Most business continuity plans are written to satisfy an auditor, filed in a shared drive, and never read again. They describe scenarios in the abstract – “loss of premises”, “significant disruption” – in language that makes it easy not to picture the thing actually happening.
So picture it instead. It is a Tuesday. At seven in the morning you get a call: nobody is getting into the building today. It might be a fire in the unit next door, a burst main, a power fault, a police cordon, a flood. The cause barely matters. What matters is that forty people have nowhere to sit, and your customers have no idea yet.
Here is how that day actually unfolds, hour by hour, and where most businesses discover the gap between the plan they have and the plan they needed.
08:15 – The first thing you notice is the phones
Before anyone worries about files or systems, the phones stop. Customers ring the main number and it rings out, or worse, it rings in an empty building. Your sales line, your support line, your accounts line – all pointing at hardware nobody can reach.
This is the failure that does the most reputational damage in the first hour, and it is also the easiest to design out. A cloud-hosted phone system is not tied to the building. Numbers follow people. Calls route to mobiles or softphones on laptops, hunt groups carry on working, and the customer ringing at 08:15 hears the same greeting they always hear.
If your telephony still terminates in a cabinet on site, that is the single highest-value thing to change before you do anything else.
Cloud telephony and connectivity
09:00 – Your team are standing in a car park
The second question is where people work. If the answer depends on a server in the building, the answer is nowhere.
This is the practical test of whether you have genuinely moved to the cloud or simply moved some things to the cloud. Plenty of businesses run Microsoft 365 for email and documents while their line-of-business system – the ERP, the accounts package, the stock system, the thing the business actually runs on – still lives on a physical server behind the door nobody can open.
Hosting that system properly means the building becomes irrelevant to whether people can work. Staff log in from home, from a serviced office, from a customer site, and the working day carries on.
Hosted cloud infrastructure · Read how one organisation made the move
10:30 – Somebody asks where the files are
By mid-morning the questions get specific. Where is the signed contract. Where is the drawing the customer needs today. Where is the version of the spreadsheet from Friday.
Two things catch businesses out here.
The first is backup that has never been tested. A backup job that reports success every night is not the same as a backup you have actually restored from. The moment you need it is the worst possible moment to discover the retention was wrong, the job had been failing silently for weeks, or the only copy sits on a NAS in the building you cannot enter.
The second is the Microsoft 365 assumption. A great many businesses believe Microsoft backs up their data. Microsoft protects the platform; the data in it is your responsibility. Deleted mailboxes, corrupted SharePoint libraries and files encrypted by ransomware are not Microsoft’s problem to restore, and the standard retention windows are shorter than most people assume.
Why Microsoft 365 needs its own backup
By lunchtime – customers have worked it out
Nobody has been able to reach you for four hours. Orders have not been acknowledged. A delivery has not been confirmed. At this point the incident stops being operational and starts being commercial.
The businesses that come through this well are not the ones with the cleverest technology. They are the ones who could tell customers what was happening within the first hour, because they had a way to reach them that did not depend on the office. A current contact list held somewhere accessible, a nominated person to communicate, a holding message that goes out before customers start chasing.
It costs nothing and it is the most commonly missing item in an otherwise decent plan.
The next morning – what this actually costs
The direct costs are the visible ones: replacing kit, temporary space, overtime. They are rarely the biggest number.
The real cost is the trading you did not do, and it compounds. A day of lost orders is recoverable. A week of silence while a competitor answers the calls you could not is a different conversation. For businesses with contractual service levels or supply-chain obligations, there may be penalties attached to the downtime itself.
This is also where cyber incidents differ from physical ones in an important way. A flood ends. Ransomware does not end until you either restore cleanly or pay – and if the attacker has been in your network for weeks before triggering, your backups may be compromised too. Detecting that early is a different discipline from backing up, and it needs monitoring rather than storage.
