Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

Business Continuity Basics for Non-Technical Managers

Floods, power failures, a ransomware incident, a supplier collapse, a building nobody can enter. Malaysian businesses meet these regularly, and the ones that recover fastest are the ones that decided in advance who does what. This one-day programme is written for managers without a technical or risk background. Participants work out which activities cannot stop, how long each can be down before real damage, what the first hour looks like, and how to test the plan so it is not discovered to be fiction during an actual incident.

Programme Agenda

Continuity, Disaster Recovery and Crisis Management
Three related things that get confused. What business continuity covers, where IT disaster recovery sits inside it, and when an incident becomes a crisis requiring different decision-making and different people.

Threats That Actually Disrupt Malaysian Operations
Flooding and monsoon disruption, power and connectivity loss, fire and building access, ransomware and system outage, supplier and logistics failure, key-person loss, and public health disruption. Assessing each on likelihood and impact for your own operation.

Business Impact Analysis
Listing your business activities and identifying the critical few. Working out the financial, regulatory, reputational and contractual consequences of each being unavailable for an hour, a day, a week. The exercise that decides everything else in the plan.

RTO, RPO and Minimum Operating Requirements
Recovery time objective and recovery point objective in plain terms, set by the business rather than by IT. Defining the minimum people, systems, data, premises and suppliers needed to keep a critical activity running at a reduced level.

Building the Continuity Plan
Activation triggers and who has authority to declare. Roles and responsibilities with named deputies, workarounds and manual fallbacks, alternate sites and remote working arrangements, and the call tree and contact list that works when the office phone system is down.

Crisis Response and the First Hour
The crisis team, the initial assessment, and the decisions that have to be made before information is complete. Logging decisions as you go, and the common failure of everyone waiting for one person who is unreachable.

Crisis Communication
Who speaks to staff, customers, suppliers, regulators and the public, and in what order. Holding statements prepared in advance, managing social media during an incident, and the notification obligations that may apply, including personal data breach expectations under the PDPA.

Testing, Review and Keeping It Alive
Walkthroughs, tabletop exercises and full simulations, and what each is worth. Running a tabletop exercise in the session on a realistic scenario, capturing what failed, and setting the review cycle that stops the plan going stale.

Learning Outcomes:
Distinguish business continuity, disaster recovery and crisis management
Assess the disruption scenarios most likely to affect your operation
Run a business impact analysis and identify your critical activities
Set RTO and RPO from business consequence, not IT preference
Define the minimum operating requirements for each critical activity
Draft a continuity plan with activation triggers and named roles
Run the first hour of a crisis and communicate to each audience
Test a plan through a tabletop exercise and act on what fails

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Beginner to Intermediate
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Operations, admin, facilities and department managers, business owners and SME management, and HR or finance staff who end up coordinating during an incident. IT staff attend too, usually to get the business side of recovery objectives agreed with the people who own the decision.

No. The programme is deliberately written for non-technical managers. Technical recovery detail is treated as something you specify requirements for and then hold IT or a vendor accountable to, not something you configure yourself.

A cyber incident is one disruption scenario among several here, and the plan you build covers flooding, power loss, supplier failure and key-person loss too. For the technical response to a security incident specifically, see our data breach response and incident management programme.

Yes. The final session is a tabletop exercise on a realistic scenario, run against the plans participants drafted during the day. The debrief is usually where people discover which assumptions in their plan do not hold.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.