There are some possible errors or wrong approaches in BC. The most common are as follows:
- No BI: There may be a BIA, but it's not complete or does not cover all the possible business-related risks.
- Not applied: Some cases are skipped and not considered; perhaps even the entire BC analysis just because it can't happen to me. As with security, all organizations need a proper BCP and all cases must be considered in some way.
- Non-involvement of business level: You cannot understand the risks and define the possible budget to avoid (or minimize) them without the C-levels.
- Technology focus: Written BC is a process, not necessarily a single technical solution. Technologies came later, and can help in some decisions, but are mostly ...