New Zealand does not have to imagine disruption. Canterbury in 2010 and 2011, Kaikōura in 2016, the Auckland Anniversary floods and Cyclone Gabrielle in 2023. Add a national grid running down a long thin country, freight moving across Cook Strait, and an economy where a single port outage reroutes supply chains for months.
Most New Zealand organisations have been through something. What varies enormously is whether the experience turned into a system or turned into a story people tell.
ISO 22301:2019 is the international standard for business continuity management systems. It asks which of your activities genuinely cannot stop, how long they can be interrupted before consequences become unacceptable, what you will do when that happens, and whether you have tested it. Nathan ISO Consulting implements it for New Zealand organisations across both islands.
The vocabulary, because it decides the design
| Term | What it means | Why it matters |
|---|---|---|
| Business impact analysis | Structured assessment of which activities support your most important products and services, and the consequences of interrupting them | Everything else derives from it. A weak BIA produces a plan that protects the wrong things |
| MTPD | Maximum tolerable period of disruption, beyond which harm becomes unacceptable | Sets the outer boundary for every recovery target |
| RTO | Recovery time objective, the target time to resume an activity | Must sit inside the MTPD and be achievable with resources you actually hold |
| RPO | Recovery point objective, the maximum tolerable data loss expressed as time | Drives backup and replication design, and is where IT and business assumptions most often diverge |
| MBCO | Minimum business continuity objective, the reduced service level you must sustain during disruption | Turns continuity from all-or-nothing into something operationally realistic |
New Zealand's disruption profile is specific
Generic continuity planning underweights the things that actually interrupt New Zealand businesses. Four exposures deserve explicit treatment.
Wellington and Canterbury carry obvious exposure, and the Alpine Fault presents a scenario that South Island organisations increasingly plan against. Seismic disruption is distinctive because it damages premises, transport and staff simultaneously, and because access restrictions can outlast the event by weeks. A plan assuming your people can reach an alternate site has assumed away the hard part.
Cyclone Gabrielle and the Auckland Anniversary floods demonstrated that severe weather now interrupts at national scale rather than regionally. Hawke's Bay, Tairāwhiti, Northland and Auckland carry particular exposure, and the pattern of road closures isolating communities for extended periods is a supply chain problem as much as a facilities one.
Cook Strait freight, a small number of major ports, a long grid, and international connectivity through a limited number of cable landings. New Zealand organisations often discover during an exercise that their contingency plan and their competitor's contingency plan both depend on the same alternative route.
The most frequent cause of disruption is now a supplier or a system rather than an earthquake. Cloud provider outages, a failed software update, a ransomware event at a logistics partner. Scenarios where your provider fails and you do not deserve as much attention as the natural hazards, and usually get less.
Regulatory and sector expectations
New Zealand has no general business continuity statute. Obligations arrive by sector and by contract.
The exercise programme is the part that decides everything
More than any other management system standard, ISO 22301 is undone by documentation nobody has tested. A plan that has never been exercised is a hypothesis.
Clause 8.5 requires an exercising and testing programme. The design of those exercises matters more than their frequency. A scenario in which everything fails simultaneously teaches nothing, because the response is simply to declare a disaster. A scenario in which your primary data centre is unavailable for eleven hours during month-end processing, and two key people are unreachable, teaches a great deal.
We design and facilitate exercises built to surface problems. The measure of a good exercise is the length of the findings list, and an exercise that produces none has told you only that the scenario was too easy.
How Nathan ISO Consulting assists
Why organisations choose Nathan
| Common approach | Our approach |
|---|---|
| A BIA emailed to department heads as a survey | A facilitated BIA where dependencies get contested in the room |
| Recovery objectives set by the business, never checked against IT | RTOs and RPOs tested against actual infrastructure capability before sign-off |
| One plan applied to every site nationally | Plans reflecting the hazards each site genuinely faces |
| Exercises designed to be passed | Exercises designed to find problems, measured by the findings they generate |
| Natural hazards planned for, third parties ignored | Supplier and cloud dependency mapped in, because that is now the more frequent cause |
| A plan delivered and shelved | Annual exercise cycles and BIA refresh built into the engagement |
Sectors and regions
Financial services and insurance work concentrates in Auckland and Wellington. Utilities, energy and lifeline operators sit across both islands, including geothermal and hydro generation, transmission and distribution, and water and wastewater authorities. Ports and logistics work spans Auckland, Tauranga, Napier, Wellington, Nelson, Lyttelton, Timaru, Port Chalmers and Bluff.
We also work with health providers, aged care operators, government agencies and their suppliers, telecommunications and data centre operators, food and dairy processors, and manufacturers in the Waikato, Canterbury and Manawatū. Regional exposure shapes the work: Wellington and Canterbury clients weight seismic scenarios, Hawke's Bay, Tairāwhiti and Northland clients weight weather and access, and South Island clients increasingly plan against Alpine Fault scenarios.
Frequently asked questions
There is no general statute. Obligations arrive by sector, including Reserve Bank and FMA expectations for financial institutions and civil defence duties for lifeline utilities, and most commonly through contractual requirements imposed by enterprise and government customers.
Not currently. The Government consulted during 2026 on strengthening critical infrastructure cyber security and resilience, including potential legislation, and submissions have closed. Essential service operators are building capability ahead of any regime rather than waiting.
RTO is how quickly an activity must be resumed after disruption. RPO is how much data loss you can tolerate, expressed as time. They answer different questions and are frequently confused, which produces backup arrangements that cannot support the recovery targets.
At minimum annually, and more often for your most critical activities or after significant change. What matters more than frequency is scenario design: an exercise that everyone passes comfortably has told you the scenario was too easy.
If you operate in the South Island, it is worth planning against. The distinguishing feature is duration and access rather than damage alone, so recovery objectives need to account for people being unable to reach sites for extended periods.
Yes, and that reflects the current reality for most organisations. The standard requires you to understand dependencies including supply chain, and scenarios where a provider fails while you remain intact deserve as much exercise time as natural hazards.
Not automatically. Prudential expectations sit with the regulated entity and include requirements the standard does not address, particularly around outsourcing arrangements. A well-built BCMS delivers most of the underlying capability and produces evidence in one place.
Yes, and the pairing is natural. They share a common structure, and ICT continuity appears in both. Organisations facing both cyber and operational resilience expectations generally run them as one system with a single governance and audit cycle.
A structured assessment identifying which activities support your most important products and services, what they depend on, and how consequences escalate over time when they stop. It is the foundation of the system and the phase organisations most often rush.
Typically 16 to 26 weeks. The business impact analysis takes the most elapsed time because it needs input from across the organisation, and at least one exercise must be completed and documented before a Stage 2 audit.
Rarely. Existing plans usually contain useful content, particularly around incident response. The work concentrates on building a defensible BIA underneath them, testing recovery objectives against real capability, and adding the exercise and review cycle the standard requires.
Both islands. Our continuity work spans Auckland, Wellington, Christchurch, Hamilton, Tauranga, Napier, Nelson, Dunedin and Invercargill, with site attendance where exercises and workshops benefit from being in the room.
Start with what cannot stop
If you already know which activities genuinely cannot be interrupted, tell us. If the answer is that every manager believes their function is critical, that is a normal starting point and the business impact analysis is how it gets resolved.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving