← University
Business Impact Analysis: What Gets Disrupted and How Badly
0 of 4

A regional distribution company operating out of southern Alberta had grown steadily over 12 years, expanding from a single warehouse serving local retailers to a network of 3 facilities employing 87 staff and managing inventory for clients across western Canada. The company's general manager had built the operation through practical experience rather than formal planning, and the business had weathered minor disruptions before—a 2-day power outage at one facility, a brief ransomware scare that the IT contractor resolved before any data was encrypted, and the unexpected resignation of the operations supervisor who had managed the Calgary warehouse since its opening.

None of these events had caused lasting harm, but a recent board meeting had changed the general manager's perspective. A director with experience in manufacturing had asked a simple question: if the company's primary warehouse management system went offline for 72 hours during peak season, which clients would be lost permanently, and how much revenue would never be recovered? The general manager could not answer. The financial controller offered estimates but acknowledged they were guesses. The IT contractor, present by phone, noted that the current backup system restored data to a point 48 hours before any failure, but no one in the room could say whether a 48-hour data gap was acceptable or catastrophic.

The board directed management to conduct a formal analysis before the next quarter. The general manager began by listing the company's functions: receiving shipments, updating inventory records, picking and packing orders, dispatching trucks, invoicing clients, processing payroll, maintaining refrigeration for temperature-sensitive goods, and communicating with customs brokers for cross-border shipments. Some of these functions seemed obviously essential, but the interdependencies were unclear. The refrigeration system, for example, depended on continuous monitoring by a contracted technician who worked remotely and whose availability during a regional emergency was uncertain.

The company's largest client, a grocery chain representing 34 percent of annual revenue, had recently added contractual language requiring suppliers to demonstrate business continuity capabilities. The deadline for demonstrating compliance was 90 days away. The general manager now faced the task of determining which functions could tolerate interruption, which could not, what consequences would follow from various disruption scenarios, and what recovery targets the company needed to establish—all before any continuity plan could be written.

Recovery Time and Recovery Point Objectives: Setting Targets That Drive Planning

Every organization, whether a small accounting firm in Halifax, a construction company in Calgary, or a community non-profit in Saskatoon, operates on the assumption that its critical systems and data will be available when needed. This assumption holds true under normal circumstances, but disruptions ranging from power outages to cyberattacks to natural disasters can shatter that expectation without warning. When continuity breaks down, the question becomes not simply whether recovery is possible, but how quickly operations must resume and how much data loss the organization can tolerate before the damage becomes unacceptable. These two questions form the foundation of recovery time objectives and recovery point objectives, concepts that sit at the heart of modern business continuity planning and that Canadian organizations of all sizes must understand if they hope to survive significant operational interruptions.

Recovery time objective, commonly abbreviated as RTO, represents the maximum acceptable duration that a business function, system, or process can remain unavailable before the organization suffers unacceptable consequences. The consequences might be financial, reputational, regulatory, or some combination of all three. A payroll processing system that goes down for two hours might cause inconvenience, but a payroll system that remains unavailable for two weeks could result in legal violations under employment standards legislation, damage to employee trust, and potential penalties from the Canada Revenue Agency for late remittances. The recovery time objective forces organizations to define precisely how long they can tolerate being without a particular capability before the costs outweigh the investment required to recover more quickly.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.