Madrid · Domestic and International Service info@imts.es
ES / EN / PT

Business Continuity Policy

BUSINESS CONTINUITY AND OPERATIONAL RESILIENCE POLICY

At Infraestructuras de Medios Técnicos y Servicios (IMTS), our business model is based on protecting and ensuring our clients’ operational continuity. We provide critical services: Security Management, Managed Technical Support, Intelligence (OSINT), and Governance, Risk, and Compliance (GRC).

We understand that, in the event of a critical incident, a cyberattack, or a disaster, our clients need us more than ever. Therefore, IMTS management recognizes that our own operational resilience is not an option, but a strategic and contractual obligation. We do not sell resilience that we do not apply within our own organization.

Through this Policy, IMTS establishes the principles of its Business Continuity Management System (BCMS), rigorously aligned with international best practices, with a particular emphasis on the ISO 22301 standard, as well as the principles of the DORA, NIS2, ISO/IEC 27001, and National Security Scheme (ENS) frameworks.

1. POLICY OBJECTIVE

The main objective of our BCM is to ensure that, in the event of a serious disruption (technological failures, cyberattacks, natural disasters, unavailability of facilities, or critical supply chain failures), IMTS is capable of:

  1. Protect the safety and lives of our employees and partners.
  2. Maintain or restore the provision of our critical services within predefined timeframes (RTO – Recovery Time Objective) with zero or strictly controlled data loss (RPO – Recovery Point Objective).
  3. Safeguard the confidentiality, integrity, and availability of our clients’ information, even when operating in contingency mode.
  4. Minimize the financial, operational, and reputational impact for both IMTS and the organizations that rely on us.

2. PRINCIPLES OF OUR BUSINESS CONTINUITY

To fulfill this commitment, our continuity model is based on the following operational pillars:

  1. Business Impact Analysis (BIA) and Risk Identification We do not improvise in the face of crises. IMTS maintains an up-to-date, comprehensive analysis of all its processes to identify those that are critical to the delivery of our services. We periodically assess threats that could disrupt our operations to establish preventive controls and mitigation strategies before the risk materializes.
  2. Recovery and Redundancy Strategies Our infrastructure, information systems, and network architectures are designed according to the principles of high availability and redundancy. Our staff is equipped with the necessary technology and procedures to operate 100% securely in remote mode (secure telework) if our physical facilities were to become inoperable, ensuring that technical support, monitoring, and consulting services continue uninterrupted.
  3. Crisis Management and Communication We have a predefined Crisis Management Committee with clear roles and responsibilities. In the event of a high-impact incident, our contingency communication channels ensure prompt, transparent, and accurate information sharing with our clients, critical suppliers, and relevant authorities.
  4. Supply Chain Resilience We know that we are only as strong as our weakest link. Therefore, and just as we do for our clients with our IT Supplier Management service, we require our critical suppliers (cloud services, telecommunications, data centers) to have auditable business continuity plans and service level agreements (SLAs) aligned with our own recovery objectives.

3. TRAINING, CULTURE, AND CONTINUOUS TESTING

A continuity plan that isn’t tested is merely a false sense of security.

At IMTS, the Business Continuity Management System is a living entity. We conduct exercises, drills, and recovery tests at least annually, ranging from the recovery of critical systems (restoration of immutable backups) to simulations of the unavailability of key personnel or the failure of operational sites. Any lessons learned from these tests are immediately incorporated into updates to our plans through a Continuous Improvement (PDCA) model.

Likewise, we consider it critical that the entire IMTS team understand their role in the event of a disruption. For this reason, our staff receives regular training on incident response procedures and contingency operational protocols.

4. MANAGEMENT COMMITMENT

IMTS management leads this effort, ensuring the provision of the financial, technological, and human resources necessary to continuously maintain, test, and strengthen our Business Continuity Management System.

We approve and support this policy, requiring every member of the organization to embrace it as their own, thereby ensuring that IMTS remains the most reliable technology and security partner for our clients, regardless of the circumstances surrounding us.

Approved by IMTS Senior Management. Last revised: May 2026