24/7 monitoring, detection and response · Why cyber risk is a board-level risk
What a plan that actually works contains
A useful continuity plan is short, specific, and answers two numbers for every critical system.
Recovery Time Objective (RTO) – how long can this be down before it genuinely hurts?
Recovery Point Objective (RPO) – how much data can we afford to lose and re-key?
Most businesses have never set these, which means their IT is protected to whatever standard happens to have accumulated rather than to what the business actually needs. Setting them is a business decision, not a technical one, and it usually takes an afternoon.
| System | Typical RTO | Typical RPO | What that implies |
|---|---|---|---|
| Phones and email | Under 1 hour | Near zero | Cloud-hosted, not on-site |
| Line-of-business / ERP | 4–8 hours | Under 1 hour | Hosted or replicated, tested failover |
| File storage | 4–24 hours | Under 4 hours | Versioned backup, off-site copy |
| Archive and historic data | Days | 24 hours | Lower-cost backup tier is fine |
Once those numbers exist, most arguments about what to spend resolve themselves.
The short checklist
Work through these and you will be ahead of most businesses your size:
- Can your phones be answered if nobody can enter the building?
- Can staff access every critical system from home, today, without IT intervention?
- When did you last perform a test restore – not check a backup report, but actually restore a file and open it?
- Is your Microsoft 365 data backed up independently of Microsoft?
- Do you have an off-site or immutable copy that ransomware cannot reach?
- Could you contact every key customer and supplier without access to the office?
- Do you know who makes the call to invoke the plan, and who deputises if they are unreachable?
- Has anyone read the plan in the last twelve months?
If you answered no to more than two of those, the gap is not technical – it is that nobody has been given the time to close it.
Why this is rising up the agenda
Resilience is also becoming a regulatory question rather than a purely voluntary one. The Cyber Security and Resilience Bill currently before Parliament extends duties around incident reporting and supply-chain resilience, and the direction of travel is clear: larger customers will increasingly ask their suppliers to evidence continuity arrangements as a condition of doing business.
For most SMEs the commercial driver arrives before the legal one. Tender questionnaires already ask about disaster recovery, and “we have backups” is no longer an answer that scores well.
How to prepare for the Cyber Security and Resilience Bill
Frequently asked questions
What is the difference between business continuity and disaster recovery?
Business continuity is the whole plan for keeping the organisation trading – people, premises, communications, suppliers. Disaster recovery is the IT subset of that: restoring systems and data. You need both, but a disaster recovery plan alone will not tell you how to answer the phone.
How often should a business continuity plan be tested?
At least annually, and after any significant change to your systems or premises. A desktop walkthrough with the management team takes a couple of hours and reliably surfaces gaps. Test restores should happen far more frequently than that – quarterly at minimum.
Isn’t cloud hosting enough on its own?
No. Cloud hosting removes your dependence on a physical building, which solves a large part of the problem, but it does not protect you from deletion, corruption, ransomware or account compromise. You still need independent backup and a way to detect an attacker before they act.
How much should an SME budget for business continuity?
There is no single figure, because it depends entirely on your RTO and RPO. The useful exercise is to work out what a day of downtime costs your business, then compare that to the cost of reducing the risk. For most SMEs the honest answer is that the gap can be closed for less than the cost of one bad day.
We’re a small business – is this really necessary?
Smaller businesses are usually more exposed, not less, because they have fewer people, less redundancy and thinner cash reserves to absorb a fortnight of disruption. The plan can be proportionate, but it should exist.
Where to start
You do not need a hundred-page document. You need to know your RTO and RPO for the handful of systems the business genuinely cannot trade without, and you need to have tested that you can actually hit them.
If you would like a straightforward view of where your business stands, EBS runs continuity and resilience reviews for organisations across Birmingham and the West Midlands – a short assessment of your current position, the gaps that matter, and what it would take to close them.
Managed IT support in Birmingham
Talk to the EBS team about a continuity review.