Small Business Continuity Plan: A Practical One-Page Guide

Small Business Continuity Plan: A Practical One-Page Guide
A business continuity plan for small business operations does not need to begin with a dramatic disaster. One unavailable manager, a failed internet connection, a locked office or a supplier outage can stop customer work surprisingly quickly. The warning signs are familiar: nobody knows which orders come first, staff use different contact lists, callers hear an unanswered phone and vital information sits on a laptop that cannot be reached.
A business continuity plan (BCP) explains how you will keep essential work running during disruption and recover in a controlled order. For a small business, the useful version does not need to begin as a thick policy. Start with one operational page that tells the team what matters, who takes charge, what the fallback is and when to escalate.
This guide helps you write that page, add time-based recovery actions and test it in 30 minutes. It covers people, premises, suppliers, systems, data and customer communications. You can copy the headings into your own working document; there is no special software or imagined download required.
Why one useful page beats an unread emergency folder
The UK government’s business continuity toolkit frames continuity around identifying the parts of an organisation it cannot afford to lose. That is a productive starting point for a small team because it shifts attention from every possible disaster to the few outcomes that must continue.
Your first page is not the entire continuity programme. It is the control panel. Supporting items such as staff details, supplier contacts, insurance information, system recovery instructions and site maps can sit behind it. The page should point to those records without exposing personal or security-sensitive information unnecessarily.
A useful page passes three tests:
- A colleague can understand it in five minutes without the owner explaining it.
- It still works if the usual decision-maker is unavailable.
- Every fallback names an owner, a trigger and a way to confirm that it worked.
If the plan only lists risks, it will not direct a response. If it only lists telephone numbers, it will not set priorities. If it assumes every normal system remains available, it is not a continuity plan.
Spend 20 minutes deciding what must survive
Before writing the plan, run a short business impact triage. Gather the people who understand sales, delivery, customer service, finance and technology. Ask them to identify the smallest set of outcomes the business must protect.
Name essential outcomes, not whole departments
“Keep operations running” is too broad. “Confirm today’s engineer visits”, “dispatch paid orders”, “answer urgent support calls” and “authorise payroll” are specific enough to plan around.
For each outcome, record:
- the customer or business consequence if it stops;
- the maximum tolerable downtime: the longest interruption you can accept before the effect becomes serious;
- the minimum people, information, equipment and supplier access required;
- the simplest safe manual workaround;
- the evidence that the service is operating again.
Do not pretend every activity is urgent. A routine marketing report may wait for a week, while access to the day’s appointment list may be needed within an hour. Ranking work honestly prevents the loudest request from displacing the most important recovery.
Find the single points of failure hiding in normal work
Small businesses often concentrate knowledge and access in a few places. Look for processes where only one person knows the password, one device stores the file, one supplier can deliver the part or one office receives every call.
Ask “what if this is unavailable today?” about:
- the owner or another key employee;
- the main premises;
- internet access, electricity and mobile coverage;
- customer, order and scheduling records;
- the main telephone number and shared inbox;
- card, invoicing or banking access;
- a critical supplier, courier or contractor;
- administrator accounts and authentication devices.
The aim is not to remove every dependency immediately. It is to know which ones need a verified alternative and which risks the business has consciously accepted.
Write your one-page small business continuity plan
Use the following eight sections as the working page. Keep each answer short enough to act on. Store detailed instructions elsewhere and give them clear locations.
1. Activation: who declares an incident?
Name a primary incident lead and at least one deputy. Define simple activation triggers, such as the main premises being inaccessible, an essential system being unavailable beyond its tolerated time, or staff being unable to serve customers safely.
State where the team will assemble or communicate if normal channels fail. Avoid relying on a chat group that can only be reached through the same unavailable identity system as the rest of the business.
2. Immediate priorities: what happens first?
Write the first actions in order. People’s safety and emergency guidance come before operational recovery. After that, the sequence might be:
- Confirm who is safe and available.
