15.07.2025
Blog
Regulatory
Verwaltung Digital
Cyber Security
Public Sector

Regulation as a strategic lever for resilience

Organisations – whether in the private or public sector – are now under increasing pressure to implement regulatory requirements such as ISO 22301, BSI 200-4 or, in future, NIS2 in a meaningful way. This article shows how companies and public authorities can use regulatory requirements as the foundation for an integrated and successful Business Continuity Management (BCM) framework.

Robert Stricker
Vice President, Security Consulting

Resilience is currently in high demand everywhere and is emerging as a new trend, not just in the field of cyber security. Whilst resilience describes the ability to be robust, withstand disruptions and recover quickly, BCM is the systematic approach to achieving this. It protects organisations from falling into the infamous ‘headless chicken mode’ – that is, reacting to crises in an uncoordinated and haphazard manner.

To promote resilience within organisations, we have developed the RHINO principle. It symbolises resilience; it is robust and resilient, and therefore offers little opportunity for attack.

The principle is based on five pillars (R-H-I-N-O):

  • R – Regulation & Compliance
  • H – Human Firewall
  • I – Intrusion Prevention
  • N – Contingency Plans & Crisis Management
  • O – Optimisation & Continuous Improvement

The first letter of the Nashorn Principle stands for a key success factor: regulation and compliance. They establish binding guidelines, promote clear structures and make resilience measurable and manageable. Anyone wishing to build a strategic BCM framework cannot ignore them.

Business Continuity Management operates within the complex interplay of numerous standards and legal requirements – at both national and international levels. Organisations, particularly in the public sector or in the field of critical infrastructure, must navigate a complex regulatory framework. This interplay includes, amongst other things:

International standards

  • ISO 22301 is the key international standard for Business Continuity Management. It defines the requirements for an effective management system to ensure business continuity. The aim is to ensure that the organisation remains operational even in the event of a crisis – through resilient processes, structures and contingency plans.
  • ISO/IEC 27001 complements this focus by setting out requirements for an information security management system (ISMS). After all, without a secure IT infrastructure, true continuity is not possible – IT risks and BCM are closely interlinked.

National standards

  • BSI Standard 200-4 from the Federal Office for Information Security is a BCM guide specifically tailored to Germany. It describes a three-stage maturity model for BCM and takes into account both small public authorities and large corporations. Particularly valuable: implementation can be carried out in a modular manner – ideal for the public sector.
  • KRITIS requirements (e.g. under Section 8a of the BSIG) apply to operators of critical infrastructure (e.g. energy, healthcare, water, IT, etc.). They are obliged to take appropriate organisational and technical measures to ensure the availability of their services – this requires a BCM as a foundation. Implementation is regularly audited.

Important to note:

Although the national transposition law has not yet come into force, the NIS2 Directive remains binding at EU level. Companies should therefore take a proactive approach and prepare for the upcoming requirements. This includes, in particular:

  • Assessing whether the organisation is affected: Determining whether the organisation falls within the scope of the extended NIS2 regulations.
  • Implementing security measures: Introducing or adapting information security management systems (ISMS) in accordance with the requirements of NIS2.
  • Training and awareness-raising: Staff, particularly those in management positions, should be informed about the new obligations and trained accordingly.

Regulations as a guide

These regulatory frameworks provide the basis for the development and implementation of business continuity management. Anyone who takes resilience seriously cannot ignore regulatory requirements. However, rather than viewing them as a burden, they should be used as a guide and an opportunity. When combined with a clear strategy and genuine leadership responsibility, they result in a resilient organisation – vigilant, robust and capable of taking action. Just like our symbol: the rhinoceros.

In the next article, you’ll read about the role employees play in building and maintaining a resilient organisation.

Robert Stricker
Vice President, Security Consulting

Robert Stricker is Vice President of Security Consulting at Materna.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more