Platform · Business Continuity
A register of what the business does and depends on, a guided business impact analysis that sets the recovery objectives, plans that inherit them, exercises that test them, and a live task board the moment a plan is activated for real.
Why it matters
Most continuity programs are written once and reviewed annually. Recovery objectives are typed from memory, the call tree points at people who changed roles two quarters ago, and the plan has never been run under pressure. When the incident arrives, the document is the last thing anyone opens.
Alvor hangs everything off the business process. Each process carries an owner, a deputy, ordered steps, and typed dependencies: the assets, vendors, people, sites, and other processes it cannot run without. A guided business impact analysis scores impact across categories and time horizons, and its approval stamps the criticality tier and derives the maximum tolerable period of disruption and a recommended RTO. Nothing is asserted; it is analysed.
Plans inherit their objectives from the approved analysis, the most stringent value winning. Exercises record achieved RTO and RPO against target. A real incident turns the plan into a live task board, and every finding feeds the risk register. ISO 22301 alignment and evidence for ISO 27001 A.5.30, NIST CSF Recover, and SOC 2 A1.2 fall out of the work itself.
When it happens
Checklists flatten into tasks, each assigned to a named person or the primary holder of a recovery role. Assignees are notified the moment the plan goes live.
Payments processing · Continuity plan
Active incidentActivated 02:14 · six tasks across three recovery roles
Verify settlement file integrity
Confirm vendor SLA invoked
Redirect payment traffic to standby processor
Publish status page update
Declare incident, notify plan owner
Fail over primary database
Capabilities
Processes, analysis, plans, exercises, activations, findings. Each stage feeds the next, and nothing lives in a binder.
Business processes with owners, deputies, ordered steps, and peak periods. Typed dependencies link each process to the assets, vendors, people, and sites it cannot run without.
Impact scored across categories and time horizons. Approval stamps the criticality tier, derives MTPD and a recommended RTO, and schedules the next review automatically.
A plan covering processes inherits RTO, RPO, and MTD from their approved BIAs; the most stringent value wins. RTO gap analysis flags assets that recover slower than the process needs.
Walkthroughs, simulations, component tests, and full failover drills. Results capture achieved RTO and RPO against target, and lessons learned become tracked findings.
Activating a plan flattens its checklists into a real-time task board with auto-assignment and notifications. Incidents run active, stood down, then closed, in enforced order.
Exercise and debrief findings convert into operational risks in the central register. The same records evidence ISO 22301 alignment, ISO 27001 A.5.30, NIST CSF Recover, and SOC 2 A1.2.
AI assistant
“Which Tier 1 processes have no active plan?” is answered from your register, not from a report someone compiled last quarter.
The assistant drafts business processes and continuity plans. Drafts inherit their objectives from the approved BIA, and nothing is created until you approve it.
It schedules the next tabletop, flags overdue reviews, and proposes escalating findings into the risk register.
Activating a plan, standing down, closing an incident, and approving a plan are never available to the assistant.
Approval required
Covers
Payments processing · Tier 1
Objectives
RTO 4h · RPO 1h · inherited from approved BIA
Strategies
Failover · Manual workaround
The exact change, shown before it happens. Nothing executes without approval.
Where it fits
Questions
The module runs the whole continuity program in five areas: a Dashboard for coverage and readiness, a Process Register of business processes with owners and dependencies, Plans with recovery strategies and approvals, Exercises from tabletops to full failover drills, and an Incidents & Findings register for every live activation and lesson learned. You register what the business does, analyse what it can survive, write plans against that analysis, test them, and activate them when something real breaks.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.