- Establish an incident communication channel.
- Assess which essential outcomes are affected.
- Start approved workarounds.
- Tell affected customers what is known and when the next update will come.
- Record decisions, costs, promises and changes.
Include a clear boundary for stopping unsafe or unreliable work. Continuing badly can create a larger customer, privacy or financial problem than pausing briefly and communicating honestly.
3. Essential work: what continues, pauses or moves?
List no more than five priority outcomes on the page. Beside each one, add its tolerated downtime, primary owner, deputy and minimum service level.
A property maintenance company might decide that urgent tenant faults and engineer safety checks continue, routine quote follow-up moves to the next working day, and non-urgent reporting pauses. A retailer might prioritise paid-order dispatch and customer updates while postponing catalogue changes.
The minimum service level matters. “Answer every enquiry normally” may be impossible. “Acknowledge urgent requests within one hour, capture a safe callback number and provide the next update time” is measurable under constrained conditions.
4. People and premises: where can the team work?
Record who can perform each essential role and who can approve exceptions. Add a safe alternative workplace, remote-working option or reciprocal arrangement if appropriate. Note the minimum equipment people need, rather than assuming a full office can be recreated immediately.
Plan for key-person absence as well as building loss. Deputies need actual access and enough practice to act. A name in a document is not a fallback if that person has never opened the scheduling system or handled the supplier account.
5. Systems and data: what can be restored or worked around?
For every priority outcome, point to the system of record, the backup or export, the recovery owner and the last successful test. The National Cyber Security Centre guidance on backing up data recommends identifying essential data, keeping backups separate and checking that recovery works.
A backup is only evidence after somebody has restored a representative file or service. Record the result and the date. Also define a temporary capture method so orders, callbacks and decisions made during an outage can be reconciled later instead of disappearing into scraps of paper and personal messages.
6. Suppliers: which alternatives are real?
List critical suppliers and the effect of their failure. For each one, record the escalation contact, an alternative source where practical, any lead time and who may authorise extra cost.
Check the alternative before relying on it. A second courier that does not serve your postcode, a spare laptop without the required application or an account that still needs the absent owner’s approval is not operational resilience.

7. Customer and staff communication: how will updates travel?
Decide who communicates, which audiences need an update and what channels remain available. Prepare facts, not dramatic scripts. A sound incident update says:
- what service is affected;
- what customers can still do;
- what your team is doing now;
- when the next update will arrive;
- where urgent requests should go.
Keep one approved source of truth so the website, voicemail, email and staff responses do not contradict one another. Protect customer information when staff move to temporary tools or personal devices; urgency does not remove the need for sensible access control.
Telephone continuity deserves an explicit check because the main business number may be the route customers already trust. Record where calls go if the office or internet link fails, who can change routing, how voicemail is recovered and how callbacks are assigned. If mobile softphones use Session Initiation Protocol (SIP), also test registration, push notifications, caller identity, audio in both directions and access over mobile data rather than assuming that installing an app is enough.
8. Recovery and return: how do you leave incident mode?
Define who decides that normal service can resume. List checks for data reconciliation, outstanding customer promises, temporary access removal, supplier follow-up and any backlog created during the incident.
Recovery is not complete when the main system switches on. It is complete when temporary records have been entered, duplicate actions have been resolved, customers have received promised updates and emergency permissions have been withdrawn.
Give the plan three clocks
A single action list becomes confusing when an interruption lasts longer than expected. Add three time horizons so the team knows what changes.
The first 24 hours: stabilise and communicate
Focus on safety, leadership, essential outcomes and truthful updates. Use known workarounds, reduce the service promise to something achievable and start an incident log. Confirm which dependencies failed and which alternatives actually work.
Do not spend the first hour redesigning the business. Restore the smallest safe service, tell customers when they will hear from you again and protect the information needed for later reconciliation.
