WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

New Zealand does not have to imagine disruption. Canterbury in 2010 and 2011, Kaikōura in 2016, the Auckland Anniversary floods and Cyclone Gabrielle in 2023. Add a national grid running down a long thin country, freight moving across Cook Strait, and an economy where a single port outage reroutes supply chains for months.

Most New Zealand organisations have been through something. What varies enormously is whether the experience turned into a system or turned into a story people tell.

ISO 22301:2019 is the international standard for business continuity management systems. It asks which of your activities genuinely cannot stop, how long they can be interrupted before consequences become unacceptable, what you will do when that happens, and whether you have tested it. Nathan ISO Consulting implements it for New Zealand organisations across both islands.

The vocabulary, because it decides the design

TermWhat it meansWhy it matters
Business impact analysisStructured assessment of which activities support your most important products and services, and the consequences of interrupting themEverything else derives from it. A weak BIA produces a plan that protects the wrong things
MTPDMaximum tolerable period of disruption, beyond which harm becomes unacceptableSets the outer boundary for every recovery target
RTORecovery time objective, the target time to resume an activityMust sit inside the MTPD and be achievable with resources you actually hold
RPORecovery point objective, the maximum tolerable data loss expressed as timeDrives backup and replication design, and is where IT and business assumptions most often diverge
MBCOMinimum business continuity objective, the reduced service level you must sustain during disruptionTurns continuity from all-or-nothing into something operationally realistic

New Zealand's disruption profile is specific

Generic continuity planning underweights the things that actually interrupt New Zealand businesses. Four exposures deserve explicit treatment.

Seismic

Wellington and Canterbury carry obvious exposure, and the Alpine Fault presents a scenario that South Island organisations increasingly plan against. Seismic disruption is distinctive because it damages premises, transport and staff simultaneously, and because access restrictions can outlast the event by weeks. A plan assuming your people can reach an alternate site has assumed away the hard part.

Weather and flooding

Cyclone Gabrielle and the Auckland Anniversary floods demonstrated that severe weather now interrupts at national scale rather than regionally. Hawke's Bay, Tairāwhiti, Northland and Auckland carry particular exposure, and the pattern of road closures isolating communities for extended periods is a supply chain problem as much as a facilities one.

Single points of national failure

Cook Strait freight, a small number of major ports, a long grid, and international connectivity through a limited number of cable landings. New Zealand organisations often discover during an exercise that their contingency plan and their competitor's contingency plan both depend on the same alternative route.

Third party and cyber

The most frequent cause of disruption is now a supplier or a system rather than an earthquake. Cloud provider outages, a failed software update, a ransomware event at a logistics partner. Scenarios where your provider fails and you do not deserve as much attention as the natural hazards, and usually get less.

Regulatory and sector expectations

New Zealand has no general business continuity statute. Obligations arrive by sector and by contract.

  • Financial services. The Reserve Bank and the Financial Markets Authority set expectations around operational resilience and outsourcing for registered banks, licensed insurers, deposit takers and licensed market participants. Material service providers to those entities inherit the requirements contractually.
  • Critical infrastructure. New Zealand consulted during 2026 on strengthening the cyber security and resilience of critical infrastructure, including potential legislation. Nothing is in force yet, but the direction of travel is clear enough that essential service operators are building ahead of it.
  • Civil defence and emergency management. Lifeline utilities carry duties under civil defence emergency management legislation to function during and after an emergency and to participate in regional planning.
  • Health and aged care. Sector standards and contracts require continuity of care arrangements independent of any general statute.
  • Contractual flow-down. For most organisations this is where the requirement actually originates. Enterprise and government contracts increasingly require evidence of continuity capability, and ISO 22301 answers it efficiently.

The exercise programme is the part that decides everything

More than any other management system standard, ISO 22301 is undone by documentation nobody has tested. A plan that has never been exercised is a hypothesis.

Clause 8.5 requires an exercising and testing programme. The design of those exercises matters more than their frequency. A scenario in which everything fails simultaneously teaches nothing, because the response is simply to declare a disaster. A scenario in which your primary data centre is unavailable for eleven hours during month-end processing, and two key people are unreachable, teaches a great deal.

We design and facilitate exercises built to surface problems. The measure of a good exercise is the length of the findings list, and an exercise that produces none has told you only that the scenario was too easy.

