glacierr
get in touch
typical engagement
6–8 weeks · fixed fee

service · 04business continuity · disaster recovery · incident response

business resilience consulting

be ready before the disruption.

We help you prepare for disruption — connecting business continuity, disaster recovery and cyber incident response into one coherent capability, with clear responsibilities, plans your teams can follow, and exercises that show whether they work.

business continuity disaster recovery incident response exercises fixed fee
▼
bc

business continuity — keeping critical services running

dr

disaster recovery — what comes back, in what order

ir

incident response — who decides what, and when

01what changes for you

what changes for you.

Critical services mapped with targets the business set, named owners and decision rights agreed in advance, and plans that are exercised — not assumed.

01

know what actually matters

Critical services and dependencies mapped, with RTOs and RPOs set by the business.

02

clear responsibilities

Named owners, decision rights and escalation routes, agreed in advance.

03

plans people can follow at 3am

Policies, plans, playbooks and procedures written for the people who use them.

04

one joined-up response

BC, DR and IR plans that hand off cleanly instead of contradicting each other.

05

proven, not assumed

Tabletop exercises and walkthroughs that show what holds and what breaks.

06

regulator & auditor ready

ISO 22301, BCI Good Practice, FCA/PRA, DORA or NIS2 where they apply.

02what we typically find

three documents, three authors. nobody sure who makes the call.

A continuity plan, a DR document and an incident policy — written at different times, for different auditors. Nobody is sure who makes the call, and none of it has been tested with the people who would use it.

33%
of UK businesses have a continuity plan that covers cyber
25%
have a formal incident response plan
15%
formally review risks from immediate suppliers

03our approach

mobilise · analyse · document · exercise.

Four stages, each with a gate you sign. Senior consultants only — the people who scope are the people who deliver.

01 · mobilise

agree what "good" looks like

02 · analyse

find what really matters

03 · document

write the plans

04 · exercise

test them with your team

04what you get

what you get.

We plan and exercise — your teams respond and recover.

05who it's for

who it's for.

board & ceo

Clear decision rights when it counts.

cfo

A basis for resilience spend.

cio & it

Agreed recovery targets to plan to.

risk & resilience

Exercised plans and the evidence.

Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026); FCA PS21/3 and PRA SS1/21, Operational resilience (March 2021); Regulation (EU) 2022/2554, DORA (applies from 17 January 2025).

shall we get on with it?

Fixed scope, fixed fee — typically six to eight weeks. We've lived the 3am incidents; your plans should be ready for them.

also from glacierr.