Crisis Management (CM) and Business Continuity Management (BCM) are complementary organisational capabilities, but they are not interchangeable.
Understanding their differences is particularly important for the Brunei Darussalam Central Bank (BDCB), where an incident may affect not only internal operations but also regulated financial institutions, payment and settlement activities, stakeholders, and potentially confidence in the wider financial system.
BDCB carries responsibilities for monetary policy, currency issuance, regulation, and supervision of banks and other financial institutions. Its statutory objectives include domestic price stability, financial-system stability, efficient payment systems, and development of a sound and progressive financial-services sector.
BDCB also operates Brunei Darussalam's National Payment and Settlement Systems (NPSS), comprising the Real-Time Gross Settlement (RTGS), Automated Clearing House (ACH), and Central Securities Depository (CSD).
Consequently, the same initiating event could require BCM, CM, or both, depending on its consequences.
The distinction can be expressed simply:
BCM focuses primarily on maintaining and recovering critical business functions following disruption. CM focuses on providing strategic leadership, coordination, and decision-making when an event creates crisis-level consequences, uncertainty, and stakeholder concerns.
The distinction is important, but the two capabilities should operate as part of an integrated organisational resilience framework.
BCMpedia defines Crisis Management as the overall coordination of an organisation's response to a crisis in an effective and timely manner, to avoid or minimise damage to its profitability, reputation or ability to operate.
For BDCB, this definition should be interpreted within the context of a central bank.
The purpose of CM is therefore broader than restoring an interrupted process. It provides the strategic management capability required when an event creates substantial uncertainty, requires decisions beyond normal operational authority, affects multiple stakeholders, or threatens important organisational objectives.
This interpretation is consistent with ISO 22361:2022 — Security and resilience — Crisis management — Guidelines. ISO describes the standard as guidance for planning, establishing, maintaining, reviewing, and continually improving a strategic crisis-management capability.
Its principal elements include organisational context, development of the capability, crisis leadership, decision-making, crisis communication, training, validation, and learning.
For BDCB, CM, therefore, involves capabilities such as:
CM asks the strategic question:
“How should BDCB manage this situation and its wider consequences?”
Business Continuity Management is concerned principally with protecting the organisation's ability to continue and recover priority activities following disruption.
BCMpedia describes Business Continuity as safeguarding the interests of an organisation and its key stakeholders by protecting critical business functions against predetermined disruptions. BCMpedia
Its description of a BCM framework similarly identifies BCM as a methodology and planning process for managing disruption-related risk.
For BDCB, BCM would therefore focus on questions such as:
BCM asks the operational continuity question:
“How will BDCB continue or recover its critical business functions following disruption?”
The principal differences can be summarised as follows.
|
Dimension |
Crisis Management |
Business Continuity Management |
|
Primary purpose |
Strategic management of a crisis and its consequences |
Continuity and recovery of critical business functions |
|
Primary focus |
Organisation-wide strategic consequences |
Business disruption and recovery |
|
Primary trigger |
Crisis scenario or escalating event |
Disaster or disruptive event affecting critical activities |
|
Key question |
How should BDCB strategically manage the situation? |
How will BDCB continue or recover critical activities? |
|
Leadership |
Senior management / Crisis Management Team |
Business continuity and business-function management |
|
Decision environment |
High uncertainty, ambiguity, and time pressure |
Pre-planned continuity and recovery requirements |
|
Scope |
Strategic, organisation-wide, and potentially system-wide |
Primarily organisational functions, processes, and resources |
|
Stakeholders |
Potentially government, regulators, financial institutions, employees, media, public, and other authorities |
Primarily affected business units, employees, suppliers, technology teams, and service stakeholders |
|
Communication |
Strategic stakeholder and crisis communication |
Operational continuity and recovery communication |
|
Typical plans |
Crisis Management Plan and crisis playbooks |
Business Continuity Plans and recovery procedures |
|
Success measure |
Strategic control, stabilisation, and effective management of consequences |
Critical functions were maintained or recovered within the agreed requirements |
|
End state |
Crisis stabilised and strategic control restored |
Priority activities restored to acceptable operating levels |
The difference is one of purpose and management perspective, rather than a rigid boundary.
A particularly important distinction is the difference between a disaster, which is traditionally addressed through BCM and recovery arrangements, and a crisis scenario, which is used to prepare the organisation's crisis-management capability.
