Most business continuity plans fail for a boring reason. They are too long. Somebody downloads a template, fills in forty pages, saves it to a folder, and never opens it again. Two years later it describes a decommissioned server, a phone system nobody uses, and an emergency contact who left. When something goes wrong, nobody reads it, because nobody can find the part that matters in under a minute.

For a company under fifty people, we think the right answer is one page. Not because you deserve less planning than a big company, but because a one page plan is a plan you will actually update. This article walks through what belongs on that page, who owns each part, and a review ritual that takes about an hour a year. We will also clear up the difference between continuity and disaster recovery, since the two terms get used interchangeably and they are not the same thing.

Continuity and Disaster Recovery Are Not the Same Thing

Here is the plainest version we know. Disaster recovery is about restoring technology. Business continuity is about continuing to serve customers, including while the technology is still broken.

Disaster recovery answers questions like: where are the backups, how long until the server is rebuilt, and how much data will we lose. Continuity answers questions like: how do we take orders today, who calls our biggest customers, and where does everyone work if the building is closed. The federal Ready.gov business continuity plan template makes the distinction structural, listing an information technology disaster recovery plan as its own appendix item, to be included separately if it is not folded into the continuity plan.

Both matter. If you only have time for one conversation this quarter, have the continuity one. It keeps revenue moving while the technical work happens.

Start With What Must Keep Running

Ready.gov calls this a business impact analysis. For a company your size, it is a twenty minute conversation with three or four people who know how work actually gets done. Ask one question about each function: if this stopped this morning, when does it start costing us real money?

  • Rank functions, not systems. “Taking customer orders” and “paying employees” are functions. Your order entry software is a system that supports one. Ranking functions keeps you from protecting a tool you could work around.
  • Put a clock on each one. Some functions can pause for a week without harm. Some cannot pause for two hours. Write the number down. That number, not a salesperson’s recommendation, is what justifies spending on redundancy.
  • Name the manual workaround. The Ready.gov template specifically calls for documenting manual workarounds. Paper order forms, a cell phone list, a spreadsheet, cash and a receipt book. Unglamorous and effective.
  • Decide how much data you can afford to lose. If your backup runs nightly, a failure at 4 p.m. costs you a day of work. That may be perfectly acceptable. It just needs to be a decision rather than a discovery.

Who Decides to Invoke the Plan

This is the part small companies skip and it is the part that costs the most. In a crisis, the expensive delay is almost never technical. It is four people waiting for someone to make a call.

Name one person who can declare an incident and start the plan, and name two backups in order. The Ready.gov template asks organizations to document succession of management and delegation of authority for exactly this reason. Write it as a sentence a stranger could follow: if the owner cannot be reached within thirty minutes, the operations manager decides, and if neither is reachable, the office manager decides. Then write down what that person is authorized to do without further approval, such as sending everyone home, spending up to a set dollar amount, or calling your IT provider and approving emergency work.

The One Page Plan

Everything above collapses into a single page with six blocks. Print it. Keep a copy off the network. Ready.gov recommends keeping plan copies in multiple accessible places, including secure websites and USB drives, and the logic is simple: a plan stored only in the system that just failed is not a plan.

  1. Critical functions and their clocks. Three to six lines. Function, how long it can stop, and the manual workaround.
  2. Who decides, and their backups. Three names with mobile numbers and the authority each one carries.
  3. Where the backups and documentation live. Name the backup system, where copies are kept, who can restore, and where the network diagram, asset list, and password vault are. CISA’s Cyber Essentials guidance recommends regular automated backups plus protections including physical security, encryption, and offline copies. Write down when the last test restore happened.
  4. How we communicate if email is down. Pick a primary and a backup that do not depend on the same system. A group text thread plus a phone tree works. So does a messaging app on personal phones. Keep a printed contact list, because your contacts live in the thing that is broken.
  5. Where people work if the building is unavailable. Home, a second location, a partner’s conference room, or a coworking space. Note what staff need to work remotely and whether they already have it. Flood, fire, and a burst pipe all produce the same problem.
  6. Key contacts. IT provider, internet provider with the account number, landlord, insurance agent with the policy number, bank, payroll company, and your two largest customers. Include after hours numbers.

One caution on the cloud. Moving to hosted services removes some risks and adds others. As Harrison says, the cloud is just someone else’s computer, and your plan still needs an answer for the morning that computer is unreachable. We covered that specific scenario in our post on what a cloud outage means for your business.

The Annual Review Ritual

Put it on the calendar for the same week every year. Ours is one hour, and it looks like this. Read the page out loud with two or three people. Correct anything that changed: staff, phone numbers, vendors, systems, locations. Confirm one backup restore was tested in the last twelve months and write the date on the page. Then pick a single scenario, say the internet is out all day, and talk through the first two hours. Not a drill, just a conversation.

The SBA recommends practicing your plan with staff so you are ready when a disaster occurs, and assessing which disasters are most likely to affect your business, since knowing that helps you return to operations faster. In North Texas that list usually starts with severe storms, extended power loss, and cyber incidents. The SBA also offers low interest disaster loans, including economic injury disaster loans, which is worth knowing before you need it.

The Bottom Line

A one page continuity plan that gets reviewed every year beats a forty page plan that gets written once. Decide what must keep running, name who calls it, write down where the backups and documentation live, agree how you will talk to each other without email, and pick a place to work. Then look at it once a year and fix what changed. That is the whole discipline: an afternoon to build, an hour a year to maintain. If you outsource IT, ask your provider to bring their part of the page to that review, which is one of the working habits we describe in what to look for in an IT partner.

If you want help building the page, or someone to pressure test the plan you already have, we do this with clients every year. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).