Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Guide

How to Build a Business Continuity Plan (Small Business)

A plain-English guide to writing a business continuity plan that actually works when something goes wrong — what to include, who needs one, and where to start.

If a burst pipe closed your office tomorrow, or ransomware locked your files on a Monday morning, how long before your business was trading normally again? A business continuity plan is simply the document that answers that question in advance — so you’re not working it out in a panic while the clock runs and customers wait.

This guide keeps it practical. No corporate templates, no jargon. Just what a continuity plan is, what belongs in it, who needs one, and how to write a version that genuinely helps on a bad day.

What a business continuity plan actually is

A business continuity plan (BCP) is a short, practical document that sets out how your business keeps operating — or gets back on its feet quickly — when something disrupts normal work. That “something” might be a flood, a power cut, a cyber attack, a failed server, a key supplier going under, or a member of staff being suddenly unavailable.

The point isn’t to predict every possible disaster. It’s to work out, calmly and in advance, what your business truly can’t run without, and to have a plan for each of those things. Done well, it turns a crisis from a scramble into a sequence of steps you’ve already thought through.

A good plan is honest about priorities. Not everything matters equally. Payroll running, orders being taken, patient or client records being accessible — these are the things that hurt within hours. Working out that order of importance is half the value of the exercise.

What a continuity plan includes

You don’t need a huge document. A useful small-business plan usually covers these areas:

  • Your critical functions. List what the business must be able to do to keep earning and keep customers safe. Be specific: “take card payments”, “access case files”, “send invoices”. Rank them by how quickly their loss would bite.
  • Your recovery time goals. For each critical function, note how long you could survive without it. An hour? A day? This shapes everything else, because faster recovery costs more to prepare for.
  • Your data and systems. Where does your important data live, and how is it protected? This is where reliable backup and continuity planning matters — you want backups that are recent, tested, and stored away from the thing that might fail. If you can’t confidently answer “when did we last successfully restore from backup?”, that’s your first gap.
  • Your people and roles. Who does what when something goes wrong? Who declares an incident, who talks to staff, who contacts customers, who calls your IT support? Name real people, and a deputy for each, in case someone’s on holiday.
  • Your key contacts and access. Phone numbers for your IT provider, insurer, bank, landlord and main suppliers. Details of how to access systems if the office is off-limits — and crucially, not stored only on the systems that might be down.
  • Your recovery steps. The actual sequence: what happens in the first hour, the first day, the first week. Cyber incidents especially need this written down, because sensible cyber security response — isolate, assess, restore, notify — is hard to improvise under pressure.
  • Communications. What you’ll tell staff, customers and, if needed, the ICO. A holding message drafted in advance saves precious time and prevents a worse impression.

The document should be readable in ten minutes and findable when systems are down. A plan that only exists as a file on the server that just died is no plan at all.

Who needs one, and when

Honestly, any business that would lose money, customers or trust from a day of downtime needs a continuity plan — which is nearly all of them. But some feel the pain harder.

Regulated and record-heavy businesses are the clearest case. If you’re an accountant in the middle of a filing deadline, a law firm holding client files, or a dental practice that can’t see patients without its records, an outage isn’t an inconvenience — it’s lost revenue and a compliance problem at once. For these, continuity planning isn’t optional.

Small teams need it more than they think. When one person holds the passwords, knows the supplier, or is the only one who understands a system, their absence — or a laptop failure — can stall the whole business. A plan spreads that knowledge so it doesn’t walk out the door.

As for when: the honest answer is before you need it, which in practice means now. The best time to plan is a quiet week, not the morning your files won’t open. It’s also worth revisiting the plan after any real change — new premises, new systems, a bigger team, or a near-miss that showed you a gap. And if the worst has already happened, the priority shifts to data recovery first, with the plan written properly once you’re back on your feet.

Making a start

You don’t have to do this in one sitting, or alone. Start with the single question at the top of this guide — how long could we survive without our most important system? — and write down what you find. Even a rough first draft is worth far more than a perfect plan you never begin.

If you’d like a hand pressure-testing your setup — checking your backups really restore, mapping what would break, and turning it into a plan your team can actually follow — that’s exactly the kind of thing we help South London and Surrey businesses with. Get in touch and we’ll talk it through in plain English, no scare tactics.

Frequently asked questions

What's the difference between a business continuity plan and a disaster recovery plan?

A business continuity plan is the wider document — it covers how the whole business keeps trading through any disruption, including people, premises, phones and suppliers. Disaster recovery is the IT part of that plan: how you get systems, data and access back. You need both, but the IT recovery steps sit inside the broader continuity plan rather than replacing it.

How often should we test our continuity plan?

At least once a year, and again after any big change — a new system, an office move, or a jump in headcount. A plan that's never been tested is really just a hopeful document. A short annual walkthrough, plus a genuine test of your backups, is enough for most small businesses to catch the gaps before a real incident does.

We're a five-person business. Is a continuity plan really worth it?

Yes, and it needn't be long. Small teams are often more exposed, not less, because one person usually holds knowledge or access nobody else has. A two-page plan covering your key systems, your backups and who does what in a crisis will serve you far better than a fifty-page document nobody reads.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.