Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryBusiness Continuity Plan (BCP)
Contents & downloads
- GOV-POL-002
- QHSE-PLN-002
- QHSE-PRO-001
- TEC-PRO-001
Nomenclature
| Term | Definition |
|---|---|
| ASD | Australian Signals Directorate. |
| BCMS | Business Continuity Management System (ISO 22301). |
| BCP | Business Continuity Plan (this document). |
| BIA | Business Impact Analysis. |
| BCS | Becloudsmart — Westlink’s external managed cloud services provider (MCSP) for Microsoft 365 administration, identity and access control. |
| CMP | Crisis Management Plan (QHSE-PLN-002). |
| CRE | CRE Insurance Broking — Westlink’s insurance broker and first contact for insurable events. |
| DISP | Defence Industry Security Program. |
| ICT | Information and communications technology. |
| MAO | Maximum Acceptable Outage — the longest a critical function can be unavailable before the organisation suffers unacceptable harm. Sets the outer boundary for recovery. |
| MCSP | Managed Cloud Services Provider. |
| NDB | Notifiable Data Breach (Privacy Act 1988 (Cth) Part IIIC). |
| OAIC | Office of the Australian Information Commissioner. |
| RPO | Recovery Point Objective — the maximum tolerable data loss measured in time. Informs backup frequency and replication strategy. |
| RTO | Recovery Time Objective — the target time within which a function must be restored after a disruption. Must be less than or equal to the MAO. |
| SaaS | Software as a Service — cloud-delivered software applications. |
| SPP | Security Policies and Plans — Westlink’s DISP security governance document (DEF-POL-001). |
| VoIP | Voice over Internet Protocol — internet telephony. Westlink uses the 3CX platform. |
Purpose
This plan describes how Westlink maintains and restores its critical business functions during and after a disruptive event. It defines recovery objectives, response and recovery strategies, roles and responsibilities, communications, and the testing and maintenance regime that keeps the plan current.
The plan is aligned with ISO 22301:2019 (Business Continuity Management Systems) and integrates Westlink’s DISP Entry level obligations through the Security Policies and Plans (SPP). It supports Westlink’s JOSCAR-AU 2026 business-continuity commitment.
Scope
This plan applies to all Westlink personnel, critical business functions, supporting ICT services and key vendors. Westlink is a remote-capable organisation operating from its Perth head office with a regional presence in Brisbane (QLD) and a Singapore-based staff member; during a disruption personnel can work from any location using a laptop, mobile and internet connection.
The critical functions in scope are:
-
Operations — project management, HSEQ and compliance;
-
Finance — accounts payable and receivable, and reporting; and
-
Business Development — requests for quotation and tenders.
Crisis management — the enterprise-level response to events that threaten Westlink’s people, reputation or legal standing — sits outside this plan and is governed by the Crisis Management Plan (QHSE-PLN-002). The default business-continuity lead is the Finance and Technology Manager (FTM); the default crisis lead is the Chief Executive Officer (CEO).
Definitions
Continuity is the ability to maintain or restore critical functions within their defined recovery tolerances (MAO, RTO and RPO). Acronyms and specialist terms are defined in the Nomenclature table in the front matter.
Standards and Obligations
This plan is read with the ISO 22301:2019 business-continuity framework and Westlink’s DISP Entry level obligations implemented through the SPP. Where a cyber incident involves a ransomware or cyber-extortion payment, a report to the Australian Signals Directorate is mandatory within 72 hours under the Cyber Security Act 2024 (Cth) Part 3; that obligation is owned by the Cyber Security Procedure (TEC-PRO-001), which this plan cross-references rather than duplicates.
Objectives and Targets
The objectives of this plan are to:
-
Protect the safety of personnel, and the security of Westlink information, assets and reputation, during a disruption;
-
Maintain or rapidly restore the critical functions (Operations, Finance and Business Development) within their recovery tolerances;
-
Meet Westlink’s contractual, legal, DISP and customer obligations throughout the disruption; and
-
Provide clear escalation paths, communications and recovery actions, and improve the plan after each event.
