Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Business Continuity Plan for a Small Business: A Plain-English Guide

In short

A business continuity plan is your written answer to one question: how do we keep serving customers when something goes wrong? This guide explains the main risks, what RTO and RPO mean in plain terms, how backups fit in, and how to test your plan. You will finish with a simple template you can actually fill in this week.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

What a business continuity plan actually is

A business continuity plan, or BCP, is a written answer to one simple question: when something goes wrong, how do we keep serving our customers?

That “something” might be a flood, a fire, a burst pipe, a power cut, a key supplier going under, half your team off sick at once, or a cyber attack that locks you out of your own systems. A BCP does not try to predict exactly which one will happen. It sets out, in advance and in calm conditions, what you will do so that a bad day does not become a lost business.

The value is not really the document. It is the thinking. When you write a plan, you make the awkward decisions once, in daylight, instead of scrambling to make them at 7am with the phones down and staff waiting for instructions.

You do not need a huge, formal binder. For most small businesses a clear, short plan that people will genuinely read and follow is far more useful than a fifty-page document that lives forgotten in a drawer.

The risks worth planning for

Start by listing what could realistically stop you trading. Keep it grounded in your business rather than worst-case drama. Common ones for UK small firms include:

  • Loss of premises — fire, flood, a burst pipe, or a landlord problem that means you cannot get into the building.
  • Loss of IT and data — hardware failure, accidental deletion, or ransomware that encrypts your files.
  • Loss of power or internet — increasingly serious now that phones, card payments and cloud software all depend on connectivity.
  • Loss of key people — the one person who knows the payroll, the passwords, or the client relationships is suddenly unavailable.
  • Loss of a supplier — a critical supplier, software provider or subcontractor fails or is breached.
  • Cyber attack — a scam, a breach, or fraud that locks you out or drains an account.

For each risk, ask two questions: how likely is it, and how badly would it hurt us? You do not need a fancy scoring system. Sorting them into “deal with first” and “keep an eye on” is enough to guide where you spend your effort.

RTO and RPO in plain terms

Two bits of jargon are worth learning, because they turn vague worry into concrete targets. They only sound technical.

RTO — Recovery Time Objective. This is how quickly you need to be back up and running. If your online booking system goes down, can you cope for four hours? A day? A week? The RTO is the honest answer to “how long can we survive without this before it really hurts?”

RPO — Recovery Point Objective. This is how much data you can afford to lose, measured in time. If your last usable backup was from last night and disaster strikes at 4pm, you have lost a day’s work. Is that acceptable, or do you need backups every hour? The RPO is the answer to “how far back is it okay to go?”

Here is the plain-English version. RTO is about time without the system. RPO is about lost work. Shorter targets cost more, because they need faster recovery and more frequent backups. So set them per system, not for everything at once. Your accounting records might need a tight RPO; the marketing folder probably does not.

RTO is about time without the system. RPO is about lost work. Shorter targets cost more, so set them per system, not for everything at once.

Writing down an RTO and RPO for your two or three most important systems is one of the most useful hours you will spend. It tells you exactly how good your backups and recovery need to be, rather than leaving it to guesswork.

Where backups fit in

Backups are the foundation of any continuity plan, because most disasters end with the same need: getting your data back. A solid approach worth knowing is the 3-2-1 rule — three copies of your data, on two different types of storage, with one kept off-site or offline. We cover this properly in our guide to business backups and 3-2-1 disaster recovery.

Two points catch small businesses out. First, cloud software is not a backup. Microsoft 365 and similar services keep the platform running, but if a member of staff deletes files, or a scammer gets in and destroys data, you still want your own independent backup of what was inside. Second, a backup you have never restored is only a hope. Many firms discover their backups were incomplete or corrupted only when they finally need them.

Good password hygiene sits alongside backups here, because losing access to your accounts can be as disruptive as losing the data. A password manager such as Proton Pass keeps your logins and recovery codes secure and available to the right people in a crisis, and our password manager guide explains how to roll one out.

Do not forget phones and communication

Continuity is not only about data. If customers cannot reach you, they assume you are shut. Think about how you would answer calls if your office was unreachable. A modern internet-based phone system makes this far easier, because calls can be diverted to mobiles or a temporary location in minutes rather than being tied to a physical line at one address. Providers such as Airlandline offer UK business phone and broadband set up this way, and our overview of business VoIP phone systems explains the options.

Also plan how you will tell people what is happening: staff, customers and suppliers. A short pre-agreed message and an up-to-date contact list save a lot of panic.

A simple template approach

You can write a workable plan in a single afternoon. Cover these sections:

  1. Key contacts. Staff, your IT support, insurers, landlord, bank, main suppliers. Store a copy somewhere you can reach even if your systems are down.
  2. Critical functions. The two or three things the business must keep doing to survive, and who owns each one.
  3. Risks and impact. Your short list from earlier, sorted by priority.
  4. RTO and RPO. Your recovery targets for each critical system.
  5. Recovery steps. For each big risk, a simple numbered list of what to do first, second and third, and who does it.
  6. Backups. Where they are, how to restore them, and who has access.
  7. Communication. How you will reach staff and customers, and a draft holding message.
  8. Review date. When you will next test and update the plan.

Keep it in plain language. The test of a good plan is whether someone who is not you could pick it up during a crisis and know what to do.

Test it, or it is just a document

A plan you have never tested is a guess. Testing does not need to be a full-scale drill. Two low-cost tests catch most problems:

  • A tabletop walk-through. Gather the team, describe a scenario — “it’s Monday, the office is flooded” — and talk through who does what. Note every point where the plan is unclear or someone says “I didn’t know I was doing that.”
  • A real restore test. Actually recover some files from your backup and check they open. This is the single most reassuring test you can run.

Review the plan at least once a year, and after any big change such as new premises, new software or a new IT provider. People, systems and suppliers move on, and a plan that describes last year’s setup can be worse than no plan at all.

Where DACROS fits

A good managed IT partner takes much of this off your plate: reliable, tested backups; sensible recovery targets; and a continuity plan that reflects how your business really works. If you would like a hand writing or stress-testing your plan, or you are not sure whether your backups would actually work, get in touch with DACROS or read more about what managed IT support includes. You can also see our full range of services to understand how the pieces fit together.

The hardest part is starting. Block out an afternoon, use the template above, and you will end the day with something far more valuable than a document — a business that knows how it would cope.

Frequently asked questions

What is the difference between a business continuity plan and a disaster recovery plan?

A business continuity plan (BCP) is the wider document. It covers how the whole business keeps running, including staff, premises, phones, suppliers and communication. A disaster recovery plan is usually a narrower, more technical part of it, focused on getting IT systems and data back. For most small businesses, one combined BCP that has a clear IT recovery section inside it is enough.

How long should a small business continuity plan be?

Short enough that people will actually read it. For most small businesses that means a handful of pages: your key risks, who does what, your recovery time and recovery point targets, your contact list, and your step-by-step recovery notes. A tidy five to ten page plan that is kept up to date beats a fifty page document nobody opens.

How often should we test our business continuity plan?

At least once a year, and again after any big change such as moving premises, switching IT provider, or adopting new software. Testing does not have to be dramatic. A tabletop walk-through where you talk through a scenario around a table, plus an actual test restore of your backups, will catch most problems.

Do we really need a plan if we use cloud software like Microsoft 365?

Yes. Cloud software keeps the platform running, but it does not decide who does what when your office loses power, your accounts are locked by a scammer, or a supplier fails. It also does not replace your own backups of the data inside those services. A BCP ties all of that together into decisions your team can follow under pressure.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.