← University
Testing and Exercising Your Continuity Plan
0 of 4

A business continuity plan dated 18 months earlier sits in a 3-ring binder on a shelf in the operations manager's office at a regional food processing facility in southern Alberta. The document runs to 47 pages and includes emergency contact trees, supplier backup arrangements, IT recovery procedures, and protocols for relocating production to a secondary site if the main facility becomes unusable. The plan was developed over 6 months by a cross-functional team that included the operations manager, the plant supervisor, the IT coordinator, and a consultant retained for the project. When completed, the chief executive signed off on it and the board of directors received a summary at their quarterly meeting. Since then, the plan has remained untouched.

The facility processes and packages agricultural products for distribution to grocery chains across western Canada. It employs 83 full-time staff and operates 2 production shifts, 5 days per week. The organization's primary risks include equipment failure, supply chain disruption, food safety incidents requiring product recall, and loss of access to the facility due to fire, flood, or severe weather. The continuity plan addresses each of these scenarios in varying levels of detail, with the most comprehensive section devoted to IT system recovery and the least developed section covering manual workarounds for production equipment failure.

In the months since the plan was finalized, several changes have occurred that the document does not reflect. The IT coordinator who helped develop the plan left the organization 8 months ago and was replaced by a new hire who has never seen the continuity documentation. 3 of the 12 suppliers listed in the backup arrangements have changed their terms or ceased operations. The secondary production site identified in the plan, a partner facility 140 kilometres away, underwent a change in ownership and the informal agreement that underpinned the relocation protocol was never formalized in writing. The emergency contact tree includes direct phone numbers for 4 employees who have since departed.

The operations manager has begun raising concerns with senior leadership about the plan's reliability. A near-miss incident 2 weeks ago, when a power surge caused a 4-hour production stoppage, revealed that staff were uncertain about escalation procedures and that the documented backup generator startup sequence did not match the actual equipment configuration. No formal exercise or test of the continuity plan has ever been conducted. The chief executive has asked the operations manager to propose a testing approach that can be completed within the current fiscal quarter without disrupting production schedules or requiring significant additional budget allocation.

Using Exercise Results to Improve the Plan and the Organization

Every continuity exercise produces information, but not every organization knows what to do with it. The gap between conducting an exercise and actually improving organizational resilience represents one of the most significant failures in business continuity management across Canadian enterprises. A tabletop discussion that surfaces communication weaknesses, a walkthrough that reveals outdated contact lists, or a full simulation that exposes supply chain vulnerabilities all generate valuable insights—but those insights decay rapidly if they are not captured, analyzed, and translated into concrete improvements. The discipline of using exercise results to strengthen both the continuity plan and the broader organization is what separates mature risk management programs from compliance-driven checkbox activities.

The foundation for this improvement process rests on a straightforward principle: exercises exist not to validate plans but to test them, and testing implies the genuine possibility of discovering inadequacy. Organizations that approach exercises hoping everything will go smoothly have fundamentally misunderstood their purpose. The International Organization for Standardization, through ISO 22301 on business continuity management systems, emphasizes the requirement for organizations to evaluate exercise performance and use findings to drive continual improvement. As of the date of authorship, this standard applies broadly across Canadian industries and provides the internationally recognized framework that many regulators, insurers, and contracting parties reference when assessing continuity capabilities. The standard explicitly requires documented evidence of exercise evaluation and subsequent corrective action, creating an audit trail that demonstrates genuine organizational learning rather than mere exercise completion.

Canadian organizations operate within a patchwork of federal and provincial requirements that may mandate business continuity planning in various contexts. The Personal Information Protection and Electronic Documents Act requires organizations to implement security safeguards appropriate to the sensitivity of personal information, and regulators have increasingly interpreted this to include continuity provisions for systems handling such data. Financial institutions supervised by the Office of the Superintendent of Financial Institutions must maintain business continuity plans under Guideline B-10, which specifically addresses operational resilience. Healthcare organizations across provinces face accreditation requirements under Accreditation Canada that include emergency management and business continuity elements. Construction companies working on critical infrastructure may face contractual continuity requirements from public sector clients. Resource extraction operations in Alberta, British Columbia, and Saskatchewan often must demonstrate continuity capabilities to maintain regulatory approvals. Across all these contexts, the common thread is that conducting exercises alone does not satisfy obligations—demonstrating that exercise results lead to improvement does.

The practical work of translating exercise results into organizational improvement begins during the exercise itself, not afterward. Trained observers assigned to watch specific aspects of the response—communications flow, decision-making processes, resource deployment, or technical system performance—generate contemporaneous notes that capture details lost to memory within hours. These observers should be distinct from participants, enabling them to focus entirely on documentation rather than response activities. Many smaller organizations lack the personnel to dedicate to pure observation roles, and in those cases, designating one participant to maintain a time-stamped log of key events, decisions, and challenges provides an acceptable alternative. The log should capture what was attempted, what worked, what failed, and what was unclear rather than merely recording that activities occurred.

The immediate post-exercise period, typically called the hot debrief, represents a critical opportunity to capture raw impressions while they remain vivid. Gathering all participants within minutes of exercise conclusion and asking open questions about what surprised them, what frustrated them, and what they would do differently generates candid responses that become more guarded or rationalized as time passes. These sessions should be facilitated by someone other than the exercise designer, as participants may hesitate to criticize elements if the designer is leading the discussion. The facilitator should explicitly invite criticism and create psychological safety for honest assessment. Organizations that treat hot debriefs as celebrations of successful completion rather than investigative sessions squander their most valuable opportunity for honest feedback.

The formal after-action review extends the hot debrief into a structured analytical process conducted in the days following the exercise. This review examines whether exercise objectives were achieved, how performance compared to established recovery time objectives and recovery point objectives, what gaps existed between planned and actual responses, and what root causes explain any shortfalls. The analysis should distinguish between issues arising from plan deficiencies, training gaps, resource limitations, or external factors beyond organizational control. A plan that correctly identifies required actions but that participants failed to execute because they had not been trained presents a different problem than a plan that omits critical steps entirely. Similarly, performance that met targets under exercise conditions may not predict performance during an actual disruption when stress, incomplete information, and competing demands affect judgment.

The after-action report formalizes findings in a document that serves multiple purposes. It provides evidence of exercise completion for regulatory or contractual compliance, creates institutional memory that survives personnel turnover, establishes baseline performance against which future exercises can be measured, and most importantly, identifies specific corrective actions with assigned owners and deadlines. The report should not read as a general narrative of what happened but rather as a diagnostic document that identifies problems, proposes solutions, assigns responsibility, and establishes timelines. Vague findings like "communications could be improved" provide no basis for action, while specific findings like "the emergency contact list for third-party logistics providers contained three discontinued phone numbers and lacked email addresses for backup contacts" enable precise remediation.

Consider a mid-sized social services organization based in Ottawa that conducted a tabletop exercise simulating a ransomware attack affecting its client management database. The organization, which operated programs across the National Capital Region serving approximately four thousand vulnerable clients annually, had developed its continuity plan eighteen months earlier with external consulting assistance. The tabletop brought together the executive director, operations manager, information technology coordinator, two program managers, and the organization's part-time privacy officer for a ninety-minute session in November 2025.

The exercise scenario posited that staff arriving on a Monday morning discovered encrypted systems and a ransom demand. Participants were asked to walk through their response decisions at various stages: initial discovery, assessment of impact, notification decisions, service continuity measures, and recovery planning. The exercise revealed that while the plan clearly identified the executive director as the crisis decision-maker, it provided no guidance for situations where she was unavailable—and in fact, she was scheduled to be leading a conference presentation in Halifax during a three-day period the following month. The plan specified that client services would continue using paper-based backup procedures, but participants discovered that intake staff had never been trained on paper procedures and that the required forms had last been printed in 2019. The privacy officer noted that the plan's notification procedures referenced the federal privacy commissioner but did not address whether Ontario's privacy commissioner had jurisdiction over certain provincial funding arrangements or whether Quebec's Commission d'accès à l'information required separate notification given that some clients resided across the provincial border in Gatineau.