How Nathan ISO Consulting assists

  • Business impact analysis. Facilitated across your operations rather than emailed out as a survey, because dependencies get argued about in the room and that argument is where the real answers surface.
  • Recovery objective setting. MTPD, RTO, RPO and MBCO agreed with the people who have to meet them, then tested against what your infrastructure can actually deliver before sign-off.
  • Regional risk profiling. Continuity strategies built around the hazards your specific sites face rather than a national average.
  • Dependency and supplier mapping. Your critical third parties, concentration risk, and what happens when the provider rather than you is the point of failure.
  • Continuity strategies and plans. Written for people working under pressure with degraded information, not for a document reviewer.
  • Incident and crisis management. Roles, escalation thresholds, decision authority and communications, including what gets said to customers, staff and regulators.
  • Exercise design and facilitation. Plausible scenarios, facilitated by us, with a documented findings list and a remediation plan attached.
  • Sector alignment. Where Reserve Bank expectations, lifeline utility duties or contractual continuity requirements apply, mapped so one evidence set serves all of them.
  • Certification support. Internal audit, management review, certification body selection and attendance at Stage 1 and Stage 2.
  • Ongoing maintenance. Annual exercise cycles and BIA refresh, because dependencies change faster than documents do.

Why organisations choose Nathan

Common approachOur approach
A BIA emailed to department heads as a surveyA facilitated BIA where dependencies get contested in the room
Recovery objectives set by the business, never checked against ITRTOs and RPOs tested against actual infrastructure capability before sign-off
One plan applied to every site nationallyPlans reflecting the hazards each site genuinely faces
Exercises designed to be passedExercises designed to find problems, measured by the findings they generate
Natural hazards planned for, third parties ignoredSupplier and cloud dependency mapped in, because that is now the more frequent cause
A plan delivered and shelvedAnnual exercise cycles and BIA refresh built into the engagement

Sectors and regions

Financial services and insurance work concentrates in Auckland and Wellington. Utilities, energy and lifeline operators sit across both islands, including geothermal and hydro generation, transmission and distribution, and water and wastewater authorities. Ports and logistics work spans Auckland, Tauranga, Napier, Wellington, Nelson, Lyttelton, Timaru, Port Chalmers and Bluff.

We also work with health providers, aged care operators, government agencies and their suppliers, telecommunications and data centre operators, food and dairy processors, and manufacturers in the Waikato, Canterbury and Manawatū. Regional exposure shapes the work: Wellington and Canterbury clients weight seismic scenarios, Hawke's Bay, Tairāwhiti and Northland clients weight weather and access, and South Island clients increasingly plan against Alpine Fault scenarios.

Frequently asked questions

There is no general statute. Obligations arrive by sector, including Reserve Bank and FMA expectations for financial institutions and civil defence duties for lifeline utilities, and most commonly through contractual requirements imposed by enterprise and government customers.

Not currently. The Government consulted during 2026 on strengthening critical infrastructure cyber security and resilience, including potential legislation, and submissions have closed. Essential service operators are building capability ahead of any regime rather than waiting.

RTO is how quickly an activity must be resumed after disruption. RPO is how much data loss you can tolerate, expressed as time. They answer different questions and are frequently confused, which produces backup arrangements that cannot support the recovery targets.

At minimum annually, and more often for your most critical activities or after significant change. What matters more than frequency is scenario design: an exercise that everyone passes comfortably has told you the scenario was too easy.

If you operate in the South Island, it is worth planning against. The distinguishing feature is duration and access rather than damage alone, so recovery objectives need to account for people being unable to reach sites for extended periods.

Yes, and that reflects the current reality for most organisations. The standard requires you to understand dependencies including supply chain, and scenarios where a provider fails while you remain intact deserve as much exercise time as natural hazards.

Not automatically. Prudential expectations sit with the regulated entity and include requirements the standard does not address, particularly around outsourcing arrangements. A well-built BCMS delivers most of the underlying capability and produces evidence in one place.

Yes, and the pairing is natural. They share a common structure, and ICT continuity appears in both. Organisations facing both cyber and operational resilience expectations generally run them as one system with a single governance and audit cycle.

A structured assessment identifying which activities support your most important products and services, what they depend on, and how consequences escalate over time when they stop. It is the foundation of the system and the phase organisations most often rush.

Typically 16 to 26 weeks. The business impact analysis takes the most elapsed time because it needs input from across the organisation, and at least one exercise must be completed and documented before a Stage 2 audit.

Rarely. Existing plans usually contain useful content, particularly around incident response. The work concentrates on building a defensible BIA underneath them, testing recovery objectives against real capability, and adding the exercise and review cycle the standard requires.

Both islands. Our continuity work spans Auckland, Wellington, Christchurch, Hamilton, Tauranga, Napier, Nelson, Dunedin and Invercargill, with site attendance where exercises and workshops benefit from being in the room.

Start with what cannot stop

If you already know which activities genuinely cannot be interrupted, tell us. If the answer is that every manager believes their function is critical, that is a normal starting point and the business impact analysis is how it gets resolved.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance