Feedback on a Business Continuity Exercise
An exercise may be technically successful yet reveal that a business continuity plan is not sufficiently operational. The term “business continuity exercise debrief” specifically refers to the process of transforming the observations made during the simulation into verifiable improvements to the business continuity plan, crisis management, and recovery capabilities. Without this step, the exercise remains a one-time demonstration. With it, it becomes a driver of governance and operational resilience.
In organizations subject to strict requirements regarding availability, compliance, or oversight, lessons learned should not be treated as mere administrative reports. They must lead to decisions, assign responsibilities, and fuel a cycle of continuous improvement consistent with the requirements of ISO 22301.
Why Feedback Determines the Value of the Exercise
A business continuity exercise rarely evaluates the BCP as a whole. Instead, it tests one or more specific scenarios: the ability to mobilize the crisis response team, the accuracy of on-call contact information, the failover of a critical operation, the implementation of a communication procedure, or coordination with a key service provider.
The overall outcome—the exercise was completed, the timeline was met, and participants were present—is not sufficient to assess the organization’s preparedness. A crisis response team may have been activated on time but still made decisions based on incomplete information. An IT recovery may proceed smoothly even though business units are unable to prioritize which activities to restore. Conversely, a scenario deemed difficult may reveal a useful weakness, provided that it is analyzed without immediately seeking to justify the discrepancy.
The post-project review provides this analysis. It distinguishes between what worked due to a sustainable capability and what worked due to a combination of circumstances, the exceptional availability of certain employees, or a simplified scenario. This distinction is essential to avoid an overly favorable interpretation of the results.
Prepare the REX before even starting the exercise
The quality of debriefing is largely determined before the simulation begins. If the objectives, success criteria, and observation procedures are not defined, post-exercise discussions may be limited to general impressions. While impressions are useful, they are not sufficient to guide corrective actions.
Objectives must be linked to specific capabilities. For example, verifying that designated personnel can classify an incident, initiate the appropriate escalation, and provide an initial shared status update within a specified timeframe. For a business continuity plan (BCP) exercise, this may involve confirming the order in which applications are to be restored, the availability of access permissions, or the compatibility between the technical restart and business dependencies.
Each objective benefits from being linked to observable elements: timestamps of decisions, messages sent, procedures consulted, discrepancies identified, unanswered questions, and decisions made. The person in charge of the exercise is not necessarily the best observer. Designated observers who are informed of their role and assigned to specific phases provide a more reliable perspective.
Define criteria that measure ability, not performance
A tabletop exercise helps evaluate decision-making processes, interfaces between teams, and understanding of roles. It does not always demonstrate the technical feasibility of a switchover. A technical test, on the other hand, can confirm that an environment can be restored without testing the business units’ ability to operate in degraded mode.
The REX criteria must take this limitation into account. It would be inappropriate to conclude that a PRA is fully operational after a single crisis simulation. Similarly, criticizing a crisis exercise for failing to produce an actual recovery would be to confuse the objectives. The appropriate level of rigor depends on the type of exercise, the scope involved, the criticality of the activities, and the maturity of the system.
Conducting a Lessons Learned Session on Business Continuity
The immediate debriefing should take place quickly, ideally at the end of the exercise or within the following hours. Its purpose is not to assign individual blame. Rather, it involves gathering the facts while they are still clear: what participants understood, what information was missing, what obstacles they encountered, and what difficult decisions they had to make.
This process must be facilitated systematically. Participants must be able to report deviations without fear that the REX will be used as a tool for personal evaluation. A culture of transparency is particularly important when the exercise involves management, IT teams, business units, security, communications, and third parties. The challenges identified often lie at the interfaces between these groups, rather than in isolated failures.
A post-event debriefing takes place after the logs, observations, and deliverables have been compiled. It allows for a comparison between perceptions and factual evidence. A decision perceived as being late may, for example, have been made within the expected timeframe but poorly communicated to the teams. Conversely, a procedure considered to be well-known may never have been used during the exercise because it was difficult to locate or ill-suited to the situation.
Accurately Characterize Deviations
A useful observation describes the observed situation, what was expected, possible consequences, and contributing factors. “Communication was insufficient” is too general to prompt appropriate action. A more actionable observation would specify that the status update was not distributed to site managers for an hour due to the lack of an approved distribution channel and an available message template.
The qualification process must also avoid two pitfalls. The first is treating all discrepancies as urgent. The second is to dismiss minor discrepancies without analyzing their cumulative impact. Incorrect contact information, ambiguity regarding the role of a substitute, and the lack of a communication template can, when combined, delay a critical response.
It is helpful to distinguish between gaps in governance, processes, resources, skills, data, and technology. This approach helps identify the root causes. A slow response by a crisis management team is not necessarily remedied by a new procedure; it may stem from unclear delegation of authority, poorly defined on-call requirements, or insufficient training.
Turn findings into a managed improvement plan
The main deliverable of the REX is not the report itself. It is the action plan that results from it. For each action, you must specify a person in charge, a deadline, any dependencies, the necessary resources, and a completion criterion. “Update the Business Continuity Plan” is not a sufficient criterion. It is necessary to specify which procedures are being modified, who approves them, how they are distributed, and through what process their effectiveness will be verified.
Prioritization must be risk-based. A deviation affecting a critical activity, a regulatory requirement, or the ability to communicate during a crisis warrants expedited handling. However, a quick but unvalidated correction can create a false sense of control. When a procedure is modified, it must be reviewed with the relevant stakeholders and then tested in an appropriate exercise.
Governance plays a crucial role here. Results and major decisions must be presented to the appropriate body: the business continuity committee, the risk committee, the crisis management team, or senior management, depending on the organization. This reporting process enables decisions to be made that fall outside the scope of the Business Continuity Plan (BCP) manager, particularly when a deviation involves an investment, a contractual requirement with a supplier, or an organizational change.
Measuring Progress Between Two Exercises
A post-incident review (REX) is particularly useful when it allows for tracking progress in maturity. The indicators should be limited in number and meaningful: adherence to alert deadlines, activation of critical roles, availability of essential information, task completion rates, results of retests, or the quality of coordination with service providers.
These measures should not encourage teams to optimize the exercise at the expense of its realism. A high success rate is reassuring, but it may indicate a scenario that is too predictable or a scope that is not challenging enough. As capabilities are strengthened, scenarios must incorporate credible constraints: the unavailability of a decision-maker, the simultaneous loss of a communication tool, a supplier failure, or the need to prioritize between competing activities.
The professionalization of teams directly contributes to this momentum. Managers responsible for business continuity, risk, cybersecurity, and crisis management need a common language, methods for designing exercises, and a structured understanding of the relevant standards. The training programs offered by DRI France are designed with this focus on operational application and the development of recognized skills.
A well-conducted post-incident review does not seek to prove that the organization was prepared. It seeks to rigorously determine what the organization will actually be able to do during the next incident and what it still needs to improve before a crisis exposes these shortcomings.
This post is also available in:



