WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Australia does disruption on a scale that surprises people who have not worked here. Flood, cyclone and bushfire arrive on a seasonal cycle rather than as freak events. Supply chains run down single highways for thousands of kilometres. A telecommunications outage or a faulty software update can take out payment systems across the country in an afternoon.

ISO 22301:2019 is the international standard for business continuity management systems. It asks you to work out which of your operations genuinely cannot stop, how long they can be interrupted before the consequences become unacceptable, and what you will actually do when that happens. Then it asks you to test it.

Nathan ISO Consulting builds business continuity management systems for Australian organisations, with particular focus on those carrying regulatory obligations under APRA CPS 230 or the Security of Critical Infrastructure Act.

What a BCMS produces, in the language auditors and regulators use

TermWhat it meansWhy it matters
Business impact analysis (BIA)Structured assessment of which activities support your most important products and services, and the consequences of interrupting themEverything else in the system derives from it. A weak BIA produces a plan that protects the wrong things
Maximum tolerable period of disruption (MTPD)The point beyond which interruption causes unacceptable harmSets the outer boundary for every recovery target you set
Recovery time objective (RTO)The target time to resume an activity after disruptionMust sit inside the MTPD, and must be achievable with resources you actually have
Recovery point objective (RPO)The maximum data loss you can tolerate, expressed as timeDrives backup frequency and replication design, and is where IT and business assumptions most often diverge
Minimum business continuity objective (MBCO)The reduced level of service you must sustain during disruptionTurns continuity from all-or-nothing into something operationally realistic

APRA CPS 230 is the strongest driver in the Australian market

CPS 230 commenced on 1 July 2025 for APRA-regulated entities, with a twelve-month extension for non-significant financial institutions on the business continuity and scenario analysis elements. It requires regulated entities to manage operational risk, maintain critical operations through severe disruption, and manage the risks arising from service providers.

The standard does not name ISO 22301. It does, however, ask for exactly the things a BCMS produces, and it flows down to material service providers who are not themselves regulated entities. A lot of technology vendors have discovered CPS 230 obligations arriving through a customer contract rather than a regulator.

CPS 230 requirementWhere ISO 22301 delivers it
Identify critical operationsBusiness impact analysis, Clause 8.2
Set tolerance levels for disruptionMTPD and RTO determination, Clause 8.2
Maintain a credible business continuity planContinuity strategies and plans, Clauses 8.3 and 8.4
Systematic testing including an annual exerciseExercising and testing program, Clause 8.5
Board oversight and clear senior accountabilityLeadership and governance, Clause 5
Manage material service provider riskSupply chain continuity requirements within Clauses 8.2 and 8.3
Incident escalation and notificationIncident response structure, Clause 8.4
Review and continual improvementPerformance evaluation and improvement, Clauses 9 and 10

Mapping is not equivalence. CPS 230 imposes obligations ISO 22301 does not cover, including specific service provider register and notification requirements. We build the BCMS so it satisfies the standard and evidences the prudential requirement in the same set of records.

Critical infrastructure and the SOCI Act

The Security of Critical Infrastructure Act 2018 requires responsible entities in declared sectors to maintain a critical infrastructure risk management program covering all hazards that could affect the availability of the asset. Declared sectors span energy, water, transport, communications, health care, data storage and processing, food and grocery, financial services and defence industry.

All hazards means what it says. Cyber is one hazard category among several, sitting alongside physical, personnel and supply chain hazards, plus natural events. A business continuity management system is the operational machinery behind the availability side of that program, and organisations that already run one find the CIRMP obligation considerably less daunting.

Australia's disruption profile is regional, and your plan should be too

A continuity plan written in a Sydney head office and applied unchanged to a Cairns depot is not a plan. The hazards differ, the recovery timeframes differ, and the practical constraints differ enormously.

RegionDominant disruption exposureWhat that means for the BCMS
Sydney and MelbourneConcentration risk in financial services, data centres and transport nodes; cyber and third-party outageCPS 230 driven; heavy focus on service provider dependency mapping
Brisbane, Gold Coast, Sunshine CoastFlooding, severe storms, occasional cyclone reachSeasonal readiness cycles; site relocation and staff access planning
Cairns, Townsville, DarwinCyclone season, storm surge, extended isolationPre-season activation triggers; realistic MTPDs that account for access delays
Perth, Pilbara, GoldfieldsExtreme remoteness, single-route supply chains, heat, fireStock and spares strategy; recovery targets that reflect travel realities
Regional NSW, Victoria, South AustraliaBushfire, flood, extended power interruptionManual workaround procedures; communication when networks are down
CanberraGovernment service continuity, cyber, smoke and air quality eventsPSPF interaction; continuity of services to agencies
TasmaniaStorm, power interruption, freight dependency across Bass StraitFreight contingency and inventory buffers
NationwideTelecommunications outage, cloud provider failure, software update failure, cyber incidentThird-party dependency register; scenarios that assume your provider, not you, is the point of failure

The exercise program most organisations skip

More than any other management system standard, ISO 22301 is undone by documentation that has never been tested. A plan nobody has rehearsed is a hypothesis.

Clause 8.5 requires an exercising and testing program, and CPS 230 goes further by requiring an annual business continuity exercise covering critical operations under severe but plausible scenarios. That word plausible does a lot of work. A scenario in which everything fails at once teaches nothing. A scenario in which your primary cloud region is unavailable for eleven hours during end-of-month processing teaches a great deal.

