Example of a Business Impact Analysis in Manufacturing
An effective business impact analysis does not start with a generic questionnaire, but with an operational question: How long can a facility be without a critical function before the effects become unacceptable? This example of a business impact analysis in the manufacturing sector shows how to translate that question into data that can be used for business continuity, investment, and crisis management decisions.
In the industrial sector, a production line shutdown does not merely result in the loss of a certain number of units. It can lead to lost profit margins, contractual penalties, spoilage of raw materials, unavailability of products for strategic customers, logistical bottlenecks, restart costs, and—in some processes—risks to safety, the environment, and quality. A BIA helps establish well-founded priorities, ensuring that the business continuity plan does not assign the same level of urgency to activities with vastly different consequences.
Example of a Business Impact Analysis in Manufacturing
Consider a manufacturer of technical components for the automotive industry, with three production lines, an automated warehouse, a quality control lab, and an ERP system integrated with MES, production planning, and the platforms of its major customers. The plant operates on a shift basis and fulfills orders on a just-in-time basis.
A cyber incident renders the ERP and MES systems unavailable. The machines are not physically damaged and power is available, but it is not possible to receive orders, issue production orders, verify updated bills of materials, track batches, or print the labels requested by the customer. A superficial analysis might classify the incident as an IT problem. The BIA correctly reframes it: it is a disruption to the order fulfillment and production process, with commercial, contractual, and quality implications.
The unit of analysis should not be the individual application, but rather the end-to-end process. In this case, the relevant sequence includes order entry, planning, material availability, production release, manufacturing, quality control, labeling, shipping, and billing. Each step must be examined in collaboration with managers from production, supply chain, quality, IT, maintenance, finance, and sales. Cross-functional collaboration helps reduce a common mistake: confusing the perceived criticality within a single function with the overall impact on the organization.
Data collected in this case
For each process, the BIA team identifies the average daily volume, the associated economic value, the contractual delivery windows, the technical dependencies, and the manual procedures that are actually feasible. It is not enough to simply state that a manual procedure exists: it is necessary to verify how many hours it requires, what data can be used to feed it, who is authorized to perform it, and whether it meets traceability requirements.
In the case under consideration, Line A produces components for a customer with daily deliveries and a customer inventory level equivalent to 18 hours of production. Line B serves customers with average inventory levels exceeding two days. Line C produces special, high-margin batches, planned on a weekly basis. The automated warehouse can operate in degraded mode, but with reduced picking capacity and without reliable visibility into inventory levels. The quality lab can continue to perform some inspections but cannot issue the digital certificates required for shipment.
The impact is assessed over defined time windows, such as 0–4 hours, 4–12 hours, 12–24 hours, 24–48 hours, and more than 48 hours. This approach is more useful than a one-time assessment because, in manufacturing, the effects are rarely linear. In the first few hours, it may be possible to continue using the last valid production plan; however, once a certain threshold is crossed, the risk of producing against an incorrect revision increases, as does the inability to handle customer emergencies and the accumulation of incorrectly recorded work-in-progress.
From Impact Assessment to Restoration Priorities
In the BIA workshop, Line A is a priority not only because of the potential lost revenue. After 12 hours of ERP and MES downtime, the customer may halt production, trigger contractual escalations, and request emergency deliveries. After 24 hours, the damage includes urgent logistics costs, a potential loss of credibility as a supplier, and staff efforts to reconstruct production and traceability data.
Line B has a significant financial impact but greater tolerance for downtime thanks to downstream inventory. Line C requires a different assessment: the volume is lower, but missing a specific production window could jeopardize a high-margin order or a technical qualification. The priority, therefore, does not stem from the largest department, but from a combination of impact, available time, contractual obligations, and the possibility of an alternative solution.
This analysis can reveal operational parameters such as the Maximum Tolerable Period of Disruption and the Recovery Time Objective—the target time within which to restore a minimum acceptable level of capacity. For the planning and MES of Line A, for example, the RTO could be set at 8 hours. For full normalization of traceability, the target could be more extended, provided that a controlled mode for production and shipping is available within the first few hours without violating quality requirements.
The Recovery Point Objective completes the picture when data is critical. If the ERP backup allows for recovery with a maximum loss of 24 hours of transactions, that value may be incompatible with the need to reconstruct batches, work-in-progress, and shipments. The BIA does not definethe backup architecture on its own, but it provides the business requirement that allows IT to size it correctly.
An excerpt from the BIA results
In the case described, the final report could identify four main findings:
- The planning and release process for Line A requires an alternative capacity within 8 hours;
- Shipping requires verified minimum information regarding orders, lots, quantities, and customer requirements within 12 hours;
- The automated warehouse must have tested fallback procedures in place, with formally accepted volume limits;
- Production records must be reconstructed before the end of the next shift to ensure traceability and inventory integrity.
These results must be linked to responsible parties, minimum resources, dependencies, and activation criteria. An RTO without an owner and a viable strategy remains merely a statement, not a resilience requirement.
Dependencies That Affect the Result
In manufacturing, external and cross-functional dependencies often determine the actual recoverability of the process. A plant may have generators and electrical redundancy, but it can still come to a standstill due to the unavailability of a critical supplier, connectivity, compressed air, an industrial control system, specialized personnel, or quality certifications.
The BIA must also highlight cascading dependencies. In the example, the ability to produce manually depends on the availability of the latest approved bill of materials, on approved work orders or printouts, on the presence of the quality manager, and on the ability to temporarily register batches. If any of these elements is missing, the alternative mode cannot actually be used.
It is also necessary to distinguish between technical recovery and service resumption. A server becoming available again does not mean that the process is back up and running: application validations, data reconciliation, verification of interfaces with customers and suppliers, checking of transaction queues, and authorization to resume production may still be required. This distinction is crucial to avoid recovery times that are formally met but operationally irrelevant.
Common Errors in Plant-Level BIA
The first mistake is to limit the BIA to the value of lost revenue. Revenue is a necessary indicator, but it does not account for exposure to penalties, product recalls, non-compliance, reputational damage, restart costs, and loss of future production capacity. The second mistake is to apply identical target times to all critical systems without linking them to the processes they support.
A third mistake involves placing too much trust in manual solutions. In an industrial environment governed by quality and traceability requirements, a paper-based procedure may be appropriate for a few hours and for limited volumes, but it is not a sustainable solution for one or more days. Its effectiveness must be demonstrated through testing, not simply assumed.
Finally, the BIA should not become a static document. New customers, changes in inventory, warehouse automation, the introduction of a new MES, outsourcing, and contractual changes can rapidly alter the criticality of a process. The review should therefore be integrated with relevant organizational and technological changes.
For a manufacturing organization, a well-conducted BIA leads to a concrete decision: which capabilities need to be protected, by when they must be restored, with what resources, and at what minimum service level. The value lies not in filling out the matrix, but in the discipline with which those requirements are transformed into verifiable strategies, tests, and responsibilities.
This post is also available in:
Would you like to find out more about our training programmes?
Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.



