08Organisational level

Business continuity and disaster recovery

The learning path builds the business continuity programme an organisation needs in order to carry on delivering its services when something breaks: how the cost of downtime is measured with the business impact analysis, how recovery strategies are chosen, how the business continuity plan and the recovery plan are written, how they are tested and how you demonstrate to whoever audits you that they exist and that they work.

ISO 22301Business impact analysisStrategies and plansNIS2 and DORA

Enrol meI already have an account

6modules
26estimated hours
96test questions
6exercises
30questions in the final test

How it is delivered

Delivery
Entirely online and asynchronous, from any device: you study when you want, at your own pace.
Passing the tests
At least 70% correct answers; every answer comes with an explanation of why.
Attempts per test
Unlimited: the best attempt counts.
Time per test
20-40 minutes per test.
Progress
Tracked module by module: each module unlocks when you pass the test of the previous one.
On completion
A personal PDF certificate, with a unique verification code.
Length of access
You have 90 days from enrolment to complete the learning path. Once you complete it your access stays available with no expiry; if the deadline passes without the path being completed, the enrolment is suspended and the results you have already achieved stay on record.
Enrolment
With a personal key, after you have created your account.

The learning path in detail

Welcome. Every organisation, sooner or later, comes to a stop: a failure, an attack, a supplier that does not answer, a site that cannot be used, a person missing at the wrong moment. The difference between a disruption that is managed and one that is merely suffered is not decided on the day it happens: it is decided beforehand, with the work this learning path teaches you to do.

The thread running through it is a single question, repeated in every module with increasing precision: how long can we be down, and what does it take not to exceed that? From the answer follow the parameters (Module 2), the strategies (Module 3), the plans (Module 4), the tests (Module 5) and the evidence that whoever audits you will ask to see (Module 6).

The methodological reference is ISO 22301, read together with ISO 22317 for business impact analysis and ISO 22313 for implementation. The legal reference is the European and Italian framework that today asks for continuity explicitly: Directive (EU) 2022/2555 (NIS2) with Legislative Decree 138/2024 and the determinations of the ACN (Italy's National Cybersecurity Agency), Regulation (EU) 2022/2554 (DORA) for the financial sector and Article 32 of the GDPR on the timely restoration of the availability of personal data.

Learning objectives

By the end of the learning path you will be able to:

  • use the vocabulary of business continuity precisely and distinguish continuity, resilience, disaster recovery, emergency and crisis, which are not synonyms and do not call out the same people (Module 1);
  • run a business impact analysis and draw from it the parameters that order the programme: MTPD, RTO, RPO and MBCO, with the dependency map that makes them realistic (Module 2);
  • choose continuity and recovery strategies by comparing the cost of the solution with the cost of unavailability, and design a backup setup that can withstand an attack with encryption (Module 3);
  • write a business continuity plan and a recovery plan that can be used under pressure, with activation criteria, crisis team, communication and return to normal operations (Module 4);
  • design and run the tests of the plan, measure their outcome with indicators declared in advance and turn the lessons learned into actual changes (Module 5);
  • place the continuity programme within the applicable regulatory framework and keep ready the evidence file that an inspection, an audit or a customer will ask to see (Module 6).

Who it is for and prerequisites

No advanced technical skills are needed: the learning path explains the concepts from scratch and treats continuity as a problem of organisation before it is one of technology. It is useful, but not compulsory, to have followed Information Security Fundamentals first for the concepts of risk and control, and Incident management and response, on which this learning path borders: incident response stops the bleeding, continuity keeps the service standing while the bleeding is being stopped. The two processes start together and Module 4 shows how they connect.

How the course is delivered

The learning path is delivered entirely online, asynchronously: you can study when you want, at your own pace, from any device. The estimated total duration is 26 hours, to be spread within the completion deadline set out below.

Each module is organised into four lessons and two tests:

  1. Lesson. A reasoned treatment of the topic, with diagrams, examples and concrete cases.
  2. In depth. The up to date regulatory and technical framework, with the deadlines that count and references that can be checked at the source.
  3. Real cases. What actually happens in the market: documented episodes always read through the same grid, down to the control that would have broken the chain.
  4. In practice. What you do on Monday morning: procedures, checklists, ready-made templates and indicators with which to measure the result.
  5. Test. Closed answer questions on all four lessons of the module. Passing requires at least 70%; attempts are unlimited and the best mark counts. At the end of each attempt you get a precise explanation of every answer, including the correct ones.
  6. Exercise. A case to work through by deciding: every choice opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. Marking is automatic and you can retake it as many times as you like.