Business Impact Analysis
Risk identification, evaluation and treatment are governed by the Risk Management Procedure and the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001). The principal disruption risks for a logistics organisation, with representative examples, are set out below.
| Risk category | Representative examples |
|---|---|
| Cyber and information security | Credential compromise or MFA bypass; ransomware; SaaS outage; phishing across Microsoft 365. |
| Natural hazard and site loss | Severe weather; fire; power or telecommunications failure; building evacuation affecting personnel safety. |
| Supply-chain disruption | Port closures; industrial action; carrier insolvency; biosecurity events. |
| Workforce unavailability | Pandemic; travel restrictions; fatigue; serious injury or loss of a key staff member. |
Disruption impact is assessed against five criteria: safety and legal or regulatory exposure; customer commitments; cashflow and financial loss; the confidentiality, integrity and availability of data; and reputation.
The recovery tolerances for each critical function are set out below. The Recovery Time Objective must always be within the Maximum Acceptable Outage.
| Critical function | MAO | RTO | RPO | Key dependencies |
|---|---|---|---|---|
| Operations (PM / HSEQ / compliance) | 48 h | 8–48 h | ≤ 72 h | Microsoft 365, Dynamics 365, Teams |
| Business Development (RFQs / tenders) | 72 h | 24–72 h | ≤ 72 h | Microsoft 365, Dynamics 365, Teams |
| Finance (AP / AR / reporting) | 72–120 h | 24–48 h | ≤ 72 h | Microsoft 365, Dynamics 365, Xero, ApprovalMax, banking |
Roles and Responsibilities
Any worker may report a suspected business-continuity incident to the FTM. The FTM assigns a severity band, declares activation, determines the incident type and allocates responsibilities. If the FTM is unavailable, the fallback order is FTM, then Operations Manager, then QLD Regional Manager, then CEO. Stand-down requires the agreement of both the FTM and the CEO, once recovery tolerances are met and backlogs are under control.
| Band | Impact |
|---|---|
| P1 | Critical |
| P2 | Major |
| P3 | Moderate |
| P4 | Minor |
The Business Continuity Steering Committee comprises the CEO, the FTM, the Operations Manager, the QLD Regional Manager and the Chartering Manager. Responsibilities for the key continuity activities are allocated below (R = responsible, A = accountable, C = consulted, I = informed).
| Activity | CEO | FTM | OM | QRM | CM | BCS | CRE |
|---|---|---|---|---|---|---|---|
| Declare incident level | A | R | C | C | C | C | I |
| Cyber containment | I | A | I | I | I | R | I |
| Customer communications | A | I | R | R | C | — | — |
| Supplier rerouting | A | I | R | C | R | — | — |
| Insurance notification | A | R | C | C | C | I | R |
Activities and Schedule
The response and recovery activities are organised as scenario playbooks. Each playbook is actioned at the severity declared by the FTM. The immediate first-response checklist for a P1 or P2 event is at Appendix A.
Cyber incident
The FTM is the incident lead and notifies the CEO and Operations Manager. Within the first two hours, Becloudsmart disables affected accounts, revokes tokens, resets passwords, tightens conditional access and isolates endpoints. Personnel continue working from unaffected devices and locations. Evidence is preserved (disk and memory images, log preservation, chain of custody).
Regulatory and contractual notifications are made as required: a Notifiable Data Breach assessment and, where the threshold is met, notification to the OAIC and affected individuals; a report to the Australian Signals Directorate within 72 hours where a ransomware or cyber-extortion payment is made or proposed (mandatory under the Cyber Security Act 2024 (Cth) Part 3); a ReportCyber report to the ASD as soon as practicable; DISP reporting through the SPP; contractually required customer notices; and notification to CRE Insurance. These notifications are executed under the Cyber Security Procedure (TEC-PRO-001). Recovery validates data integrity, restores from SaaS retention in phases, and applies heightened monitoring; the root cause and corrective actions are documented post-incident.
Natural disaster or premises loss
The default posture is company-wide work-from-home once personnel safety and headcount are confirmed and local evacuation procedures are complete. Inbound numbers are rerouted to mobiles through the 3CX platform and call flows validated. Becloudsmart confirms SaaS health; personnel use mobile hotspots if fixed links fail.
Supply-chain disruption
Port and road alerts and supplier communications are monitored, and the risk register is updated where defence work is affected. Pre-qualified alternates are activated and laycan or routing adjusted, with reference to the relevant operational manuals. Force-majeure and variation clauses are applied under Westlink’s terms and conditions and contract-review guidance.