Days 2–7: make the temporary operation sustainable
Replace improvised fixes with controlled routines. Set staff rotas, replenish equipment, confirm supplier capacity and schedule customer updates. Review temporary data access and remove workarounds that create unacceptable security or quality risk.
This is also the point to contact customers whose work has been prioritised or delayed. Give a realistic revised commitment rather than repeating an optimistic daily promise.
Days 8–14: choose repair, relocation or redesign
A longer disruption may require different premises, replacement equipment, new supplier terms or a deliberately reduced service. Recalculate staffing, cash commitments and customer priorities using current information. Preserve the incident log so decisions can be reviewed after normal operations return.
These horizons are prompts, not guarantees. A cyber incident, fire or safety event may require specialist advice and a different sequence. Follow emergency services, official guidance and professional support where relevant.
See how the page works in a small-business scenario
Imagine a ten-person design and print company loses access to its premises after a burst pipe. The production equipment is unavailable, but staff are safe and cloud-based order records remain accessible.
Its one-page priorities might be:
- Within one hour: the deputy incident lead confirms staff availability, creates the incident log and routes urgent customer contacts to two trained employees.
- Within four hours: the account lead identifies orders due within 48 hours and contacts each customer with an update time.
- By the end of day one: the production manager confirms which jobs a pre-checked partner printer can accept and records revised costs and deadlines.
- During days 2–7: the team works remotely on design approvals, reconciles calls and emails into the order record, and sends one consistent daily update to affected customers.
- Before normal return: an authorised person checks temporary supplier files have been removed, order changes are recorded and every customer promise has an owner.
The scenario is useful because it exposes dependencies. If customer numbers only exist on an office computer, the cloud order record is not enough. If the partner printer has never run the required stock, it is only a possibility. If calls can be redirected but no one owns callbacks, routing has moved the problem rather than solved it.
Run a 30-minute exercise before you trust the plan
A tabletop exercise is a discussion-based rehearsal. It is safer and cheaper to discover a missing password, unavailable deputy or broken contact route during an exercise than during a real interruption.
Use three short rounds:
Minute 0–10: the internet connection fails
Assume the main connection will be unavailable until tomorrow. Ask the team to activate the plan, name the essential work affected and prove a fallback connection or manual route. Place a test customer call and send a test email. Check who sees each contact and how the next action is recorded.
Minute 10–20: the premises close
Now assume nobody can enter the building for three days. Identify the equipment, files and approvals that were still tied to the site. Have deputies open the systems they would need. Confirm how staff receive instructions if the normal collaboration platform is unavailable.
Minute 20–30: a key employee is absent
Remove the owner or the person who normally manages customer routing, supplier approval or system administration. Ask the deputy to make one realistic change. Do not accept “we would call them” as the fallback.
End by recording only four things:
- what failed;
- the owner of the fix;
- the deadline;
- the evidence required to close it.
An exercise is complete when the fixes are tested, not when the meeting ends. Repeat the failed step after changes are made.

Keep the page alive as the business changes
Review the page every quarter and after a major change in staff, premises, suppliers or technology. Keep the date and owner visible. Ask each deputy to confirm access rather than ticking a box on their behalf. Restore sample data, contact an alternative supplier and run at least one communication path.
The Federation of Small Businesses’ continuity guidance also emphasises a plan proportionate to critical processes. That principle helps prevent the document becoming so elaborate that a small team stops using it.
If your exercise shows that customer calls still depend on one office, device or administrator, test that dependency while normal service is available. A contained SessionCloud trial with a few users can help you verify managed softphone provisioning, SIP registration, mobile push, caller identity and callback ownership over an alternative connection. Keep it only if the test improves continuity and remains manageable for the team.
The strongest small-business continuity plan is not the longest. It is the one a deputy can activate, customers can experience as calm communication, and the team has proved under realistic pressure. Write the one-page control panel, test the weak points and improve it one verified fallback at a time.


