
A business continuity plan sets out how a company keeps trading while its systems are being restored. Backups sit inside that plan and cover one part of it, which is getting the data back. Government figures show how far apart those two things sit in practice. Overall, 74% of UK businesses back up data securely via a cloud service. However, only 44% of small businesses have a continuity plan that addresses cyber security, down from 53% the year before. In comparison, just 25% of UK businesses have a formal incident response plan.
Most businesses can recover their files. Far fewer know who makes the first decision, who calls the insurer, or where staff work on the afternoon the office is inaccessible.
Backup, disaster recovery and business continuity: three layers, three questions
A business continuity plan sits at the top of three nested layers, and each layer answers a different question.
Backup is copies of data held somewhere the primary system cannot reach. It answers: can we get the data back?
Disaster recovery is the technical sequence for restoring systems after an event, covering servers, services and integrations in order. It answers: can we get the systems working again?
Business continuity is the operational plan that keeps the business trading through the event, covering people, communications, work locations, fallback processes and the decisions someone makes in the first hour. It answers: can we keep operating while the IT is being fixed?
Backups sit inside disaster recovery, and disaster recovery sits inside continuity. A business can hold excellent backups and still fail on continuity, because nobody wrote down who does what at 9am. Our guide to disaster recovery versus business continuity covers the distinction in more depth, and Retention Is Not Backup covers the trap one layer below.
Why continuity planning slipped while attacks fell
The Cyber Security Breaches Survey 2025/2026, published by government in April 2026, records ransomware incidence among businesses falling to 1%, down from 3% in the previous two years. Over the same period, the proportion of small businesses holding a continuity plan that addresses cyber security fell from 53% to 44%.
Attention followed the threat statistics downwards. The exposure did not, because continuity planning covers considerably more than ransomware. Connectivity failures, cloud outages, key-person absence and physical incidents all produce the same problem: a business that cannot trade for a period, with nobody holding a written sequence for what happens next.
The other figure worth sitting with is the 25% who hold a formal incident response plan. Three quarters of UK businesses would be improvising in the first hour.
The five failure scenarios every business continuity plan needs to cover
A working plan covers the scenarios that account for most UK SME disruption. Five is enough.
Ransomware. Files encrypted, systems locked, a demand attached. Incidence is falling, and impact when it lands remains total.
Cloud outage. Microsoft 365, Google Workspace or a critical platform goes down and everything depending on it goes with it. Infrequent, and entirely outside your control when it happens.
Connectivity failure. The primary line drops and every cloud service becomes unreachable. Usual causes are an Openreach fault, an upstream incident, or a cable dig.
Key-person absence. The MD is unreachable, the office manager holds the only copy of the contact list and is off sick, the IT partner is away. Single points of failure around named people are the cheapest to fix and the most frequently missed.
Physical incident. Fire, flood, break-in, extended utility failure. Low probability, total impact, and the scenario that needs a location plan more than a technical one.
Working out what downtime costs you
First, put a figure on the potential cost before deciding how much cover to buy. Next, take your monthly payroll and divide it by the working hours in the month to calculate an hourly staff cost. Then, multiply that figure by the number of hours affected and the proportion of staff who would be unable to work. Add anything time-critical: missed client deadlines, delayed invoicing, penalty clauses.
The output tends to surprise people, and it makes the rest of the plan easier to justify internally.
What a working one-page business continuity plan contains
A plan for a 20 to 50 person business fits on a single page. The ten items below are what an insurer or a client auditor looks for, and our one-page continuity plan template sets them out as a document you can complete in an afternoon.
- Named incident commander and named deputy. One person decides. One person steps in when the first is unavailable.
- Escalation tree. Who calls whom, in what order, inside fifteen minutes. Names and personal mobile numbers.
- An offline copy of the plan. Printed, held by the commander and the deputy, readable without power or internet. A plan available only on the SharePoint you cannot reach fails at the moment you need it.
- A backup restore tested this quarter. Documented, dated, with evidence of a completed test. Insurers ask for this one specifically.
- Communication templates for staff, customers and suppliers, written in advance.
- A fallback communications channel. A WhatsApp group, alternative addresses, mobile numbers. Something that works while Microsoft 365 does not.
- An alternative work location. Coworking space, a triggered home-working policy, or a partner office.
- Insurance broker contact and policy number on the plan itself, alongside everything else, where someone can read it under pressure.
- Agreed cover for short-term costs while a claim is processed.
- A quarterly test cadence. Plans that have never been run have gaps that only appear under pressure.
Item 4 is the one most businesses cannot complete on their own, and it is worth separating from the other nine for that reason. Writing the plan is a ninety-minute meeting. Producing dated evidence that a restore worked requires access to the systems, which means it requires whoever administers them.
Ransomware at 9am on a Tuesday: what the first four hours look like
A 30-person accountancy practice in Newcastle. Tuesday, 09:12, staff begin reporting that files will not open and a ransom note is on screen.
Inside fifteen minutes. Incident commander declared. Endpoints isolated from the network, by the managed detection platform or the IT partner. Escalation tree activated. Insurance broker notified. Staff told on the fallback channel to stop using systems.
Inside one hour. Scope established: which systems are affected, which backups are needed. IT partner connected or on site. A communication template goes to clients acknowledging a technical issue and giving a time for the next update. NCSC’s incident management guidance sets out that an incident response plan should link to disaster recovery and business continuity plans, which is what makes the next two steps possible.
Inside four hours. A clean backup identified and a restore started on isolated infrastructure. Fallback processes running for time-critical client work: documents held locally, invoices raised manually where needed.
Inside twenty-four hours. Core systems restored on cleaned infrastructure. Clients updated with a revised timeline. Claim lodged with initial evidence attached.
First, every step in that sequence is procedural. As a result, a business with a plan can spend the first four hours working through it. By contrast, a business without one may spend those same hours deciding what to do, which is often where the real cost begins. In addition, our guide to ransomware defences that reduce downtime explains the technical protections that sit underneath your wider strategy. Finally, our cyber incident response plan for SMEs sets out the response sequence in more detail.
What UK cyber insurers ask to see at renewal
Underwriting tightened between 2023 and 2026, and renewal questions moved from policy statements towards documented evidence.
The list below reflects what we see UK insurers commonly request at renewal, drawn from our own client work.
- A documented continuity plan with a named commander, tested inside the last twelve months
- A tested backup restore with dated evidence
- A communication tree covering the first twenty-four hours
- Recovery time and recovery point objectives defined per system class
- An incident response plan with a sequence and named responders
- Cyber Essentials or an equivalent baseline of controls
Businesses that cannot supply the evidence tend to see a higher premium, a lower limit, or an exclusion. Our guide to cyber insurance renewal in 2026 lists the full pack worth assembling before the call.
Six ways SME continuity plans fail
- The plan was written and never tested. Gaps stay hidden until pressure finds them.
- The plan lives in the system that goes down. A SharePoint-only plan is unreachable during a Microsoft 365 outage.
- Nobody knows where it is, or the only person who knew has left.
- Customers hear nothing. Staff know the drill and clients sit in silence for six hours.
- The commander has no deputy. One name is a single point of failure.
- Backup evidence gets submitted as continuity evidence. ‘We back up daily’ answers a different question from the one being asked.
Where to start
Continuity planning divides into two halves. Writing the plan is a ninety-minute meeting with the right people in the room, and the one-page template will get you a working version the same afternoon. That half you can do yourself.
The other half is evidence. A dated, documented test restore is the item insurers ask for specifically, and it needs someone with access to your systems to produce it.
Ask your IT partner what evidence they can produce for a documented restore, and how often it runs.
If your renewal or a client audit is coming up, we can run a test restore, document it, and show you what your current setup would survive. Review your business continuity and disaster recovery cover, or start with the one-page templateif you would rather draft it first.
Related reading
If certification is the trigger for this work, our guide to how to get Cyber Essentials certified.
For the wider case for outsourced IT support, see why UK SMEs use an MSP.
