Backup & Continuity
Business continuity planning for SMEs: what a workable plan looks like
A practical guide to business continuity planning for UK SMEs: critical functions, realistic risks, RTO and RPO, backups, communication and a plan outline.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
A business continuity plan for an SME is a short, tested document that names the functions the business cannot trade without, the realistic risks to them, how quickly each must be restored, and who does what when something fails. It covers people, communication and workarounds as well as IT, and it is reviewed whenever systems, staff or premises change.
Most SMEs do not have a business continuity plan. They have backups, an IT provider's phone number and a belief that things will be sorted out on the day. That belief usually survives until the first real incident, when it becomes clear that nobody agreed what mattered most, who could make decisions or how staff would work in the meantime. This guide explains what continuity planning looks like for a business of up to 250 people, what to include, and how to check where you stand today.
What business continuity planning is, in plain terms
Continuity planning is deciding in advance how the business keeps operating when something stops working. Not at full capacity, and not for every conceivable catastrophe, but at an acceptable level for the disruptions that actually happen: hardware failure, ransomware, a cut broadband line, a flood in the office, a key person off sick, a supplier going under.
It answers three questions. What must keep running? What could realistically stop it? What do we do when it does? For most SMEs the answers lean heavily on IT, because email, phones, files, accounts and line-of-business systems are where the work lives, but the plan is broader than IT. It covers people, decisions, communication and workarounds.
Identify the functions you cannot trade without
Start with activities, not systems. Taking orders, invoicing, answering the phone, accessing client files, paying staff, meeting a regulatory deadline. Then map each to the systems and people behind it. A typical SME list:
| Function | Systems behind it | People who know it |
|---|---|---|
| Answering customer calls | VoIP platform, broadband, mobile apps | Reception, office manager |
| Email and documents | Microsoft 365, SharePoint | Everyone, admin with one person |
| Accounts and payroll | Accounts package, bank access | Finance manager |
| Job or case management | Line-of-business application, server | Operations lead |
| Site connectivity | Router, firewall, switches, VPN | IT provider |
The exercise usually reveals two or three things nobody had noticed: a system only one person can administer, or a function that depends on a server that has no documented recovery.
Focus on realistic risks
SMEs sometimes dismiss continuity planning because they picture earthquakes. The disruptions that actually close businesses for days are ordinary: a failed server, a ransomware infection from a phishing email, a broadband fault, a burst pipe, a power cut, a director's laptop stolen from a car, an accounts manager off for six weeks. The Cyber Security Breaches Survey 2025 found that around four in ten UK businesses identified a cyber attack or breach in the previous year, which makes a cyber incident the most likely serious disruption most SMEs will face.
For each critical function, note the two or three most likely ways it could stop and how bad that would be after an hour, a day and a week.
Set recovery targets the business agrees with
Two numbers per critical system, agreed by the directors rather than assumed by IT:
- Recovery time objective (RTO): how long the function can be down before the damage is unacceptable.
- Recovery point objective (RPO): how much work, measured in time, you can afford to lose.
Phones might get a one-hour RTO. Email four hours. The job management system four hours with a two-hour RPO. The archive server two days. These targets drive every spending decision that follows, from backup frequency to whether you need a standby server. Worked figures are in RTO vs RPO explained.
Protect the data first
Data is the one thing that cannot be re-bought. The plan should state, for each system, where it is backed up, how often, how long copies are kept, where the off-site copy is, which copy is immutable and when a restore was last tested. Follow the 3-2-1 rule, include Microsoft 365, and make sure the backups are not reachable with the same credentials as the live systems.
This is where Dig IT's experience shapes the advice. For Mr Plant Hire, servers are backed up locally several times a day and to the cloud, so a mid-afternoon failure costs hours rather than a day and a fire would not cost the business its records. The full rationale is in backup vs disaster recovery.
People, communication and workarounds
Plan how people communicate
Communication fails first and hurts most. Decide now:
- How staff are told what is happening if email and Teams are down (a WhatsApp group, a phone tree, a printed list of mobiles).
- Who speaks to customers and what they say. A short, honest holding message agreed in advance beats improvisation.
- How the phones keep being answered. Hosted VoIP with divert to mobiles handles most office closures, as covered in VoIP and business continuity.
- Which suppliers and partners need telling, and who tells them.
- When the ICO must be informed. A breach involving personal data may be reportable within 72 hours under UK GDPR, and the ICO's guidance sets out the test.
Customers judge a business by how it handles a problem far more than by whether one occurred. Silence and vagueness cost trust. Early, plain communication usually preserves it.
Make remote working part of the plan, not a workaround
If staff can work securely from home, most office-based disruptions become an inconvenience. That requires laptops rather than desktops, multi-factor authentication on Microsoft 365 and the VPN, managed devices, and the phone system on an app. Test it: a morning where everyone works from home is a cheap continuity exercise.
Remove single points of failure
The commonest reason SME recovery plans fail is that they depend on one person. One administrator with the passwords. One director who can authorise spending. One finance manager who knows how the payroll run works. Write down who deputises for whom, give a second person the admin access and store credentials in a shared password manager with break-glass access. Our article on why IT recovery plans fail deals with this at length.
Readiness checklist
If you can answer these confidently, you are better prepared than most. If not, each "no" is an item for the plan.
- Can you list the five systems the business cannot trade without?
- Do you know how long a full restore of your main server would take, from experience rather than assumption?
- Is there a backup copy that a compromised administrator account could not delete?
- Is Microsoft 365 backed up separately?
- Could a second person restore a server or switch the phones if the usual person were unreachable?
- Do staff know how they would be contacted if email were down?
- Have you worked a day without the office in the last year?
- Is there a printed contact list for staff, IT provider, VoIP provider, insurer and key suppliers, kept off-site?
- Does your cyber insurance policy require anything you are not currently doing?
- When was the plan last reviewed after a staff, system or premises change?
A plan outline that fits an SME
- Purpose and scope, one paragraph.
- Critical functions and systems, with owners and deputies.
- Recovery targets, RTO and RPO per system.
- Risk scenarios, the five or six most likely.
- Backup and recovery arrangements, what, where, how often, who checks, when last tested.
- Immediate actions per scenario, one page each.
- Roles, contacts and delegation, including who can spend money and speak to customers.
- Communication plan, staff, customers, suppliers, regulator.
- Workarounds, how each function runs manually or from home for a day.
- Suppliers and escalation, IT, telecoms, software, insurer.
- Testing schedule and review triggers.
The IT-specific sections are expanded, with wording you can adapt, in our IT disaster recovery plan template. If you would rather have it built with you, that outline is the structure Dig IT's business continuity planning service follows.
Keep the finished document short. Directors will read six pages during an incident. They will not read forty. Print two copies, keep one at home, and store a PDF somewhere that does not depend on the office network or the Microsoft 365 tenant that may be the thing that has failed.
Test it and keep it current
An untested plan is a hypothesis. Quarterly, do something small: restore a file, force the phone divert, run payroll from a laptop at home. Annually, walk through a full scenario against the clock with one key person deliberately excluded. Review the plan after every new system, new site, new supplier or change of key staff, because those are the moments it quietly goes out of date.
What to do next
Most SMEs need a day of structured work to get from "we have backups" to a plan a second person could follow. Dig IT runs that work with your directors, from the critical-function list through recovery targets to a tested first exercise. Book an IT health check as the starting point and we will tell you where the gaps are.

