Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Business continuity resources»Business continuity resources for smaller businesses: part one (Page 9)
Business continuity resources

Business continuity resources for smaller businesses: part one

Business continuity resources for smaller businesses are quite limited in the global business continuity knowledge base. In the first of three articles seeking to help address this gap, Steve Dance provides a simple guide to the building blocks of a business continuity plan.
May 9, 20256 Mins Read
business continuity planning concept - a number of interconnected cogs on a bright blue background.

There is a huge volume of information on the topic of business continuity – although much of it ignores the needs of smaller businesses (SMEs / SMBs); which then results in a lack of engagement. There are, in my opinion, three main issues for this, related to the source and intent of available content:

  1. A considerable amount of business continuity content is written by specialists FOR specialists: it’s full of jargon and often assumes that dedicated resources are available to develop and subsequently drive business continuity plan principles throughout an organization. In an SME environment, the person responsible for leading business continuity also has a ‘day job’ and hence limited time available.
  2. Service providers and consultants also generate a significant proportion of business continuity content. Their content, however, is often focussed on selling and promoting their services which, again, are often aimed at BCP specialists.
  3. The proliferation of fear, uncertainty, and doubt (FUD) content which is designed to prompt the reader into action. This type of content is particularly unhelpful, it promises dire consequences, imparting little in the way of actionable know-how.

All this combines to create a significant lack of relevance to the SME. SMEs need practical, jargon free advice which recognises that resources are limited. Three factors could significantly help here:

  1. A plain, jargon free guide to the components of a business continuity plan,
  2. A framework to structure the activities of business continuity plan development and maintenance (aka a business continuity plan template),
  3. Some practical ‘how to’ guidance on capturing relevant BCP content and on deploying and maintaining the plan.

Over a three-article series about practical approaches to business continuity planning for SMEs, I will address each of the three points above. In this article I’ll attempt point 1 – a jargon free guide to the components or building blocks of a business continuity plan:

1: Establishing scope and priorities

Establishing scope and priorities is often referred to as a ‘business impact analysis’ or a ‘business impact assessment’. Either way it gets shortened to BIA. It is intended to create an understanding of the things in your organization that support its operational capability and the overall consequences of malfunction or failure. It starts with some basic questions about key interaction points with customers, clients, or the public.  In an SME this could be: “What is it we get paid for?” For non-profit organizations this could be, “How do we support our beneficiaries?” For public sector bodies it could be “How do we make sure we maintain essential services to the public?”

A good perspective is to consider the external recipients of your products and services and how they acquire and receive them. This is the first step in understanding the specific activities within the organization’s operations that a business continuity plan should focus on. The next step is to consider the consequences of these points of interaction becoming inoperable or significantly impaired for an extended period. Are there, for instance, exposures related to goodwill & reputation, contractual obligations, statutory & regulatory liabilities , safety & well-being or public health ? Consider also how long this inoperability or impairment could be tolerated – establishing this tolerance to disruption sets the target threshold for operational recovery.   

The scope and priorities stage described above incorporates activities often referred to as ‘impact assessment’, ‘risk assessment’ & ‘dependency analysis’; or more generally the ‘BIA’. In essence it’s about determining what operations are critical to your organization and the capabilities required to support them.

2: Establish intrinsic capability

The next step is an assessment of whether the organization has the basic capabilities needed for the key interaction points identified in the scope and priorities step to continue to operate during an incident or crisis. Consideration is given to the existing infrastructure of the organization:

  • Do you have workplace backup facilities (physical or remote)?
  • Can your IT systems be recovered quickly?
  • Is essential equipment replaceable within a reasonable timeframe?

When this baseline is established, the organization will then have a clear foundation on which to build an effective business continuity plan or, alternatively, will be clear about where additional resources need to be established.

This stage is critical – if the intrinsic capabilities within the organization are inadequate any subsequent planning activities will be compromised unless the deficiencies are addressed.

3: Develop response and recovery plans

Now it’s time to turn your analysis into action. Work with the people and teams that manage your core operations to develop clear, concise, procedures for responding to disruptions.

The structure of an operational recovery plan should be as simple as possible, designed for ease of use, in a tabular rather than narrative format and should accommodate the following information:

  • Leadership team members, including their roles and contact details.
  • How the team will communicate during a recovery (tools, platforms, access).
  • Key internal and external contacts.
  • Specific consideration for actions taken under different incident scenarios, including:
    • Loss of workplace or inaccessibility to this.
    • IT systems failure.

Response and recovery plans must be designed to be straightforward, concise and, above all easy to action in pressurised situations.

4: Communications framework

During a major incident any organization will need to have a robust approach to both external and internal communications.

The communications framework defines how the whole organization will communicate during the response and recovery stages of an incident. Communications is often the ‘make or break’ part of incident management and recovery, being the ‘glue’ that holds recovery activities together; it will also be how the organization’s handling of an incident is perceived and judged by external parties.

The communications framework defines how the organization will communicate with interested and involved parties, what channels will be used for communications, and who will operate or ‘own’ those channels. 

5: Business continuity management framework

This aspect of business continuity planning establishes a management structure and responsibilities for ensuring the ongoing relevance and integrity of an organization’s business continuity arrangements and for performing the scheduled assurance activities. These activities will include:

  • Periodically reconfirming the understanding of business priorities and tolerances, ensuring that scope and priorities remain relevant.
  • Ensuring capabilities and available resources remain in line with recovery needs. This may include IT failover and recovery tests to ensure that IT systems can be recovered within the required timeframes.
  • Confirming that functional and departmental plans remain relevant and fit for purpose. 

The above five areas are the essential building blocks of a business continuity plan for any organization. Applying them will ensure that a SME has a robust plan to protect itself from disruptive events as well as providing confirmation to third parties that a comprehensive and managed business continuity plan and associated processes are in place.

The author

Steve Dance is founder of RiskCentric. RiskCentric provides templates to make business continuity planning easier for SMEs

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleBoardroom lingo: how CISOs can translate cyber technicalities into a language that the board can understand
Next Article Anti-Ransomware Day: promoting  best practices for prevention and response

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
AI implementation concept

Why AI is forcing a rethink of enterprise resilience

June 18, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?