The IT coordinator revealed during discussion that the organization's backup systems had been moved to a different cloud provider six months earlier, but the plan still referenced the former provider and the credentials for the new system were known only to the IT coordinator. Participants debated whether they would actually pay a ransom and discovered that board members had never discussed this question, that the organization lacked cyber insurance that might guide such decisions, and that the executive director was uncertain about legal restrictions on ransom payments. The operations manager observed that the plan assumed staff would work remotely during facility disruption but that several program staff lacked reliable home internet access and that client confidentiality requirements might prohibit certain remote work configurations.

The hot debrief immediately following the exercise generated frank acknowledgment that the plan was substantially out of date and that assumptions made during its development no longer held. Participants expressed concern that if an actual attack occurred in its current state, the organization would struggle to maintain services to vulnerable clients while managing recovery. The executive director committed to treating continuity planning as a governance priority rather than an administrative task.

The after-action review conducted over the following two weeks examined each gap identified during the exercise and traced its root cause. The analysis revealed several patterns. First, the plan had been created as a one-time project rather than an ongoing program, with no designated owner responsible for keeping it current. Personnel changes, technology changes, and operational changes had accumulated without triggering plan updates. Second, the plan addressed some issues at a generic level without sufficient operational detail for staff to actually execute procedures. Knowing that paper-based backup procedures existed differed fundamentally from knowing where forms were located, how they should be completed, and how data would eventually be re-entered into restored systems. Third, the plan had been developed primarily with input from management and IT without sufficient involvement from frontline program staff who would actually implement alternative procedures. Fourth, the governance and legal dimensions of continuity—board authority, ransom payment policies, regulatory notifications, insurance coverage—had received less attention than operational and technical dimensions.

The corrective action plan that emerged from this analysis assigned specific improvements to specific individuals with specific deadlines. The executive director agreed to present a business continuity governance framework to the board at the January 2026 meeting, including a recommended position on ransom payments and a request for authority to procure cyber insurance. The operations manager took responsibility for developing detailed paper-based service delivery procedures with input from program staff and for conducting training sessions by the end of January 2026. The IT coordinator agreed to update all technical documentation, verify backup systems, and establish a secondary person with backup access credentials. The privacy officer committed to clarifying notification obligations across relevant jurisdictions and updating the plan's notification procedures accordingly. The executive director designated the operations manager as the ongoing plan owner responsible for quarterly reviews and for triggering updates whenever significant operational or technology changes occurred.

This scenario illustrates how exercise results, properly analyzed, reveal not just plan deficiencies but organizational weaknesses. The Ottawa social services organization did not merely need to update a document—it needed to establish governance structures for continuity decision-making, create training programs for alternative procedures, assign ongoing ownership for plan maintenance, and procure insurance coverage appropriate to its risk exposure. The exercise identified specific technical gaps like outdated contact information, but more importantly, it exposed systemic issues around accountability, training, governance, and risk transfer that required organizational rather than merely editorial responses.

The improvement process extends beyond the immediate corrective action plan to include measuring whether improvements actually enhance resilience. Organizations should track whether identified gaps are closed within established timelines, but closure alone does not guarantee effectiveness. A revised procedure documented in the plan is not validated until personnel demonstrate ability to execute it. Updated contact information is not useful until someone verifies that the contacts respond appropriately. New governance authorities are not functional until decision-makers understand them. Follow-up exercises, whether comprehensive or targeted at specific areas of concern, validate that improvements achieved their intended effects.

