Riskonnect Business Continuity & Resilience (formerly Castellan)
Riskonnect’s web-based SaaS application streamlines and automates business continuity management (BCM) across organizations. It supports Business Impact Analysis (BIA), planning, exercise management, crisis management, threat intelligence, emergency notification, and operational resilience. The platform offers customizable templates, integrated notifications, and real-time reporting for increased confidence in resilience and organization-wide accountability.
Features
- Holistic program view with dynamic dependency mapping
- Automated, email-driven workflow engine for task management
- Guided, customizable templates for BIAs, plans, exercises, and documents
- Seamless integration with enterprise systems and real-time data sync
- User profiles to control access to data and features
- Pre-built reports and customizable dashboards for insights
- Integrated, two-way notifications to employees and plan members
- Scenario-based crisis and exercise management with live reporting
- User friendly interface with multilingual support
Benefits
- Centralized platform for readiness, response, and recovery management
- Aligns with ISO 22301 and BCM best practices
- Intuitive interface for both frequent and occasional users
- Minimal need for central administration and oversight
- Empowers stakeholders to own and update plans
- Efficient, cost-effective plan creation and maintenance
- Access plan information anytime, including offline availability
- Email-driven task management to streamline reviews and approvals
- Integrated data to enhance speed, accuracy, and visibility
- Latest plan updates always accessible to authorized users
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 8 8 2 7 2 3 7 0 1 5 1 2 1
Contact
Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS)
Shane Yeeda
Telephone: +1 770 790 4683
Email: legal@riskonnect.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No, the majority of planned maintenance is undertaken with no client impact.
- System requirements
-
- User browser must Support TLS 1.2 encryption (https) of pages
- User browser must have JavaScript Enabled.
- Windows 8.1 or above
- Mac OS X 10.6 or above
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide 24x7x365 Operational and Technical support delivered by our team of Service Delivery Specialists. The team is contactable by email, phone or via the customer support portal which logs and tracks tickets through to completion.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All customers have access to technical and functional documentation through our Customer Success Portal 24x7 with UK based email and telephone support staff. All support related issues are logged on the portal with full visibility to the client. Each client will have a dedicated Account Executive and Customer Success Manager (CSM) for additional assistance and support as required. The CSM will hold a regular business reviews and maintain a Rolling Action Item Log to ensure you are always getting the very best out of your subscription.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Riskonnect's Business Continuity & Resilience offers comprehensive support throughout the implementation process, led by an experienced business continuity practitioner supported by our team of service delivery specialists.
Our standard implementation service provides training to client system administrators such that they will be able to configure and administer the system going forward. Standard implementation covers the core development of BIAs and Plan entities. These sessions are delivered using a train the trainer approach to enable administrators with the required knowledge to complete the work with remote support from the software specialists. Each training session will focus on specific elements of system configuration with intervals allowed for completion of setup work by administrators as part of the formal implementation path.
This provides the following benefits:
o Collaborative, short focused training sessions on system components with hands on activity;
o Integrated system set-up through the training sessions so that the training delivers real benefit and a system that is ready to be used;
o Knowledge retention is maximised by using the actual client system rather than a training system and through completing live setup;
o Key learning opportunity for administrators ensuring that they retain the skills required to update and manage the site. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Documentation is available via our integrated Customer Support Portal.
- Video Tutorials via on screen links.
- End-of-contract data extraction
- At any time, including at the end of the contract, client administrators are able to extract their data easily using the reports already built into the system which will output the data as Excel/CSV files for ease of use offline, without the need for technical assistance. In addition, users can print and save their BIAs and Plans in PDF format and administrators can output and save detailed reports in Excel format. We can provide additional support for this process if other formats are required.
- End-of-contract process
- At the end of the contract, clients are able to extract all of their data including BIA and Plan content themselves via the client administrator interface and we can provide assistance with this process if required. For security and data protection purposes, we would permanently delete/destroy client data no later than 10 days after the end date of the contract. If the client requests the last available back-up of the data, this can be provided at no additional charge unless a specific format is required for which there may be an additional charge, otherwise there are no other additional costs relating to the end of the contract.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The desktop version is also viewable on mobile devices as it is delivered via a web browser. The layout of the screen will dynamically adapt to the screen size of the device used to access it. In addition the mobile app provides offline access to BC plans and Crisis Management capabilities if there is a network outage.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
We have a suite of API's for importing data including Employees, Resources, Suppliers and Sites. We also provide OOTB RESTful API's for integration with third party applications and import API's to programmatically manage data imports into the system.
Once we enable API’s for a client there is a simple client administrator menu option which presents the user with a screen which is very similar to the Executive Dashboard screen, including a wizard-style interface to set up each API type required and which generates the required authentication keys. This means that the system (e.g. for employee data) the client is using at their end can be flexible since their IT team simply need to build the link to the appropriate API.
There are two options for automated data imports:
o Bulk File Transfer
o RESTful API (single record) Using a RESTful API is preferred, as this:
- Places control of the data transfer with the client;
- Operates via a client specific URL on the existing client domain, so is not a shared data transfer service;
- Pushes data to our software requiring no access or any entry points within any client infrastructure;
- Is secure. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Client administrators can customise and configure their software instance as required. Edits to terminology to align to individual organisational language and the designing of new templates, documents, workflows and customisable dashboard reporting is all very straightforward and can be achieved using simple tick box, text box and drag and drop options.