Workforce unavailability
Westlink operates remote-first and enforces fatigue-management and wellbeing controls. Alternates are kept ready with SaaS and MFA access, and Teams channels are used for handover and communication.
Insurance-relevant and DISP-relevant events
For an insurable event, CRE Insurance is the first notification, following the contract, legal and insurance review process. For a DISP-relevant event, information is restricted to need-to-know and evidence preserved, managed under the SPP, with Defence security and insider-threat awareness reinforced.
Resources
Preventive resilience measures reduce the likelihood and impact of a disruption and are maintained between events:
-
Governance and policy — cyber controls (MFA, conditional access, least privilege, device hardening, administrator segmentation) under the Cyber Security Procedure (TEC-PRO-001); personal data handled under the Privacy Policy; DISP Entry level controls under the SPP;
-
Technology resilience — reliance on native SaaS retention and versioning (Microsoft 365, Dynamics 365, Xero, ApprovalMax and related platforms); pre-configured VoIP rerouting and overflow to mobiles on the 3CX platform; spare laptops held offsite for key roles, with Intune compliance, BitLocker encryption and conditional access; and
-
People and process — cross-training and current standard operating procedures for alternates; fatigue and wellbeing controls under the Work Health and Safety Policy (GOV-POL-002); and supplier-continuity assurance through pre-qualification and third-party management.
Becloudsmart provides managed cloud services and identity administration; CRE Insurance Broking is the insurance broker; and key personnel and vendor contacts are maintained in the contact directory at Appendix B.
Monitoring and Reporting
Communication during a disruption is timely, accurate, least-privilege and customer-first, with a single source of truth. Primary channels are Teams and Microsoft 365 email, VoIP and mobile, with SMS as a fallback and a website notice where external communication is required. Stakeholder notification triggers and service levels are set out below.
| Stakeholder | Trigger | Owner | Channel | Service level |
|---|---|---|---|---|
| All workers | P1 / P2 declared | FTM | Teams + email | 60 min |
| Key customers | Service impact ≥ 4 h | OM / QRM | Phone / email | As needed |
| Carriers / agents | Reroute or alternates | OM / CM | Phone / email | As needed |
| CRE Insurance | Insurable event | FTM | Phone / email | Immediate |
| DISP / Defence | DISP-relevant event | Per SPP | Per SPP | Per SPP |
Review
The plan is tested and maintained on the following cycle, and is reviewed at least annually by the Business Continuity Steering Committee and after any activation or material organisational change.
-
Quarterly — desktop review by the Steering Committee against a rotating scenario (cyber, premises loss, supply chain, workforce);
-
Half-yearly — technical drill of VoIP reroute failover, clean-device SaaS access and alternate communications;
-
Annually — full exercise of company-wide remote-work continuity and customer communications, including continuity when Steering Committee members are unavailable; and
-
After every activation — an after-action review that captures lessons, updates this plan and the DISP risk register, and refreshes Defence security awareness.
References
This plan is read in conjunction with ISO 22301:2019 (business continuity management systems), the Cyber Security Act 2024 (Cth) Part 3, the Privacy Act 1988 (Cth) Part IIIC (Notifiable Data Breach scheme), the Defence Industry Security Program (DISP) Entry level requirements, and the internal documents listed in the Related Documents table in the front matter — in particular the Crisis Management Plan (QHSE-PLN-002), the Cyber Security Procedure (TEC-PRO-001), the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001) and the Work Health and Safety Policy (GOV-POL-002).
Compliance coverage — cited by 1 requirement across 1 framework
JOSCAR-AU 2026(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.15.1 | Q2.15.1 | Full | Business Continuity Plan — recovery objectives (MAO/RTO/RPO), scenario playbooks, roles, communications and testing/maintenance regime. Rebuilt and renumbered from legacy WLK-GBL-QHSE-PLN-002; closes this question. |
Declared compliance references (1)
JOSCAR-Q2.15.1
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 08/06/2026 | WLK-GBL-QHSE-PLN-002 | Business Continuity Plan (BCP) | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Initial issue in new WMS. Rebuilt from legacy WLK-GBL-QHSE-PLN-002 and renumbered to QHSE-PLN-001. Closes JOSCAR-AU 2026 Q2.15.1. |