27.05.2025
Blog
Resilience
Cyber Security

Resilience and Business Continuity in the Public Sector – Crisis-proof and Future-proof

Effective business continuity management (BCM) helps organisations become more resilient and manage crises in a structured manner. Without BCM, organisations are at risk of disruption – whether from cyber-attacks or unforeseeable events such as natural disasters.

Robert Stricker
Vice President, Security Consulting

According to a Bitkom study, 76 per cent of respondents believe that the public sector is less well prepared for cyber-attacks than the private sector. At the same time, there is a significant need for improvement in the implementation of IT security standards and contingency plans.

Ensuring the operational capability of state institutions is essential, particularly in the context of geopolitical tensions. The “Operations Plan Germany”, drawn up in the context of a potential NATO alliance case in 2029, underlines the need to specifically integrate resilience and business continuity strategies. This includes the expansion of critical infrastructure and effective crisis preparedness. Inter-municipal and international cooperation is necessary to minimise logistical bottlenecks. The public sector must act proactively to remain resilient under extreme conditions. The ‘Operations Plan Germany’ provides a framework for combining existing security concepts with modern resilience strategies, thereby ensuring sustainable crisis management.

BCM as a strategic task

  • Safeguarding public services
  • Compliance with regulatory requirements
  • Protection of critical infrastructure and sensitive data
  • Minimising financial and reputational damage
  • Coordination with IT service providers and external partners

Resilience and BCM: Two sides of the same coin

Resilience is the ability to adapt to external influences and recover quickly from disruptions. BCM serves as a structured approach to strengthening this capability by establishing contingency plans and preventative measures. The aim is to minimise ‘headless chicken mode’ – uncoordinated action in crisis situations.

Regulatory requirements and practical implementation

There are numerous requirements set out in both international standards (ISO 22301, ISO 27001) and national standards (BSI 200-4, KRITIS regulations) that are necessary for effective BCM. Despite the complexity, pragmatic implementation is possible – through regular training, the allocation of responsibilities, system updates and defined emergency procedures.

The rhino principle

Robust, vigilant and resilient – the rhinoceros symbolises successful BCM. Anyone wishing to make their organisation crisis-proof should think strategically, act preventatively and build long-term resilience.

  • Regulatory requirements and compliance – Strategic objectives and guidelines for BCM that are linked to the organisation’s goals. It is important for management to set top-down objectives in order to create a resilient organisation.
  • Human Firewall – Raising staff awareness of security risks. A culture that embraces mistakes and failures helps to prevent panic in an emergency.
  • Intrusion Prevention – Preventive security measures such as network segmentation, system hardening and multi-factor authentication reduce the attack surface and strengthen the organisation’s ability to respond.
  • Contingency plans and crisis management – Clear responsibilities, decision-making structures and communication channels in the event of a crisis are essential. A crisis management team must be prepared and capable of taking action.
  • Optimisation and continuous improvement – BCM is an ongoing process. Security measures must be regularly reviewed and adapted to ensure the organisation remains resilient in the long term. 

Effective BCM requires strategic support, sufficient resources, consistent implementation and continuous improvement. Managers should not only delegate but also provide active support. A resilient organisation is better able to cope with emergencies and remains capable of functioning despite them. 

Defining responsibilities 

In an emergency, a targeted approach is crucial. Well-intentioned but uncoordinated help can do more harm than good. Clear responsibilities, defined procedures and effective communication management are essential. Acting independently without consultation should be avoided. Who is responsible for Business Continuity Management (BCM)? A designated person, a crisis management team with defined roles, and decision-making processes are required. These must be established and practised in advance so that there is no need to improvise in stressful situations. Clear lines of communication and flat decision-making structures are essential for rapid responses. 

Resilience also means planning for stand-ins – having just one BCM officer is not a sustainable solution. Equally important are the areas where people are not responsible: during a crisis, nobody should be burdened with irrelevant tasks. Regular drills help to identify errors at an early stage and optimise processes. 

Key steps: 

  • Business process analysis: identifying critical processes and dependencies
  • Business Impact Analysis (BIA): Assessment of the consequences of outages
  • Contingency plans: Documentation of measures with realistic recovery times
  • Tests and exercises: Regular validation and optimisation 

BCM ensures resilience and enables organisations to remain operational. Getting started is more important than perfection – it is better to start small than not at all. 

Further information: Business Continuity Management 

Robert Stricker
Vice President, Security Consulting

Robert Stricker is Vice President of Security Consulting at Materna.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more