15.07.2025
Blog
Regulatory
Verwaltung Digital
Cyber Security
Public Sector

Regulation as a strategic lever for resilience

Organisations – whether in the private or public sector – are now under increasing pressure to implement regulatory requirements such as ISO 22301, BSI 200-4 or, in future, NIS2 in a meaningful way. This article shows how companies and public authorities can use regulatory requirements as the foundation for an integrated and successful Business Continuity Management (BCM) framework.

Robert Stricker
Vice President Security Consulting

Resilience is currently in high demand everywhere and is emerging as a new trend, not just in the field of cyber security. Whilst resilience describes the ability to be robust, withstand disruptions and recover quickly, BCM is the systematic approach to achieving this. It protects organisations from falling into the infamous ‘headless chicken mode’ – that is, reacting to crises in an uncoordinated and haphazard manner.

To promote resilience within organisations, we have developed the RHINO principle. It symbolises resilience; it is robust and resilient, and therefore offers little opportunity for attack.

The principle is based on five pillars (R-H-I-N-O):

  • R – Regulation & Compliance
  • H – Human Firewall
  • I – Intrusion Prevention
  • N – Contingency Plans & Crisis Management
  • O – Optimisation & Continuous Improvement

The first letter of the Nashorn Principle stands for a key success factor: regulation and compliance. They establish binding guidelines, promote clear structures and make resilience measurable and manageable. Anyone wishing to build a strategic BCM framework cannot ignore them.

Business Continuity Management operates within the complex interplay of numerous standards and legal requirements – at both national and international levels. Organisations, particularly in the public sector or in the field of critical infrastructure, must navigate a complex regulatory framework. This interplay includes, amongst other things:

International standards

  • ISO 22301 is the key international standard for Business Continuity Management. It defines the requirements for an effective management system to ensure business continuity. The aim is to ensure that the organisation remains operational even in the event of a crisis – through resilient processes, structures and contingency plans.
  • ISO/IEC 27001 complements this focus by setting out requirements for an information security management system (ISMS). After all, without a secure IT infrastructure, true continuity is not possible – IT risks and BCM are closely interlinked.

National standards

  • BSI Standard 200-4 from the Federal Office for Information Security is a BCM guide specifically tailored to Germany. It describes a three-stage maturity model for BCM and takes into account both small public authorities and large corporations. Particularly valuable: implementation can be carried out in a modular manner – ideal for the public sector.
  • KRITIS requirements (e.g. under Section 8a of the BSIG) apply to operators of critical infrastructure (e.g. energy, healthcare, water, IT, etc.). They are obliged to take appropriate organisational and technical measures to ensure the availability of their services – this requires a BCM as a foundation. Implementation is regularly audited.

Important to note:

Although the national transposition law has not yet come into force, the NIS2 Directive remains binding at EU level. Companies should therefore take a proactive approach and prepare for the upcoming requirements. This includes, in particular:

  • Assessing whether the organisation is affected: Determining whether the organisation falls within the scope of the extended NIS2 regulations.
  • Implementing security measures: Introducing or adapting information security management systems (ISMS) in accordance with the requirements of NIS2.
  • Training and awareness-raising: Staff, particularly those in management positions, should be informed about the new obligations and trained accordingly.

Regulations as a guide

These regulatory frameworks provide the basis for the development and implementation of business continuity management. Anyone who takes resilience seriously cannot ignore regulatory requirements. However, rather than viewing them as a burden, they should be used as a guide and an opportunity. When combined with a clear strategy and genuine leadership responsibility, they result in a resilient organisation – vigilant, robust and capable of taking action. Just like our symbol: the rhinoceros.

In the next article, you’ll read about the role employees play in building and maintaining a resilient organisation.

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more