Skip to content

Emergency Plans Fail Due to External Dependencies – BCM Programmes Outpace Many Companies

The bottom line: 76 percent of companies experienced disruptions caused by external partners with damages sometimes exceeding 10 million dollars, yet only 31 percent conduct joint tests with critical third-party providers.

Traditional emergency plans no longer protect against modern outage risks. While 92 percent of companies believe they can achieve their recovery objectives, fewer than 40 percent succeed in a real emergency – because they understand and test external dependencies too little.

The current Optro BCM Report 2026, based on 506 surveys of risk, compliance, audit, BCM and IT executives in North America, the United Kingdom, Germany and the United Arab Emirates, reveals a significant gap between planning and reality: 92 percent of companies are convinced they can achieve their defined recovery objectives in a real emergency. However, fewer than 40 percent actually managed to do so during the last major disruption.

The cause lies in an outdated architecture of emergency planning programmes. Many BCM plans date from a time when applications ran in their own data centres, supply chains were manageable and critical business processes largely remained within company boundaries. Today, companies operate in networked ecosystems of cloud infrastructures, SaaS platforms, external service providers and digital supply chains – traditional BCM is no longer sufficient. 76 percent of surveyed companies experienced disruptions caused by external partners over the past two years. Almost half reported damage of at least one million US dollars, while in Germany 8.2 percent reported losses exceeding ten million US dollars.

The central problem does not lie in insufficient investment. Companies have been investing in emergency plans, governance structures and restart concepts for years – but operational implementation under real conditions often fails. This is evident in another figure: 91 percent of surveyed organisations report negative impacts on customers and employees resulting from insufficient response to outages.

Particularly critical is the testing deficit with third-party providers: only 31 percent of surveyed organisations conduct joint continuity or crisis tests with critical third-party providers. The majority instead rely on contracts, documentation and assurances without validating these under realistic conditions. Cloud infrastructure is cited in the report as the most common single third-party risk. The failure of a cloud provider can today affect hundreds of business processes simultaneously, and disruptions in identity services, data platforms or communication systems can spread throughout entire organisations within minutes.


Source: www.it-daily.net · Published 17 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: