"In a crisis, the plan you trained for is the only plan you have."
Business Continuity Planning
Instructor Sele: The crisis is over. The client's building is damaged, some staff are shaken, and operations are disrupted. Your job does not end when the fire is out. SafeHaven professionals support clients not just through the crisis — but through the recovery. This final module covers business continuity and closes out the course.
Section 1 — What Is Business Continuity Planning?
Business Continuity Planning (BCP) is the process of ensuring that a client's essential functions can continue — or be rapidly restored — following a crisis. For a security operation, BCP means: maintaining security coverage during the recovery period; supporting the client's return to normal operations safely; adapting the security posture to the changed environment (damaged infrastructure, disrupted access, elevated threat following the incident); documenting the recovery process for legal, insurance, and operational purposes.
Section 2 — The Security Component of BCP
Following a major incident, the security team's BCP responsibilities include: Site assessment — assess all access points, perimeter integrity, CCTV systems, and communication systems for damage. Access control restoration — establish temporary access control if the permanent system is damaged. Guard deployment review — adjust post deployments to account for changed site conditions. Threat reassessment — the incident itself may have elevated the threat level; update the threat assessment immediately. Client briefing — advise the client on security implications of the recovery plan.
Section 3 — The Emergency Response Plan (ERP)
The ERP is the pre-prepared document that defines all roles, responsibilities, and actions for identified emergency scenarios at a specific site. A complete ERP includes: identified emergency scenarios (fire, medical, bomb threat, armed intrusion, civil unrest, natural disaster); command structure and IC designation for each scenario; evacuation routes and assembly points; communication plan and contact list; resource list (extinguishers, first aid, emergency equipment locations); post-incident recovery procedures.
The ERP must be reviewed annually, updated after every major incident, and briefed to all staff before their first shift. An ERP that sits in a drawer is not an ERP — it is a liability.
Section 4 — Course 5 Review — Key Principles
Across all 10 modules, Course 5 is built on five crisis management principles: Prepare before — not during: training, plans, and drills must exist before the crisis arrives. One IC, one command: every crisis response has a single Incident Commander. Life before property: every decision in a crisis prioritises human life above all else. Communicate with control: authorised communication only, facts only. Learn from every incident: the hot wash and AAR are not optional.
- •BCP ensures essential functions continue or are rapidly restored after a crisis
- •Post-incident security BCP: assess the site, restore access control, adjust deployments, reassess the threat
- •The ERP must be reviewed annually and updated after every major incident
- •The five crisis principles: prepare before; one IC; life before property; communicate with control; learn from every incident
- •Completion of Course 5 qualifies SafeHaven guards for crisis response and emergency co-ordinator roles
"After every major incident I have managed, I ask myself one question: what would have been different if we had been better prepared? Every answer to that question becomes a training objective. The guards who impress me most are not the ones who are calm in a crisis because they are naturally calm — it is the ones who are calm because they have trained for it so many times that the crisis feels familiar. Preparation is courage in advance. This course is that preparation."
Which of the following best describes "Business Continuity Planning" in a security context?