TL;DR:
- A business continuity plan (BCP) identifies what would stop your business operating and documents how you’d keep going anyway — it’s not just about IT failures
- For small businesses, a useful BCP is often a short, clear document you’ve actually tested, not a 50-page document nobody reads
- The NCSC’s guidance for small organisations and the BSI’s PAS 2015 standard are the most practical starting points for UK businesses
Most small businesses don’t have a business continuity plan. When something goes wrong — a ransomware attack, a flood, a key employee handing in their notice at the worst possible moment — they improvise. Sometimes that works. Often it doesn’t, and the damage is worse than it needed to be.
Business continuity planning sounds like something that only large organisations with dedicated risk teams do. The reality is that a useful plan for a small business doesn’t need to be complex. It needs to be honest about your vulnerabilities and practical about what you’d actually do.
What Business Continuity Planning Is (and Isn’t)
A business continuity plan answers the question: if something prevents us from operating normally, how do we keep serving our customers and protecting our business until we’re back to normal?
It’s broader than IT disaster recovery, which focuses specifically on restoring systems and data after a technical failure. BCP covers the whole picture: your people, your premises, your suppliers, your cash flow, and your ability to communicate with customers.
Common disruptions that BCPs address:
- Cyber attacks (particularly ransomware, which can take down IT systems for days or weeks)
- Loss of premises (fire, flood, burst pipes, landlord disputes)
- Loss of key staff (illness, resignation, sudden unavailability)
- Supplier failure (your critical supplier goes into administration or has a major outage)
- Utility failures (extended power or internet outage)
- Data loss (accidental deletion, hardware failure, or the cyber attack scenario above)
Not all of these need equal treatment. Part of the planning process is working out which disruptions would actually threaten your business’s survival.
Start with a Simple Risk Assessment
Before writing anything, spend an hour identifying your business’s critical dependencies — the things it absolutely cannot function without.
Systems and data: What software do you use every day? Where is your customer and financial data? What happens if you can’t access it for a day? A week?
People: Is there one person who holds critical knowledge or relationships that no one else has? What happens if they’re unavailable?
Suppliers: Are there suppliers whose failure would stop you from delivering your product or service? How long could you operate without them?
Premises: Could your team work from home if your office became unusable? For how long?
Customers: Which customers or contracts account for a disproportionate share of your revenue? What would losing one of them for a month look like?
For each dependency, note the likely impact and how long you could tolerate the disruption before it became serious. This sets your recovery time objectives (RTOs) — the maximum acceptable downtime for each critical function.
The Core Elements of a Small Business BCP
Once you know your critical dependencies and recovery time objectives, your plan needs to address each one:
Contact information. A list of everyone relevant — your team, your key suppliers, your IT support provider, your insurers, your bank emergency line — that’s accessible when your normal systems aren’t. A printed copy is valuable here; a plan that only exists on the server that’s been encrypted isn’t much use.
Incident response steps. For your most likely scenarios (typically: cyber attack, premises unavailability, and key staff unavailability), a short checklist of who does what in the first 24 hours. Who decides when to invoke the plan? Who communicates with customers? Who contacts the relevant authorities (police, ICO for data breaches, insurers)?
Alternative operating arrangements. How do you operate if you can’t use your normal premises? What do staff use to work if company devices are unavailable? Which manual processes would replace digital ones in a pinch? Where are the paper forms for things you normally do online?
Backup and recovery specifics. Where are your backups? How recent? Have you tested restoring from them? Who has access? This section should be specific enough that someone unfamiliar with your systems could act on it.
Communication plan. How do you tell customers about a disruption? What can you tell them about timelines? Who’s authorised to speak on behalf of the business?
The Importance of Testing
The most common BCP failure mode is a plan that was written, approved, and never looked at again until something went wrong. At that point people discover it has outdated contact numbers, no longer reflects the systems actually in use, and assumes capabilities the business no longer has.
Testing doesn’t have to be a full-scale exercise. For most small businesses, two types of testing are practical:
Tabletop exercise: Gather your team (or just yourself if you’re a sole trader with a couple of employees) and talk through a scenario. “It’s Monday morning. We’ve discovered our systems have been encrypted by ransomware. Our IT support can’t restore from backup for at least 48 hours. What do we do?” The gaps that emerge from this conversation are the gaps you need to fix.
Backup restore test: Pick a file or database from your backups and actually restore it. Not to verify the backup exists — to verify you can retrieve specific data from it within your recovery time objective. Many businesses discover their backups have been failing silently, or are structured in a way that makes recovery much slower than assumed.
Review and update the plan at least annually, or whenever you make significant changes to your systems, team, or suppliers.
UK Resources Worth Knowing
NCSC Small Business Guide and Cyber Action Plan — the National Cyber Security Centre produces practical, jargon-free guidance specifically for small organisations. The Cyber Action Plan questionnaire identifies gaps in your current security posture that would affect resilience.
Cyber Essentials — achieving Cyber Essentials certification (covered elsewhere on this site) is a good foundation for the cyber resilience elements of your BCP. It forces you to document and address the most common attack vectors.
British Standards Institution PAS 2015 — a publicly available specification for business continuity management in smaller organisations. More structured than the NCSC guidance, useful if you need to demonstrate BCP capability to customers or insurers.
Your insurer — many business insurance policies include business interruption cover. Understanding exactly what triggers it, what the claims process is, and what your insurer expects you to have documented is part of business continuity planning. Some insurers now offer discounts or easier underwriting to businesses with documented BCPs.
A plan you’ve actually written, tested once, and updated when your business changed is dramatically more useful than a perfect plan that doesn’t exist.