The software supports role-based security through assigned custom roles to manage access and user permissions. Permissions can be customised directly from within the software and each user can be assigned a standard or custom role or given access at the individual document, BIA, plan, or exercise level.
Scaling
- Independence of resources
-
The Resilience environment runs on highly available hardware in the Azure infrastructure. The environment is consistently monitored for performance with the primary metric of millisecond page
response time averages. Resilience’s goal is 90% of page responses within less than 500 milliseconds. In
addition, the infrastructure is sustained at 25% capacity, with the remaining capacity held to support
spikes in usage. In addition, we maintain a status page for customer visibility to performance:
https://status.castellanbc.com/
Analytics
- Service usage metrics
- Yes
- Metrics types
- Client Administrators are able to monitor and track service usage themselves. Using the Customisable dashboards, Administrators can use a simple wizard-style interface to create a number of graphs which provide an at-a-glance, real-time, overview of the BC program. These can be used to report to upper management. Client Administrators can also track BC program compliance using the default dashboard which can be filtered by area. Many of the built in reports can also be scheduled to provide regular reports or run on request by the user including audit and user access reports.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
There is a wealth of reporting available as part of our standard licence, including the capability of creating custom reports. The suite of pre-built reports includes Gap Analysis, and RAG indicators to show warnings, strategic and planning reports such as 'What If' and critical data analysis reporting.
Data can be exported as an Excel file or as a pdf. We also provides a public reporting API which allows clients to access their data to produce reporting extracts to upload into a third party analytics tools they may be using (e.g. Power BI or Tableau). - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Zip File
- Reporting API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- Zip File
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Riskonnect's Business Continuity & Resilience is provided on a high availability environment that provides an 99.97% uptime SLA for application availability excluding scheduled downtime and agreed client maintenance.
- Approach to resilience
-
The servers for the service are located across two geographically separate locations and are configured for redundancy and resilience:
o Data is stored on a highly redundant storage array;
o Databases are serviced by a database cluster;
o Websites are serviced by a load balanced pair of web servers;
o Security patches are applied monthly after they have been tested;
o For DR purposes data is replicated to a secondary location within the same geographic region via an encrypted private backbone network;
o An Azure traffic manager is used to redirect traffic between the Primary and Secondary sites
In the event of a catastrophic failure we can switch over to the secondary location within our standard RTO of three hours, with an RPO of fifteen minutes. - Outage reporting
- Riskonnect's Business Continuity & Resilience is a high availability application, availability is proactively monitored 24x7 by our own technical staff. This includes monitoring software which provides automated alerts via email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- All access to the underlying infrastructure is via two-factor VPN, and limited to users who require access to undertake their role.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO22301, SOC II, GDPR, CPRA
- Information security policies and processes
-
Riskonnect maintains a NIST / ISO27001 / SOC II aligned Information Security and Compliance environment that enforces strict access controls, data protection, system integrity, and continuous monitoring to safeguard confidentiality, integrity, and availability of all information assets.
In addition, our Information Security Forum which consists of the Global Head of Strategy, Head of Administration and Special Projects, Head of Global Infrastructure Architecture and The Information Security Manager. All managers ensure that documented security procedures and work instructions within their area of responsibility are carried out correctly to achieve compliance with security policies and standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Components of the service are tracked within our asset register which is reviewed every three months. When components near end of life a migration plan is created to move to new components prior to the end of life date.
All changes to software and components are tracked via a ticketing system with appropriate sign-offs by different teams. This includes security and risk assessments, confidentiality, integrity, availability, alignment to product roadmap and rollback plans.
Customers are communicated to via predefined channels prior to any changes which could impact the availability of the solution. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
To assess potential threats to our services, we run monthly vulnerability scans to identify security vulnerabilities and software configuration issues in all our environments.
Patches are deployed as follows, depending on their category:
• High: within 7-14 days (normally within 24 hours)
• Moderate: within 30 days
• Low: At our discretion
• Informational: At our discretion
Information on potential threats is also obtained from: Cyber Security Information Sharing Partnership (CiSP), Microsoft, Homeland Security National Cyber Awareness System. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Resilience aligns with ISO 27001, ISO 22301, and SOC II frameworks, ensuring that monitoring and incident response processes meet recognized security standards.
The Resilience environment is monitored in real time.
Response to Potential Compromises:
Immediate alerting and triage by the Security Operations team.
Containment and isolation of affected systems to prevent further impact.
Remediation actions executed based on predefined criteria and tracked until closure.
Post-incident review to capture lessons learned and strengthen controls. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We have a fully documented process for incident management ensuring that a consistent methodology is followed when an incident occurs which impact the services we provide, such that full service is restored as quickly as possible.
Users can report incidents through our Help Desk ticketing system or by telephone or email through our Service Delivery team. Incidents can also be automatically detected via our monitoring tools and escalated.
During an incident, reports are provided to clients at a frequency that is consistent with the deadline assigned to resolution of the incident, but typically every 30 minutes via email or SMS. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- A-Lign
- ISO/IEC 27001 accreditation date
- Tuesday 19 December 2023
- What the ISO/IEC 27001 doesn’t cover
- None
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fdf9abb4-76f7-4cfa-8f6e-3c86afef4729
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 22301
- HIPPA / HITECH
- SOC II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-