BCMpedia defines a disaster as a sudden, unplanned event causing great damage or serious loss to an organisation. Its accompanying explanation notes that such an event can result in an organisation being unable to provide critical business functions for a predetermined period, effectively denying access to people, processes, or infrastructure.
From a BCM perspective, the central issue is therefore disruption.
For example, BDCB could experience:
Flooding is affecting access to premises
The BCM question is whether the affected critical business functions can continue from another location.
Major technology outage
The BCM question is whether alternative procedures or recovery systems can maintain priority activities.
Extended telecommunications failure
The BCM question is how critical functions can operate using alternative communication arrangements.
Loss of critical staff availability
The BCM question is whether minimum staffing arrangements, alternates and cross-trained personnel can maintain required services.
In each example, BCM concentrates on the continuity consequence.
BCMpedia defines a Crisis Scenario as a situation that might disrupt the business. It further describes it as a set of informed assumptions concerning a situation that may require human intervention and action to resolve.
For crisis-management purposes, a scenario should extend beyond identifying the initiating threat. It should explore how the situation could develop, what strategic consequences could arise, which stakeholders could become involved, what uncertainty could emerge, and what decisions senior management might face.
For BDCB, examples could include:
These are planning scenarios, not assertions that such events have occurred at BDCB.
The distinction becomes clearer when the two concepts are compared directly.
|
Dimension |
Disaster — BCM Perspective |
Crisis Scenario — CM Perspective |
|
Primary concern |
Loss or disruption of critical business functions |
Strategic consequences arising from an evolving situation |
|
Core problem |
Availability of people, processes, premises, technology, or suppliers |
Uncertainty, strategic consequences, stakeholder pressure, and decision complexity |
|
Primary objective |
Continue and recover critical operations |
Establish strategic control and manage the crisis |
|
Typical planning question |
“How will we continue?” |
“How will we manage this situation?” |
|
Planning basis |
Business Impact Analysis and recovery requirements |
Crisis Scenario Risk Analysis and Strategic Consequences |
|
Typical activation |
Critical activity cannot operate normally |
The situation requires strategic leadership beyond normal management |
|
Management response |
Activate Business Continuity Plans |
Activate the Crisis Management Team and CM arrangements |
|
Primary outputs |
Continuity procedures, recovery strategies, and resource arrangements |
Strategic objectives, decisions, response strategies, and crisis communication |
|
Time orientation |
Continuity and recovery against predefined objectives |
Immediate and evolving strategic decision-making |
|
Uncertainty |
Often supported by predefined recovery arrangements |
Frequently characterised by incomplete, changing, or contradictory information |
The difference can therefore be expressed as:
Disaster → Disruption → Critical Business Functions Affected → Business Continuity Response → Continuity and Recovery
Crisis Scenario → Escalating Situation → Strategic Consequences and Uncertainty → Crisis Management Response → Stabilisation and Strategic Recovery
These two sequences should be converted into separate professional diagrams in the final eBook rather than retaining the text-arrow versions.
A major event should not necessarily be classified exclusively as either a disaster or a crisis.
Consider a severe cyberattack.
From the BCM perspective, the cyberattack may make critical technology unavailable. Business units activate continuity arrangements, and technology teams implement recovery procedures.
From the CM perspective, the same cyberattack may create uncertainty regarding transaction integrity, affect financial institutions, attract media attention, generate misinformation, and require strategic decisions from BDCB's senior management.
The progression could therefore be:
These are presented as two separate diagrams (side-by-side) to demonstrate that the same initiating event can create different management requirements.
BDCB's RTGS system provides a useful example of the distinction.
BDCB states that it operates the NPSS comprising RTGS, ACH, and CSD. RTGS supports real-time settlement of large-value and urgent interbank payments, while ACH clearing obligations are ultimately submitted to RTGS for settlement.
Suppose a technology failure causes RTGS to become unavailable.
The immediate continuity questions include:
The objective is continuity and recovery.
If the outage becomes prolonged or its consequences become uncertain, additional questions arise:
At this point, the issue is no longer simply whether RTGS can be restored. It becomes a question of how BDCB strategically manages the wider situation.
A useful distinction for BDCB practitioners is:
BCM primarily manages the consequences of operational disruption.
Its principal concern is the availability and recovery of:
CM primarily manages the strategic consequences of an abnormal and potentially escalating situation.
