27.05.2025
Blog
Resilience
Cyber Security

Resilience and Business Continuity in the Public Sector – Crisis-proof and Future-proof

Effective business continuity management (BCM) helps organisations become more resilient and manage crises in a structured manner. Without BCM, organisations are at risk of disruption – whether from cyber-attacks or unforeseeable events such as natural disasters.

Robert Stricker
Vice President Security Consulting

According to a Bitkom study, 76 per cent of respondents believe that the public sector is less well prepared for cyber-attacks than the private sector. At the same time, there is a significant need for improvement in the implementation of IT security standards and contingency plans.

Ensuring the operational capability of state institutions is essential, particularly in the context of geopolitical tensions. The “Operations Plan Germany”, drawn up in the context of a potential NATO alliance case in 2029, underlines the need to specifically integrate resilience and business continuity strategies. This includes the expansion of critical infrastructure and effective crisis preparedness. Inter-municipal and international cooperation is necessary to minimise logistical bottlenecks. The public sector must act proactively to remain resilient under extreme conditions. The ‘Operations Plan Germany’ provides a framework for combining existing security concepts with modern resilience strategies, thereby ensuring sustainable crisis management.

BCM as a strategic task

  • Safeguarding public services
  • Compliance with regulatory requirements
  • Protection of critical infrastructure and sensitive data
  • Minimising financial and reputational damage
  • Coordination with IT service providers and external partners

Resilience and BCM: Two sides of the same coin

Resilience is the ability to adapt to external influences and recover quickly from disruptions. BCM serves as a structured approach to strengthening this capability by establishing contingency plans and preventative measures. The aim is to minimise ‘headless chicken mode’ – uncoordinated action in crisis situations.

Regulatory requirements and practical implementation

There are numerous requirements set out in both international standards (ISO 22301, ISO 27001) and national standards (BSI 200-4, KRITIS regulations) that are necessary for effective BCM. Despite the complexity, pragmatic implementation is possible – through regular training, the allocation of responsibilities, system updates and defined emergency procedures.

The rhino principle

Robust, vigilant and resilient – the rhinoceros symbolises successful BCM. Anyone wishing to make their organisation crisis-proof should think strategically, act preventatively and build long-term resilience.

  • Regulatory requirements and compliance – Strategic objectives and guidelines for BCM that are linked to the organisation’s goals. It is important for management to set top-down objectives in order to create a resilient organisation.
  • Human Firewall – Raising staff awareness of security risks. A culture that embraces mistakes and failures helps to prevent panic in an emergency.
  • Intrusion Prevention – Preventive security measures such as network segmentation, system hardening and multi-factor authentication reduce the attack surface and strengthen the organisation’s ability to respond.
  • Contingency plans and crisis management – Clear responsibilities, decision-making structures and communication channels in the event of a crisis are essential. A crisis management team must be prepared and capable of taking action.
  • Optimisation and continuous improvement – BCM is an ongoing process. Security measures must be regularly reviewed and adapted to ensure the organisation remains resilient in the long term. 

Effective BCM requires strategic support, sufficient resources, consistent implementation and continuous improvement. Managers should not only delegate but also provide active support. A resilient organisation is better able to cope with emergencies and remains capable of functioning despite them. 

Defining responsibilities 

In an emergency, a targeted approach is crucial. Well-intentioned but uncoordinated help can do more harm than good. Clear responsibilities, defined procedures and effective communication management are essential. Acting independently without consultation should be avoided. Who is responsible for Business Continuity Management (BCM)? A designated person, a crisis management team with defined roles, and decision-making processes are required. These must be established and practised in advance so that there is no need to improvise in stressful situations. Clear lines of communication and flat decision-making structures are essential for rapid responses. 

Resilience also means planning for stand-ins – having just one BCM officer is not a sustainable solution. Equally important are the areas where people are not responsible: during a crisis, nobody should be burdened with irrelevant tasks. Regular drills help to identify errors at an early stage and optimise processes. 

Key steps: 

  • Business process analysis: identifying critical processes and dependencies
  • Business Impact Analysis (BIA): Assessment of the consequences of outages
  • Contingency plans: Documentation of measures with realistic recovery times
  • Tests and exercises: Regular validation and optimisation 

BCM ensures resilience and enables organisations to remain operational. Getting started is more important than perfection – it is better to start small than not at all. 

Further information: Business Continuity Management 

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more