Business Continuity Plan for Small Businesses (+ Template)

A business continuity plan is a documented plan for keeping your essential operations running — or getting them back quickly — when something disrupts the business. That could be a power cut, a burst pipe, a ransomware attack, a supplier failing, or a key person being unavailable. For a small business it does not need to be a 40-page binder; it needs to be a few clear pages that the right people can act on.

This guide walks through how to build one, with a template outline you can copy at the end.

Continuity, disaster recovery and incident response

  • Business continuity plan (BCP) — keeps the whole business functioning: people, premises, processes, suppliers, customers
  • Disaster recovery plan (DRP) — the IT subset: restoring systems and data
  • Incident response plan — the immediate steps during a specific event, especially a security incident

They overlap. The continuity plan is the umbrella; the other two plug into it.

Why small businesses skip it — and why that is a mistake

It feels like corporate overhead, and nothing has gone badly wrong yet. But small businesses are less able to absorb a week of downtime than large ones, and the disruptions that cause it — ransomware, a failed server, a flooded office — are common. A few hours spent planning turns a crisis into an inconvenience.

Step 1: Business impact analysis

List what your business actually does, then work out which functions are critical and how long each could stop before it seriously hurts.

  • Identify your core functions (taking orders, delivering the service, invoicing, paying staff, customer support)
  • For each, estimate the maximum tolerable downtime — hours, a day, a week?
  • Note what each function depends on — specific staff, systems, data, premises, suppliers, internet
  • Rank them, so recovery effort goes to what matters first

Step 2: Risk assessment

You are not trying to predict everything — just the disruptions that are plausible and would hurt.

  • Power or internet outage
  • Building inaccessible — fire, flood, gas leak, weather
  • Cyberattack or ransomware locking your systems
  • Hardware failure — server, NAS, key workstation
  • Loss of a key person for an extended period
  • A critical supplier or software vendor failing

Step 3: Recovery strategies

For each critical function, decide how you would keep it going or restore it:

  • Work from elsewhere — staff laptops, cloud systems and a tested remote-access setup mean a lost office is not a lost business
  • Manual workarounds — how you take orders or record sales on paper for a few hours
  • Alternate suppliers — a second option identified before you need it
  • IT recovery — covered by your disaster recovery plan, built on 3-2-1 backups and clear RTO and RPO targets
  • Cross-training — more than one person can do each critical task

Step 4: Write the plan

Keep it to a document people can follow under stress. It should contain:

  • Roles — who leads, who talks to staff, who talks to customers, who handles IT
  • A contact tree — staff, key suppliers, insurer, bank, IT provider, landlord — kept current and stored where you can reach it if the network is down
  • A short procedure for each of your top disruptions
  • Where backups are, how to invoke IT recovery, and the recovery targets
  • How and where the team assembles (physically or a video call) if the office is gone

Step 5: Test and maintain

  • Run a tabletop exercise once a year — talk through a scenario with the people named in the plan
  • Actually test the parts you can — a backup restore, remote access, the phone divert
  • Review after any change to staff, premises, systems or suppliers
  • Fix what the test exposed — that is the point of testing

Template outline (copy this)

  1. Purpose and scope — one paragraph
  2. Critical functions — table: function, max tolerable downtime, dependencies
  3. Key risks — the handful you are planning for
  4. Roles and responsibilities — named people and deputies
  5. Contact list — staff, suppliers, insurer, bank, IT, landlord, utilities
  6. Response procedures — one short section per top risk
  7. IT recovery — reference to the disaster recovery plan, backup locations, RTO/RPO
  8. Communications — how you tell staff and customers, holding statements
  9. Return to normal — how you stand down and review
  10. Test log and revision history

Common mistakes

  • Writing it once and never testing it
  • Storing the only copy on the server it is meant to help you recover
  • Naming one person for everything — who covers their role?
  • Ignoring suppliers and utilities and focusing only on IT
  • Making it so long nobody reads it

When to get help

If you have a server, staff who cannot work when systems are down, or compliance obligations, it is worth having someone run the IT side properly. We build the disaster recovery plan, backups and testing as part of our managed IT support.

Want the IT side of your continuity plan sorted? See our backup and disaster recovery service or talk to our Edmonton team.

Frequently asked questions

What is a business continuity plan?

A documented plan for keeping your essential business functions running, or restoring them quickly, when something disrupts normal operations – an outage, a fire, a cyberattack, the loss of a key supplier or person. It covers the whole business, not just IT.

What is the difference between a business continuity plan and a disaster recovery plan?

The continuity plan covers keeping the business operating overall. The disaster recovery plan is the IT-focused subset – how systems and data are restored. The DR plan supports the continuity plan.

How long should a small business continuity plan be?

Short enough that people will actually use it. For most small businesses that is a handful of pages: critical functions, who does what, contact details, and a clear procedure for the few most likely disruptions.

How often should we test and update it?

Review it at least once a year and after any significant change to staff, systems, premises or suppliers. Run a short tabletop walkthrough annually so the people named in it know their roles.