Its principal concerns include:
The distinction should not create organisational silos. Instead, it helps determine which management capability should lead which part of the response.
ISO 22361:2022 guides organisations to develop a strategic crisis-management capability. The standard specifically addresses organisational context, capability development, crisis leadership, decision-making challenges, crisis communication, training, validation, and learning.
Importantly, ISO also states that crisis management has relationships and interdependencies with other disciplines while remaining distinct from them.
This supports an integrated approach for BDCB.
The Crisis Management Team should not attempt to replace BCM, cybersecurity, technology recovery, emergency response, security, or specialist operational teams. Instead, CM should provide the strategic layer of leadership and coordination when consequences exceed the scope of routine management.
For BDCB, this distinction is particularly relevant because a serious incident can develop consequences across organisational boundaries and potentially affect regulated entities and financial infrastructure.
ISO 22361 does not prescribe a fixed list of sector-specific crisis types; its guidance is designed for organisations generally. Accordingly, BDCB should identify crisis scenarios from its own organisational context, mandate, dependencies, and risk environment.
For this implementation guide, BDCB's crisis landscape should include the following planning categories.
|
Crisis Category |
Illustrative BDCB Scenario |
Principal CM Concern |
|
Natural |
Severe flooding, extreme weather, and regional natural disasters |
Simultaneous impacts on BDCB, workforce, infrastructure, and financial institutions |
|
Technological |
Critical system, network, or data-centre failure |
Prolonged operational and financial infrastructure disruption |
|
Cyber |
Cyberattack, ransomware, data manipulation |
Availability, confidentiality, integrity, and stakeholder confidence |
|
Payment and Settlement |
RTGS, ACH, or CSD disruption |
Settlement, liquidity, participant coordination, and wider consequences |
|
Financial-System |
Severe institutional stress or contagion |
Financial stability and confidence |
|
Confrontation |
Protest, blockade, or significant stakeholder confrontation |
Safety, access, reputation, and stakeholder management |
|
Malevolence |
Sabotage, hostile attack, extortion, or cyber espionage |
Safety, security, and strategic response |
|
Organisational Misconduct |
Fraud, corruption, deception, or serious governance failure |
Integrity, accountability, legal and reputational consequences |
|
Workplace Violence |
Armed intruder or serious violent incident |
Life safety, workforce welfare, and organisational response |
|
Rumours / Misinformation |
False information concerning BDCB, currency, or financial stability |
Confidence and crisis communication |
|
People |
Pandemic or widespread critical-staff unavailability |
Leadership, continuity, and sustained organisational capability |
|
Third Party / Supply Chain |
Failure of critical technology, telecom, or service provider |
Dependency management and cascading disruption |
These scenarios should be treated as illustrative planning assumptions, not statements that the events have occurred at BDCB.
A business continuity event may remain a BCM issue throughout its lifecycle.
For example, a temporary premises outage may be managed effectively using an alternate worksite without significant strategic consequences.
However, CM may need to be activated when the disruption begins generating broader consequences.
A useful escalation model is:
This should be converted into a standalone professional diagram titled “From Business Disruption to Strategic Crisis”.
The decision to activate CM should therefore not depend solely on elapsed time or operational severity.
Escalation indicators can include:
During a major event, the two capabilities should operate concurrently.
Business Continuity Management → Maintain and Recover Critical Business Functions
Crisis Management → Provide Strategic Leadership, Direction and Coordination
Both contribute to:
Organisational Stabilisation → Sustainable Recovery → Lessons Learned and Improvement
These should be converted into a professional integrated diagram titled “Integrating Crisis Management and Business Continuity Management”.
The relationship can be understood through three management levels.
Senior management determines strategic priorities, risk posture, stakeholder approach, and organisational response.
Business, technology, communications, security, BCM, and other teams coordinate implementation.
Affected functions execute continuity procedures, technology recovery, alternative working arrangements, and operational restoration.
This separation preserves clear responsibilities while enabling coordinated response.
Not every disruption requires activation of the Crisis Management Team.
Examples could include:
In such circumstances, BCM or normal incident-management arrangements may be sufficient.
CM should not become an additional approval layer for every operational disruption.
Conversely, some crises may require substantial strategic management even when BDCB's critical business functions remain operational.
Examples could include:
In these situations, the organisation may be operationally functioning but strategically in crisis.
This is one of the most important differences between CM and BCM.
