Picture Tuesday morning without your systems. The server room flooded overnight, or ransomware locked every file at 3am, or the building is simply inaccessible. Staff are standing around, orders are landing unanswered, and everyone is looking at you for the plan. If the honest answer is “we’d figure it out”, that is not a plan; it is a hope with a letterhead.
Business continuity planning replaces that hope with a documented, tested answer to the only question that matters in a crisis: how does this business keep trading while things are broken? We build and test those plans for businesses across Scotland, sized for SMEs rather than corporates, and written so they still make sense at 3am.
Continuity planning vs disaster recovery
The two terms get used interchangeably and should not be. Disaster recovery is the IT piece: restoring systems and data after a failure, with defined recovery times. Business continuity is the whole-business piece: how you keep operating during the disruption, which includes IT recovery but also premises, people, suppliers and communication. If the office is inaccessible, DR gets your server back; continuity planning is what tells twenty staff where to work from and which customers get called first.
We provide both, and they interlock: the disaster recovery capability sits inside the continuity plan as its IT annex. What follows covers the full plan.
What our business continuity planning covers
Risk and impact assessment. We start with what could actually stop your business, weighted by likelihood and cost: cyber attack, hardware failure, premises loss, connectivity failure, supplier collapse, key-person absence. Then the business impact analysis puts numbers on each: what an hour, a day and a week of each disruption costs, which is what turns arguments about spending into arithmetic.
Recovery objectives that mean something. For each critical system and process we agree two numbers: how long you can afford to be without it, and how much data you can afford to lose. Those targets, not vendor brochures, drive the technical design and the cost. A business that can tolerate a day offline should not pay for instant failover; a business losing orders by the minute should not discover its backups take three days to restore.
The plan itself. A short, usable document: recovery order for systems, roles and deputies by name, contact trees, workaround procedures for operating without key systems, supplier and insurer details, and communication templates for staff and customers. The corporate version of this runs to eighty unread pages; ours is built to be picked up mid-incident. Our free business continuity plan template shows the structure we use.
Testing, because untested plans are fiction. Plans meet reality on a schedule, not during a crisis: restore tests that prove the backups actually restore within the agreed time, and tabletop walkthroughs where your team works a scenario and finds the gaps on paper instead of live. Every test produces fixes, which is the point.
Annual review. Systems, staff and suppliers change; a plan describing the business as it was two years ago fails precisely when consulted. We re-verify the plan against reality on a schedule, and after any significant change.
Why insurers and clients keep asking about this
Continuity planning has quietly become an external requirement rather than an internal virtue. Cyber insurers increasingly ask about continuity and recovery arrangements at renewal, with tested backups a common condition of cover. Larger clients push continuity questionnaires down their supply chains, and public-sector tenders ask directly. Certification schemes point the same direction: the recovery disciplines here overlap heavily with what Cyber Essentials preparation demands.
Which means a tested plan now does double duty: it protects the business, and it is evidence you can hand to whoever is asking, in a form they recognise.
How engagements run
- Scoping. What the business does, what it runs on, what disruption costs. Usually one working session with the owner or ops lead.
- Assessment and objectives. Risk analysis, impact numbers, and agreed recovery targets per system.
- Build. The plan drafted, the technical gaps priced (a backup change, a failover link, a phone-system fallback), and fixes agreed before anything is spent.
- Test. First restore test and tabletop walkthrough, with the plan corrected from what they find.
- Maintain. Scheduled re-tests and an annual review, so the plan ages with the business instead of on the shelf.
For most SMEs this runs over three to six weeks alongside normal operations, delivered from our Dundee base with the same central-belt coverage as the rest of our services.
Frequently asked questions
What’s the difference between a BCP and a DR plan?
A disaster recovery plan restores IT systems and data. A business continuity plan covers keeping the whole business operating through disruption: premises, people, suppliers, communication, with DR as its IT component. Insurers and tenders increasingly ask for the latter.
How often should a business continuity plan be tested?
Restore tests on backups at least quarterly; a full tabletop walkthrough at least annually and after any major change to systems, premises or key staff. An untested plan should be assumed wrong somewhere, because they almost always are.
What are RTO and RPO in plain terms?
RTO is how long you can afford a system to be down before recovery; RPO is how much recent data you can afford to lose. Together they size and price your recovery arrangements. We cover both properly in our RTO vs RPO guide.
Do small businesses really need this, or is it corporate box-ticking?
Smaller businesses have less slack to absorb disruption, not more: fewer people, thinner cash buffers, no second site by default. The plan is shorter than a corporate one, but the need is sharper.
Will this satisfy our insurer or a client questionnaire?
That is one of its jobs. The plan documents exactly what those questionnaires probe: backups and testing, recovery objectives, roles and communication, in evidence-ready form.
What does business continuity planning cost?
For a typical SME, a defined project fee for assessment, plan and first test, agreed after scoping, plus whatever technical fixes the assessment reveals, each priced for a yes/no decision. Businesses on our managed support plans already have much of the technical layer in place, which shrinks both numbers.
Find out where you stand
The quickest test of your current resilience is a blunt question: when did anyone last restore a file from backup, and how long did it take? If nobody knows, start with our free IT health check, which includes exactly that check, and build from what it finds. Get in touch and we will put a plan where the hope currently is.