Business continuity

A plan for the day it stops working.

Most firms have no continuity plan, or one nobody has opened since it was written. Both feel fine, right up until the morning something breaks.

The questions it answers

None of these are unlikely.

A good fit if you have never had to find out what the answers are.

  • Your main system is down and nobody can say how long rebuilding takes.
  • You cannot get into the building on Monday. Does anything actually stop?
  • The one person who knows how it all works is unreachable for a fortnight.
  • A supplier you depend on goes down, and their outage becomes yours.
  • Someone gets into your email and starts sending from it.
  • Your files are encrypted and a ransom demand is attached. Which backup do you reach for?
Resilience by design

The best continuity plan is a system that barely needs one.

Most of continuity isn't the document. It's decisions made when the system is built, so the document stays short.

01

Security first

Access is locked down when the system is built, not patched after an incident. The design assumes someone will try the door.

02

Remote by default

If the building is off-limits, work carries on from anywhere, without loosening a single control to make that possible.

03

No single point of failure

No one machine, one supplier, or one person whose absence stops the business trading.

04

Backups that restore

Scheduled, off-site, and proven by actually restoring them, not by assuming the green tick means what you hope.

05

A known recovery order

What comes back first is decided in advance. Mid-incident is the worst time to have that argument.

06

A plan people can follow

Short enough to read under pressure, current enough to be true, and usable by somebody who isn't you.

Three ways in

Review it, write it, or find out if it works.

If you already have a plan, reviewing it is the cheaper starting point, and often the only thing needed.

01

Review the one you have

Most plans were written once, for somebody else, and never read since. A walkthrough finds what breaks, and often that's all that's needed.

02

Write one from scratch

Who's in charge, who calls whom, what each person does on the day. Written so somebody can pick it up cold and follow it.

03

Test it, properly

A plan nobody has tried is a document, not a capability. Restore the backup for real, work the fallback for a day, fix what fails.

Where this comes from

I've run continuity for a global operation, where the plan was rehearsed for real, not filed.

Walking each department through what a bad day looks like, deciding what comes back first, and proving the fallback works before it's needed. Systems built to survive losing a site or a supplier, with the recovery order agreed in advance, because mid-incident is the worst time to have that argument.

The scale was different. The discipline isn't. A small firm needs the same things a big one does: a system designed to lose a piece of itself, and a plan short enough to follow at 7am.

Tested means tested

A rehearsed plan is a procedure. An untested one is a guess.

Testing means actually running on the fallback: restoring the backup, working without the primary system, on a quiet Tuesday rather than during the emergency. It removes the fear, which matters more than people expect.

If you are regulated

Evidence, not just a folder.

If a regulator or client requires your plan, they'll also want to see it's tested and current. I handle the technology and operational side and produce that evidence. Your compliance obligations stay with you and your advisers: I make sure the machinery behind the answers holds up.

Common questions

The things people ask first.

What is a business continuity plan, in plain terms?

A written answer to "what do we do if this stops working", decided before you need it. The test is whether somebody else could pick it up while the thing is on fire and follow it.

Is this the same as having backups?

No. Backups are one ingredient. Continuity is whether the business keeps operating while they restore, and how long that actually takes, which most firms have never measured.

Do I need one with only a handful of people?

Yes, a proportionate one. A few pages, not a binder. The smaller the firm, the more concentrated the risk: usually one laptop, one email account, and one person who holds it all together.

How much does it cost?

A fixed price agreed before anything starts, sized to the firm rather than a template. Reviewing an existing plan is usually much cheaper than writing one.

What does testing actually involve?

Running the plan for real: restoring the backup, working on the fallback, timing how long recovery takes. The point is finding what fails on a quiet day instead of a bad one.

What would actually stop you trading tomorrow?

If you can answer that in one sentence, you are ahead of most. If you cannot, that is the conversation, and it is free.