Mature organizations integrate exercise findings into broader risk management activities. If exercises consistently reveal that certain departments struggle with continuity procedures, this may indicate underlying operational issues—inadequate staffing, poor documentation practices, or insufficient management attention—that affect daily operations as well as crisis response. If exercises reveal excessive dependence on specific individuals whose absence creates critical gaps, this informs succession planning and cross-training priorities beyond the continuity context. If exercises expose uncertainty about regulatory obligations, this may prompt broader compliance reviews. The exercise program thereby feeds into organizational improvement that extends well beyond the continuity plan itself.

Documentation of the complete improvement cycle—from exercise findings through corrective actions to validation of effectiveness—serves multiple purposes. For regulatory compliance, it demonstrates the continual improvement that standards like ISO 22301 explicitly require. For insurance purposes, it provides evidence of proactive risk management that may support coverage claims or premium negotiations. For contractual relationships, particularly with larger organizations or public sector clients that require continuity assurances, it demonstrates maturity beyond mere plan existence. For internal governance, it gives boards and executive leadership confidence that management takes continuity seriously and maintains genuine capability rather than paper compliance.

Organizations should resist the temptation to sanitize exercise results or minimize identified deficiencies. Exercises that reveal significant problems are successful exercises—they identified issues before an actual disruption exposed them. Exercises that reveal nothing are either poorly designed, insufficiently challenging, or evidence of mature programs with few remaining gaps to discover. Most organizations fall somewhere between these extremes, and honest acknowledgment of gaps creates the foundation for improvement. Leadership that punishes exercise participants for revealing problems will quickly find that exercises produce uniformly positive but meaningless results, as participants learn to conceal difficulties rather than surface them.

Quebec organizations should note that the civil law framework creates somewhat different documentation expectations than common law provinces. The Civil Code of Quebec establishes obligations of prudence and diligence that courts assess based on what a reasonable person would do in similar circumstances. Documented evidence of systematic exercise programs, thorough analysis of results, and implementation of improvements demonstrates the prudent risk management that Quebec courts consider when assessing organizational responsibility. The protection extends to directors and officers who can demonstrate active governance oversight of continuity programs. While common law provinces rely more heavily on specific statutory obligations and contractual terms, the practical effect is similar: documented improvement cycles provide legal protection as well as operational benefit.

The connection between exercise results and organizational culture deserves attention. Organizations that genuinely use exercise findings to improve develop a culture where identifying problems is valued rather than punished, where honest assessment is expected rather than exceptional, and where resilience is understood as a continuous pursuit rather than a destination. Staff who participate in exercises that lead to meaningful improvements learn that their input matters and become more engaged in continuity efforts. Conversely, staff who participate in exercises where findings disappear into reports that produce no visible changes learn to treat exercises as bureaucratic obligations deserving minimal effort. The choice between these outcomes rests with leadership, and it manifests not in stated values but in actual responses to uncomfortable exercise findings.

For the professional or executive reading this lesson, the practical application centers on ensuring that your organization's exercise program includes robust mechanisms for translating results into improvements. This means designating trained observers for exercises, conducting hot debriefs immediately following exercises, preparing after-action reports that identify specific gaps with assigned owners and deadlines, tracking corrective action completion, and validating through subsequent exercises that improvements actually enhance capability. It means ensuring that your board or governing body receives reports on exercise findings and improvement efforts, creating accountability at the governance level. It means budgeting for improvements identified through exercises rather than treating exercises as standalone activities without implementation costs. It means establishing a plan owner responsible for ongoing maintenance and triggered updates rather than treating plan development as a periodic project. And it means fostering a culture where honest assessment is valued, where problems identified during exercises are treated as discoveries rather than failures, and where continuous improvement is embedded in how your organization approaches resilience. The plan that emerges from this process will differ substantially from the plan you started with—and that evolution, documented and validated, represents the true value of your exercise program.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options