Exceptions, enforcement, and review

Exceptions require documented CISO approval with compensating controls and an expiry date. Failure to maintain continuity capability for an owned service is a performance and compliance matter. This policy is reviewed at least annually and after any major disruption, significant organisational change, or material change to critical dependencies.

Related frameworks

For contractual attestations or audit packs, contact [email protected].