It would be misleading to treat Crisis Management simply as the highest level of Business Continuity Management.
The two capabilities overlap, but they solve different management problems.
BCM is fundamentally concerned with the continuity of critical activities following disruption.
CM is fundamentally concerned with the strategic leadership of an abnormal, uncertain, and consequential situation.
A severe disaster can create a crisis, but severity alone does not define the distinction.
Similarly, a crisis can occur without a major business interruption.
This principle is consistent with ISO 22361's treatment of crisis management as a distinct strategic capability that nevertheless has relationships and interdependencies with other organisational disciplines.
BDCB should establish clearly defined governance arrangements identifying when responsibility remains with operational management, when BCM arrangements are activated, and when escalation to the Crisis Management Team is required.
An integrated activation framework could operate as follows:
Event Detected → Operational Assessment → Incident Management
If critical business functions are disrupted:
Activate Business Continuity Arrangements
If strategic consequences or significant uncertainty emerge:
Escalate to Crisis Management
Where both conditions exist:
BCM and CM Operate Concurrently Under Coordinated Governance
The framework should define:
BCMpedia describes disaster declaration as the process used to activate BC, DR or CM arrangements after a disaster or emergency and notes the role of authorised personnel in initiating pre-arranged actions.
BCM and CM also have different but complementary responsibilities during recovery.
BCM focuses on:
CM maintains strategic oversight of:
The Crisis Management Team should therefore not necessarily stand down simply because a disrupted system has been restored.
Technical recovery may occur before strategic recovery is complete.
Both disciplines should ultimately contribute to organisational learning.
Following a significant disruption or crisis, BDCB should review:
The results should feed into revised risk assessments, continuity strategies, crisis scenarios, plans, playbooks, training, and exercises.
This reflects ISO 22361's inclusion of training, validation, and learning as part of an effective strategic crisis-management capability.
When an event occurs, management can use four questions to determine the appropriate response:
|
Question |
If Yes |
Primary Capability |
|
Are critical business functions disrupted or likely to be disrupted? |
Continuity arrangements are required |
BCM |
|
Is technology restoration required? |
Technology recovery arrangements are required |
IT Disaster Recovery |
|
Does the situation require strategic decisions beyond normal operational authority? |
Strategic crisis leadership is required |
CM |
|
Are both operational continuity and strategic consequences present? |
Integrated response is required |
BCM + CM |
The fourth situation is particularly important for BDCB.
A major cyberattack, prolonged payment-system disruption, widespread natural disaster or multi-institution financial event could require several specialist capabilities to operate simultaneously.
The distinction can ultimately be summarised through two questions:
Can BDCB continue and recover its critical business functions?
Can BDCB strategically manage the wider situation, uncertainty, and consequences?
For a significant crisis, BDCB may need to answer both questions simultaneously.
Crisis Management and Business Continuity Management are distinct but interconnected organisational capabilities.
BCMpedia's disaster definition emphasises an event that can cause serious loss and prevent an organisation from providing critical business functions, while its crisis-scenario definition focuses on an assumed situation that might disrupt the organisation and require human intervention and action.
For BDCB, BCM should primarily protect the continuity and recovery of critical business functions, while CM should provide the strategic leadership, decision-making, coordination, and communication needed to manage crisis-level consequences.
The distinction is especially significant because BDCB's responsibilities include monetary policy, currency issuance, financial-sector regulation and supervision, financial-system stability, and efficient payment systems.
BDCB also operates RTGS, ACH, and CSD, creating important relationships with financial institutions and financial-market infrastructure.
ISO 22361 reinforces this strategic perspective by treating crisis management as a capability involving context, leadership, decision-making, communication, training, validation, and learning, while acknowledging its relationships and interdependencies with other disciplines.
The implementation principle for BDCB is therefore:
BCM maintains continuity. CM maintains strategic control.
When a major event creates both operational disruption and strategic consequences, BCM and CM should operate concurrently—each performing its distinct role within an integrated organisational response.
| eBook 1: Understanding Your Organisation | ||||||
| C1 | C2 | C3 | C4 | C5 [x] | C5A | C6 [x] |
| C7 [x] | C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] |
To learn more about the course and schedule, click the buttons below for the CM-300 Crisis Management Implementer [CM-3] and the CM-5000 Crisis Management Expert Implementer [CM-5].
|
Please feel free to send us a note if you have any questions. |
||