When a crisis occurs, organizations often believe that the event itself will determine the outcome. For example:
- A major cyberattack
- A prolonged power outage
- A supply chain disruption
- A natural disaster
However, it is rarely the event itself that turns a difficult situation into an organizational catastrophe. More often, the real causes can be traced back to mistakes made long before the crisis began.
Over the years, I have seen the same pitfalls emerge repeatedly, regardless of industry, organization size, or type of threat. These mistakes often remain invisible during normal operations but become painfully obvious when pressure rises and every minute counts.
These are what I call the eight deadly sins of business continuity.
1. The Plan Never Tested
A plan may look excellent on paper. But until it has been tested under realistic conditions, no one truly knows whether it will work. The day of the crisis should never be the day of the first exercise.
2. The Plan Written to Pass an Audit
Some organizations develop plans primarily to satisfy regulatory, contractual, or insurance requirements. The document exists, but employees are unfamiliar with it and never use it. A business continuity plan only has value if it helps guide real decisions.
3. The Plan Held by One Person
When critical knowledge resides with a single individual, the organization creates a significant vulnerability. Resignations, absences, vacations, and role changes always seem to occur at the worst possible moment. Resilience must be collective.
4. The Single Scenario Mentality
Being prepared for one situation does not mean being prepared for a crisis. Organizations that plan exclusively for power outages sometimes discover that their real challenge is a cyberattack, loss of facilities, or the failure of a critical supplier. Plans must be flexible enough to adapt to the unexpected.
5. The Supplier Illusion
Outsourcing a service does not mean outsourcing risk. Your supplier can experience a disruption, cyberattack, or operational failure just as easily as you can. Business continuity planning must include critical third-party dependencies.
6. The Perfect Exercise
An exercise where everything goes perfectly is rarely a useful exercise. The true value of an exercise lies in the weaknesses it uncovers before a real crisis exposes them. It is far better to fail in a conference room than during an actual emergency.
7. The Forgotten Plan
Organizations are constantly evolving.
- Teams change.
- Technologies change.
- Suppliers change.
- Priorities change.
A plan that is not reviewed periodically gradually loses its relevance.
8. Leadership-Free Resilience
Business continuity is not solely an operational responsibility. Without leadership commitment, priorities become unclear, investments are postponed, and critical decisions are delayed. Organizational resilience always begins with strong leadership.
Simple Question to Ask Yourself
The presence of one or more of these deadly sins does not necessarily mean that your organization is vulnerable or incapable of overcoming a crisis. It does, however, suggest that there may be blind spots that deserve attention.
Before launching a major review or improvement initiative, take a moment to ask yourself the following question:
“If a major disruption occurred tomorrow morning, am I truly confident that my organization could continue its critical activities using the plans, resources, and mechanisms currently in place?”
If your answer is hesitant, cautious, or comes with several conditions attached, it may be time to revisit assumptions, test your plans, or address identified gaps.
What If You Have No Plan at All?
The absence of a plan is often the greatest sin of all.
Although many organizations recognize the importance of business continuity, crisis management, and IT disaster recovery, many continue to postpone their efforts, believing they will have time to react when a disruption occurs.
Unfortunately, a crisis rarely provides the time or conditions needed to think through governance structures, operational priorities, or recovery strategies.
The good news is that you do not need to start with a complex program or hundreds of pages of documentation. A simple, progressive approach tailored to your organization’s reality can significantly reduce risk.
The goal is not to have the perfect plan.
The goal is to start.
Conclusion
Organizations are rarely brought down by the event itself. More often, they struggle because of vulnerabilities that have been allowed to accumulate over time.
The eight deadly sins presented in this article are not uncommon. On the contrary, they are observed regularly in organizations of all sizes and across all sectors. The good news is that they can be corrected.
Testing plans, diversifying scenarios, updating documentation, engaging leadership, and fostering a genuine culture of resilience can dramatically reduce the consequences of a disruption.
Because when a crisis occurs, it is already too late to build resilience.
Strategic Support to Strengthen Your Resilience
At Benoit Racette Services-conseils inc., we help organizations protect their critical operations, ensure the safety of their teams, and maintain the trust of their clients—even when a major disruption occurs.
With nearly 30 years of specialized experience in business continuity, crisis management, emergency preparedness, and IT disaster recovery planning, Benoit Racette supports organizations with rigor and confidentiality, transforming complex challenges into concrete solutions tailored to their reality.
- Resilience diagnostic
- Updated business continuity plan
- Operational crisis management plan
- Realistic IT disaster recovery plan
- Tests and exercises to validate plans and strengthen teams
- Targeted training in continuity, crisis management, and operational preparedness
These are the tools that distinguish organizations that suffer… from those that respond with control.
Want to assess your vulnerabilities, refine your plans, or better prepare your organization?
Contact us: [email protected]


+ than 5000 subscribers