Blog
Business Continuity Carries Disproportionate Weight in an OEM Cybersecurity Assessment, and Most Suppliers Leave It Blank
Continuity is among the most heavily weighted sections of a customer cybersecurity assessment, and the one suppliers most often leave empty. What it asks for.
Neha Dvivedi · 13 September 2026
Suppliers preparing for a customer cybersecurity assessment tend to concentrate on access control, firewalls and endpoint protection. Those areas matter. But business continuity is commonly among the most heavily weighted sections of the instrument, its checkpoints are typically categorised as Must Have rather than Good to Have, making them mandatory, and it is the section suppliers most often leave empty.
Why continuity is weighted so heavily
The clue is in who issues the assessment. These instruments are frequently owned by the customer’s supply chain or business continuity function rather than its IT department. That tells you what the customer is actually worried about, and it is not primarily the confidentiality of data. It is whether a stoppage at a supplier becomes a stoppage on their line.
Recent events have sharpened that concern considerably. The Jaguar Land Rover attack in September 2025 halted production in the United Kingdom and Slovakia for over a month. In June 2026 a ransomware attack on Bajaj Auto affected corporate IT infrastructure and an engineering subsidiary. From a vehicle manufacturer’s perspective, a supplier that cannot restart is a supply problem before it is a security problem.
What the continuity section actually asks
The checkpoints in this area are consistent across instruments and are more specific than most suppliers expect.
- A documented business continuity plan. Not a statement of intent. A plan identifying critical processes, responsible individuals, activation criteria and recovery procedures.
- Defined recovery objectives. A recovery point objective and a recovery time objective, stated as RPO and RTO, for each critical system. RPO defines how much data loss is tolerable, RTO how long recovery may take. Both are numbers, and an assessment expects numbers.
- A business impact analysis. An assessment identifying which processes and systems are critical, what the consequence of their loss would be over time, and what the dependencies are. The BCP RTO RPO definitions should follow from this analysis rather than being asserted independently.
- Disaster recovery capability. Backup arrangements, restoration procedures and the infrastructure supporting them, including whether backups are held separately from production systems.
- Drills and testing. Evidence that the plan has been exercised, retained as a DR drill record. A plan never tested attracts limited credit. A single documented drill record changes the answer.
- Incident handling and escalation. How an event is detected, who is notified, and on what timeline.
- Management review. Evidence that continuity performance is reported to management and acted on, which connects continuity to the governance requirements assessed elsewhere.
Why suppliers leave it blank
Three reasons recur, and each has a straightforward answer.
The first is ownership. Continuity sits between IT, operations and management, and often belongs to nobody. Assigning it to a named individual is the necessary first step and costs nothing.
The second is a belief that continuity requires a secondary site. It does not, at least not to begin with. Defined recovery objectives, tested backups, a documented restoration procedure and a drill record address most of what is assessed. A supplier with no disaster recovery site can still produce a credible continuity section.
The third is the assumption that a backup arrangement is a continuity plan. It is not. Backups address data recovery. Continuity addresses the resumption of business processes, which is a broader question covering people, premises, suppliers and systems. Assessments ask about the broader question.
Building a credible continuity section
The sequence that works is a business impact analysis first, because everything else derives from it. List critical processes, identify supporting systems, and determine the consequence of losing each over increasing periods. From that, set recovery objectives per system, with numbers rather than descriptions.
Then document the plan itself: activation criteria, named roles, recovery procedures, contact lists and communication arrangements including how the customer is informed. Then run one drill, even a tabletop exercise lasting an hour, and write it up. A short, honest drill record including what did not work is more credible than an untested plan, and assessments generally credit evidence of exercise rather than perfection.
ISO 22301 certification in India is the formal route for organisations wanting external validation of this, and it maps directly onto what these assessment sections ask for. It is not required by any customer assessment, but it addresses the section comprehensively.
The point most suppliers miss
Continuity carries weight disproportionate to the effort required. Most of the section is documentation: an analysis, a plan, a set of numbers and a drill record. None of it requires significant expenditure, and it is one of the few areas where a supplier can move from nothing to substantially complete within a single improvement cycle.
Where measures genuinely need investment, such as offsite or immutable backup infrastructure, the scoring usually permits partial credit for work underway, provided current status and a scheduled completion date are recorded. A documented and dated plan earns marks that silence does not. For suppliers facing a submission window measured in weeks, a cybersecurity gap assessment against the instrument is normally the fastest way to separate what can be closed with documentation from what genuinely needs budget.
ISO 22301 is the formal route for organisations wanting external validation of continuity, and the control families reference sets out how the section is scored alongside the rest. MSCi works with automotive suppliers on gap assessment against these instruments. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist is a quick first look.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Vendor Cybersecurity Assessments Move from Advisory to Scored: What Indian Suppliers Are Now Being Measured On
Vehicle manufacturers in India now score suppliers on cybersecurity against weighted checklists, with corrective action deadlines. What is being measured.
13 September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Control Families, Scoring and Standards Mapping
What an automotive vendor cybersecurity assessment covers, how it is scored, the evidence it asks for, and how each control family maps to ISO standards.
13 September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 September 2026
