How Catalent Operationalized Business Continuity

John Brewer, Global Director of Security & Business Continuity at Catalent

1
Global, multi-site pharmaceutical CDMO Centralized BC, DR, and incident response
100+
Automated dependency tracking linking systems, vendors, and facilities
1
ISO 22301 aligned framework mapped across enterprise processes
25-50%
Significant cost reduction after replacing legacy GRC platform
“We weren’t confined to a box. It’s low-code, no-code. We can build what we need as our regulatory requirements grow.”
John Brewer, Global Director of Security & Business Continuity at Catalent

Problem

Static Plans. Expanding Regulations. Limited Flexibility.

Operating in a highly regulated environment, the organization anchored its resilience program to ISO 22301, while also aligning with SOC 2 and the NIS 2 Directive.

But execution was fragmented. Business continuity plans lived in static documents. Dependencies were tracked in spreadsheets. Their legacy risk platform was rigid and costly — limiting customization as regulatory requirements evolved. The team needed more than documentation. They needed operational resilience.

Q1

Solution

One Platform. Real-Time Execution.

With SmartSuite, Catalent’s team moved beyond static plans to build a fully ISO 22301–aligned resilience framework that could operate in real time. Structured BIA modules track critical metrics like RTO, RPO, and MTPD, while automated mapping links processes to their dependencies across systems, vendors, and facilities. Version-controlled governance ensures that every plan is accurate, auditable, and up to date.

AI assists in generating recovery activities, suggesting the right steps and priorities, while one-click plan activation automatically notifies the right stakeholders. Built-in testing, after-action reviews, and performance dashboards turn each plan into a living, continuously improving operational tool. The transition was rapid: the team migrated all legacy data in a single day. What was once bound in static documents is now activated, tracked, and optimized in real time.

Q2

Result

Faster Activation. Stronger Governance. Lower Cost.

SmartSuite transformed Catalent’s business continuity program from a static compliance exercise into a dynamic operational engine. Plans are now executed with real-time visibility, and teams collaborate seamlessly across functions, ensuring responses are swift, coordinated, and auditable. Documentation is fully aligned to ISO 22301, SOC 2, and NIS2 standards, making audits simpler and more reliable.

Beyond operational improvements, the platform drove a significant reduction in costs by replacing a rigid legacy GRC system, giving Catalent both flexibility and scalability to evolve with regulatory requirements.

Q3
Download Customer Story PDF
Solution Area
GRC & Resilience
Business Operations

Company Name

Catalent

Industry

Pharmacuticals

Team

Security, IT, Operations

Region

North America

Company size

Enterprise

Pain point

Manual Assessment Management, Limited Centralization and Visibility

Products replaced

AuditBoard, ServiceNow, Excel, SharePoint

About the company

For over 35 years, Catalent (catalent.com) has provided advanced drug development, manufacturing, and supply solutions to biopharmaceutical companies worldwide, combining scientific innovation, operational excellence, and regulatory rigor to deliver reliable, scalable, and compliant solutions for life sciences companies.

Website

https://www.catalent.com

“You only got what they provided versus what you could build yourself.”
John Brewer, Global Director of Security & Business Continuity at Catalent
“We imported our entire data library in about a day. It was crazy to see that transition.”
John Brewer, Global Director of Security & Business Continuity at Catalent
“The cost reduction alone has been phenomenal. If you can think it, you can build it.”
John Brewer, Global Director of Security & Business Continuity at Catalent