Progression. The 6 modules are taken in sequence: each module unlocks only after you have passed the test of the previous module.

Final test and certificate

Once you have passed the tests of every module, the final test is unlocked: 30 questions drawn at random from the topics of the whole learning path, with the same 70% pass mark and unlimited attempts. On passing it you obtain the learning path certificate, downloadable as a PDF, with a unique code that allows its authenticity to be verified.

Warning

The content is up to date as of August 2026. Two warnings specific to this subject. The first: the numerical values used in the examples (recovery objectives, hourly cost of downtime, test durations) are realistic but remain examples, and always have to be recalculated for your own context, because an objective copied from another organisation is the leading cause of plans that do not hold. The second: the rules cited have application timetables of their own and those are still moving, so before planning any compliance activity always check the official texts on EUR-Lex, in the Italian Official Journal and on the website of the ACN (Italy's National Cybersecurity Agency).

Completion deadline

You have 90 days from enrolment to complete the learning path. 15 days before the deadline you receive an email reminder.

If you complete the path within the deadline, your access stays available with no time limit and you receive the certificate. If the deadline passes without the path being completed, the enrolment is suspended: the results you have already achieved stay on record, and to carry on you need a new enrolment key.

Support

In the Announcements forum you will find messages from the tutor. For questions about the content or the exercises, use the channels indicated by your training contact.

Programme

The modules are taken in sequence: each one opens when you pass the test of the previous one.

  1. Module 1

    Business continuity: what it is, what it is not, who requires it

    The vocabulary that everything else rests on: business continuity, resilience, disaster recovery, emergency and crisis. What ISO 22301 adds compared with a plan written once, how the scope of the programme is bounded, who governs it and why the continuity policy is the first document and not the last.

    LessonLessonLessonLessonTest · 16 questionsExercise

  2. Module 2

    Business impact analysis and risk assessment

    The business impact analysis: which processes cannot stop, for how long, and what the outage costs. The four parameters that order the whole programme (MTPD, RTO, RPO, MBCO), the map of dependencies on people, suppliers, systems and sites, and the link between business impact analysis and risk assessment, which answer two different questions.

    LessonLessonLessonLessonTest · 16 questionsExercise

  3. Module 3

    Continuity and recovery strategies

    How outages are avoided and how you come back from them: redundancy and high availability, backups that stand up to ransomware (3-2-1-1-0, immutable copies, isolation), alternative sites and recovery in the cloud, continuity of people and of workstations. How to choose between the options by comparing the cost of the solution with the cost of unavailability.

    LessonLessonLessonLessonTest · 16 questionsExercise

  4. Module 4

    The plans: BCP, DRP and crisis management

    What a business continuity plan contains and how it differs from a technical recovery plan. The criteria and the procedure for invoking it, the crisis team with delegations and deputies, internal and external communication during the event, the recovery runbook and the return to normal operations, which is the phase everyone forgets to write.

    LessonLessonLessonLessonTest · 16 questionsExercise

  5. Module 5

    Testing the plan: exercises, tests and improvement

    A plan that has not been tested is a hypothesis. The types of test, from the desk review to live failover, with rising cost and realism; how you design an exercise with success criteria fixed in advance; the indicators with which continuity is measured, the internal audit and the management review, and the way lessons learned find their way back into the plan.

    LessonLessonLessonLessonTest · 16 questionsExercise

  6. Module 6

    Continuity and compliance: NIS2, DORA, GDPR and suppliers

    The rules that require continuity and what exactly they require: NIS2 and Legislative Decree 138/2024 with the ACN (Italy's National Cybersecurity Agency) measures, the DORA Regulation for the financial sector, Article 32 of the GDPR on restoring availability. Continuity in the supply chain, between contractual clauses, service levels and checks, and the evidence file to keep ready.

    LessonLessonLessonLessonTest · 16 questionsExercise

  7. Final test and certificate

    Thirty questions drawn at random from the topics of all the modules. On passing, the certificate for the learning path is issued.

    Test · 30 questionsCertificate

How to get access to the learning path

To follow "Business continuity and disaster recovery" you need an account on the platform: registration is free and takes a minute. Once the account is created you can request the enrolment key for the learning path.

Enrol meI already have an account

Back to all learning paths