We design and facilitate exercises, and we write them so they surface problems rather than confirming that the plan reads well. The measure of a good exercise is the length of the findings list.

How Nathan ISO Consulting assists

  • Business impact analysis. Facilitated across your operations to identify critical activities, dependencies and consequence timelines, with the outputs traceable back to specific business decisions.
  • Recovery objective setting. MTPD, RTO, RPO and MBCO determined with the people who will have to meet them, then tested against what your infrastructure can actually deliver.
  • Regulatory mapping. Where CPS 230, SOCI Act CIRMP obligations or contractual continuity requirements apply, mapped to the BCMS so evidence is produced once.
  • Dependency and service provider mapping. Your critical third parties, their concentration risk, and what happens when the provider rather than you is the point of failure.
  • Continuity strategies and plans. Practical strategies matched to your recovery objectives, and plans written for people under pressure rather than for a document reviewer.
  • Incident and crisis management structure. Roles, escalation thresholds, decision authority and communications, including what gets said to customers and regulators.
  • Exercise design and facilitation. Tabletop and functional exercises built on plausible scenarios, facilitated by us, with a documented findings list and remediation plan.
  • Internal audit and management review. Full internal audit against the standard, findings closed, and a documented review that satisfies both auditors and boards.
  • Certification support. Certification body selection from JAS-ANZ accredited bodies, and attendance at Stage 1 and Stage 2.
  • Ongoing maintenance. Annual exercise cycles, BIA refresh, and plan updates as your operations and dependencies change.

Why organisations choose Nathan

Common approachOur approach
A BIA run as a survey emailed to department headsA facilitated BIA where dependencies get argued about in the room, because that is where the real answers surface
Recovery objectives set by the business and never checked against IT capabilityRTOs and RPOs tested against what your infrastructure can actually deliver before they are signed off
One continuity plan applied nationallyPlans that reflect regional hazard exposure, because cyclone season in Cairns is not a Sydney risk register entry
Exercises designed to be passedExercises designed to find problems, measured by the length of the findings list
CPS 230 and ISO 22301 run as two separate projectsOne system, one set of evidence, satisfying both the standard and the prudential requirement
Third-party risk treated as a procurement issueService provider dependency mapped into the BCMS, with scenarios where the provider fails and you do not
A plan delivered and never revisitedAnnual exercise cycles and BIA refresh, because dependencies change faster than documents do

Sectors and locations we serve

Business continuity work needs presence at the sites that carry the risk. We attend those, run workshops and exercises in person where it materially improves the outcome, and deliver the rest remotely.

SectorWhere we typically work
Banking, insurance and superannuationSydney, Melbourne, Brisbane, Perth — CPS 230 driven
Energy, water and utilitiesPerth, Brisbane, Gladstone, Newcastle, Latrobe Valley, Adelaide, Darwin
Transport, ports and logisticsSydney, Melbourne, Brisbane, Fremantle, Port Hedland, Townsville, Darwin
Health and aged careAll capital cities and major regional centres
Telecommunications and data centresSydney, Melbourne, Canberra, Brisbane, Perth
Government and government suppliersCanberra, and state capitals
Manufacturing and food processingMelbourne, Geelong, Shepparton, Toowoomba, Adelaide, Bendigo
Mining and resourcesPerth, Karratha, Port Hedland, Kalgoorlie, Mackay, Mount Isa, Roxby Downs
Professional and financial servicesSydney, Melbourne, Brisbane, Adelaide, Perth, Canberra, Hobart

FAQ'S

No. There is no legal requirement to certify. It becomes a practical requirement when it appears in tender prequalification criteria, which is increasingly common in civil construction, infrastructure and government contracts, or when a head contractor requires it of subcontractors.

Not automatically. ISO 14001 requires you to identify your compliance obligations and evaluate performance against them, which makes compliance far more likely and much easier to demonstrate. The legal obligations themselves sit with your state environmental legislation, not the standard.

It is a proactive duty under Victoria's Environment Protection Act 2017 to eliminate or minimise risks of environmental harm so far as reasonably practicable. It applies to any Victorian operation regardless of whether you hold a permit, and EPA Victoria can act without a pollution event occurring.

They are separate obligations. NGER and the Safeguard Mechanism are Commonwealth schemes with their own thresholds. An ISO 14001 system provides the data collection discipline and operational control that makes those obligations far easier to meet accurately.

All states and territories. We work across Sydney, Melbourne, Brisbane, Perth, Adelaide, Canberra, Hobart and Darwin, and through industrial regional centres including Gladstone, Kwinana, the Hunter Valley, the Latrobe Valley, Kalgoorlie and Port Hedland.

Yes, and it usually should be. The three standards share a common high-level structure, so a single integrated system with combined audits means one set of internal audits and one management review instead of three separate cycles.

Generally 12 to 20 weeks. The aspects and impacts assessment takes real time to do properly, and you need operational records plus one internal audit and management review cycle before a Stage 2 audit can proceed.

Sometimes. Contaminated land, complex licence conditions, and air, noise or water monitoring sit outside management system consultancy. We will tell you where that line falls rather than quoting for work we should not be doing.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance