TL;DR: Most businesses only think about business continuity once something’s already gone wrong. This guide walks you through building a plan from scratch, in plain English, before that happens.
If your business has never had a business continuity plan, you’re in good company. Plenty of well-run Birmingham businesses have never written one down. Many small businesses have either never had the time to create a plan or have assumed that only larger organisations require one.
The truth is, it’s usually the smaller business that gets hit hardest by disruption, because there’s no backup system or spare laptop and no one else who knows how to process payroll.
A business continuity plan doesn’t need to be complicated. It needs to exist and be something your team could actually follow if the day came. This guide takes you through the steps to build one from scratch.
Start With What Your Business Can’t Function Without
Before you think about risks or recovery times, you need a clear picture of what keeps your business running day to day. This is the foundation everything else sits on, and it’s easy to get wrong by assuming “everything” is critical, which helps no one when you’re trying to prioritise.
Walk through a typical week and ask what would stop you serving customers or paying staff if it disappeared tomorrow. For most Birmingham SMEs, this list includes:
- The systems you use to take and process orders or bookings
- Access to customer and financial data
- Email and phone communication with clients
- Your website, if it drives enquiries or sales
- Payroll and any time-critical supplier payments
Rank these by how quickly their absence would cause real damage, not just inconvenience.
Mapping Your Risks
With your critical systems identified, the next step is working out what could realistically knock them offline. Skip the exotic scenarios and focus on the threats that actually affect businesses like yours:
- Power Outages: Even a few hours can halt tills, phones, and servers.
- Internet or Broadband Failure: Cloud-based systems are only as reliable as your connection.
- Ransomware and Cyber-Attacks: Often the most disruptive and the hardest to recover from without preparation.
- Staff Illness or Unavailability: What happens if the one person who knows your invoicing system is off for two weeks?
- Supplier Failure: If a key supplier can’t deliver, can you still operate?
For each risk, note how likely it is and how badly it would hurt if it happened. A simple high, medium, or low against each risk is enough to show you where to focus first.
Setting Your Recovery Targets
This is the part that trips most first-timers up, mainly because of the acronyms. Two terms matter here: RTO and RPO.
- RTO (Recovery Time Objective) is how quickly you need a system or process back up before the disruption becomes seriously damaging. If your booking system goes down, could you cope for four hours? A day? Longer than that and you start losing customers.
- RPO (Recovery Point Objective) is how much data you can afford to lose. If your last backup ran at midnight and your system crashes at 4pm the next day, you’d lose everything entered since midnight the previous day. Is that acceptable, or does it need to be closer to real time?
For instance, a Birmingham accountancy firm handling client payroll might set an RTO of four hours for its payroll system (clients need paying on time) and an RPO of one hour (they can’t afford to redo a full day’s data entry).
Meanwhile, a local retailer might set a longer RTO for its website but a tighter RPO for sales data feeding into stock management.
There’s no universal answer. The point is deciding these numbers in advance, rather than guessing under pressure during an actual incident.
Building the Plan Document
Once you know what’s critical, what threatens it, and how fast you need to recover, it’s time to put this into an actual document. At minimum, your document should cover:
- Who does what. Name specific people, not job titles alone, and give each person a backup in case they’re unavailable.
- The order of actions. What gets done first, second, and third when an incident is declared? Who makes the call to activate the plan?
- Contact details for staff, key suppliers, your IT provider, and insurers, kept somewhere accessible even if your main systems are down.
- Where backups and access credentials are stored, and who can get to them.
- How you’ll communicate with customers if there’s a visible disruption to service.
Print a copy. Store it somewhere that doesn’t rely on the very systems it’s meant to help you recover.
Keeping It Alive
A continuity plan written once and filed away is barely better than no plan at all. A plan that reflected your business two years ago might now point to the wrong contact for the wrong supplier using a system you’ve since replaced.
Government figures released in 2026 show how quickly this can happen. The Cyber Security Breaches Survey 2025/2026 found that only 44% of small businesses now have a business continuity plan covering cyber security, down from 53% the year before.
That’s a significant drop in a single year, among businesses that had previously been making progress.
Build a review into your calendar, ideally every six months, and definitely whenever something significant changes. Testing matters too. Run through the plan with your team at least once a year so people know their role before they need it for real.
How MT Services Can Help
MT Services has been supporting businesses across Birmingham and the wider Midlands since 1973, from our base in Tamworth.
That’s given us a strong view of what actually happens when things go wrong for a local business, and what separates the ones that recover quickly from the ones that don’t.
Building a continuity plan from scratch takes time most business owners don’t have spare, and it’s easy to miss gaps when you’re too close to your own operation.
That’s where a second pair of eyes helps, particularly on the IT side: backups, recovery times, and the technical detail behind your RTOs and RPOs.
FAQs
- What’s the difference between a business continuity plan and a disaster recovery plan?
A business continuity plan covers how your whole organisation keeps operating during disruption, including people, processes, and communication. A disaster recovery plan is more specific, focused on restoring IT systems and data. Knowing how to create a disaster recovery plan is usually one part of a wider continuity plan, not a standalone substitute for it. - What are the first business continuity steps for a small business?
Start by identifying which systems and processes you can’t operate without, then map the realistic risks to those systems. Everything else builds on that foundation. - Do I need specialist software to follow an IT continuity planning guide?
Most small businesses can build a solid plan using a shared document and a clear list of contacts and priorities. Software becomes more useful once you’re managing complex backups or want automated testing, but it’s not a barrier to getting started. - How often should I update my business continuity plan?
Review it at least every six months, and immediately after any significant change to staff, suppliers, or systems. A plan that isn’t reviewed regularly tends to fall out of date faster than most business owners expect.
Ready to Put a Plan in Place?
If you’re ready to build a continuity plan but aren’t sure where to start, get in touch with our team for a free, no-obligation continuity planning session.