Cybersecurity and business continuity: what if your critical supplier fails?
Assess dependencies, decision-making and recovery capabilities. Explore Behaviour’s confirmed courses to strengthen your team’s skills.
⏱️ Estimated reading time: 4 minutes
The link between cybersecurity and business continuity becomes clear when a critical supplier fails. Imagine an essential application becoming unavailable, with no estimated recovery time. The IT team is looking for alternatives, operations teams are waiting for instructions and customers are still asking for answers.
Who decides what to do, and what preparation informs those decisions?
During this European Cybersecurity Month, this question belongs on the business agenda: beyond preventing attacks, are we prepared to keep operating when an external service fails?
Cybersecurity and business continuity: third-party risk
The ENISA Threat Landscape 2026, published on 22 September and based on events in the European Union in 2025, highlights the risks of digital dependencies. Attacks on supply chains and third parties can cause incidents with far-reaching effects and significant impact.
It is not enough to ask whether the supplier has a plan. You need to know how your company will keep operating while that plan is being put into action.
There is another important distinction: restoring a technology service does not necessarily mean resuming business activities. An application may be working again while data still needs to be validated, integrations restored and backlogs cleared.
In Portugal, the framework transposing NIS 2 also makes preparedness a management responsibility. Article 25 of the framework approved by Decree-Law No. 125/2025 assigns the management bodies of essential and important entities responsibilities for overseeing risk management measures and ensuring regular cybersecurity training.
Three questions to assess your company’s preparedness
Which activities are affected?
Who makes the decisions, and what are the priorities?
What evidence shows that the response works?
As a starting point, bring together security, ICT and operations teams to discuss one scenario: a critical supplier unavailable for 24 hours. Record decisions, unanswered questions and unresolved dependencies. These gaps help identify what needs to improve — and which skills to develop.
Confirmed courses to strengthen your team’s skills
Behaviour has confirmed Live Online courses in October 2026 to strengthen skills in cybersecurity and business continuity, according to each participant’s responsibilities:
On smaller screens, swipe across the table to view the dates and Team Packs.
| Course and skills | Confirmed dates | Team Pack 2 participants |
|---|---|---|
| ICT Readiness Lead Manager Translate business continuity needs into technological capabilities that can be put into practice and verified, including recovery and supplier dependencies. |
to | €3,150total |
| NIS 2 Compliance Lead Manager Structure cybersecurity compliance by aligning governance, risk management, security measures and incident response. |
to | €3,900total |
| Cybersecurity Lead Auditor Plan and conduct audits of cybersecurity programmes and capabilities, assessing controls, practices and evidence. |
to | €3,900total |
| ISO 22301 Lead Auditor Audit the conformity and effectiveness of Business Continuity Management Systems, basing conclusions on evidence. |
to | €3,900total |
Each Team Pack applies to two employees from the same company attending the same course on the same dates. The prices shown are the totals per Team Pack.
The failure may start with a supplier. Your company’s preparation should start sooner.
Would it make sense to enrol two employees from your company on one of these courses?
Request a Team Pack proposal at training@behaviour-group.com.
Date:
Author: Behaviour Group
Copying or reproducing this article is not authorised.