The RoadmapPlanningRisk Management and Contingency Planning

Building a Business Continuity Plan

A detailed, practical guide for UK small businesses to prepare, survive and recover from disruption.

6 minute read
Planning — Risk Management and Contingency Planning
✓ Verified against GOV.UK
Sarah Mitchell
Written by Sarah Mitchell
Editor-in-Chief · GuideToBusiness

Unexpected disruption can devastate a small business, from cyber attacks to floods, power cuts or a key supplier going bust. Yet most UK SMEs either lack a business continuity plan or have something too generic to be truly helpful in a crisis. This guide walks you, step by step, through building a robust, tailored business continuity plan—explaining what’s legally required, what’s best practice, and what’s essential for survival. By the end, you’ll know exactly how to protect your business, your people, and your reputation when the unexpected hits.

Why Business Continuity Planning Matters for UK Small Businesses

Business continuity planning isn’t just for big corporates or heavily regulated sectors. For UK small businesses, the risks of disruption—from ransomware attacks to power outages, severe weather, supply chain breakdowns, or staff absence—can be existential. According to the Federation of Small Businesses, over 40% of small firms experience a major disruption each year, and many never fully recover. Without a continuity plan, you’re relying on luck and reactive decision-making at the worst possible time.

A business continuity plan (BCP) is a practical document that details how your business will maintain essential functions during and after a crisis. Unlike emergency response (which is about immediate safety) or disaster recovery (focused on restoring IT), continuity planning covers the entire business—staff, premises, IT, suppliers, customers, and your brand. It helps you minimise downtime, control costs, and keep customers, regulators, and insurers onside.

If you have contracts with public sector organisations, financial services, or high-value clients, a BCP may be a contractual or regulatory requirement. Even if it’s not, insurers increasingly expect to see robust plans before offering cost-effective cover. From a reputational and risk perspective, having a BCP is now a badge of professionalism—demonstrating to stakeholders that you take responsibility seriously.

FSB Data

A 2023 Federation of Small Businesses report found that 43% of small businesses experienced significant disruption in the previous 12 months, with cyber incidents and extreme weather among the top causes.

Key Legal and Regulatory Drivers in the UK

While there’s no universal UK law mandating business continuity planning for all SMEs, several regulations and contracts require it either directly or indirectly. For example, firms working in the financial sector must comply with FCA and PRA rules on operational resilience. Businesses handling personal data need robust plans to comply with the UK GDPR and the Data Protection Act 2018, including protocols for data breaches and IT outages.

Health and safety law (the Health and Safety at Work Act 1974) requires you to plan for emergencies that could put people at risk. If you have employees, ACAS recommends you include continuity planning in your risk assessments. Certain sectors—like food, health, utilities, or those supplying government—may have specific continuity requirements in contracts or as part of supplier audits.

Insurers are increasingly focused on continuity planning. Many business interruption insurance policies now require evidence of continuity arrangements, and may reduce payouts or deny claims if you cannot show you took reasonable steps to mitigate foreseeable risks.

Contractual Traps

If you sign contracts with large clients, always check for clauses on business continuity, disaster recovery, or supply chain risk. Failing to meet these can result in penalties or lost business if you face disruption.

Identifying and Assessing Your Business Risks

Effective continuity planning starts with understanding what could go wrong in your specific business. This is not a tick-box exercise: risk profiles vary hugely between sectors, locations, and business models. You need to consider both common threats (like IT failure) and risks unique to your business (such as reliance on a single supplier or critical staff member).

Start by mapping your business’s critical functions—those activities without which you could not deliver your core product or service. Then identify potential threats to each function. The British Business Bank and the National Cyber Security Centre both recommend scenario planning: ask yourself what would happen if your premises flooded, your systems were hacked, or a key staff member was suddenly unavailable.

Quantify the likelihood and impact of each risk. The aim isn’t to plan for every possible event, but to focus on those most likely and most damaging. Use a risk matrix to prioritise. Remember, some risks (like cyber attacks or supplier insolvency) are increasing in frequency, while others (like terrorism or extreme weather) may be rare but catastrophic if they occur.

  • IT and communications failure (hardware, software, internet outages)
  • Physical threats (fire, flood, theft, vandalism)
  • Staff unavailability (illness, strikes, transport disruption)
  • Supply chain breakdown (supplier failure, delivery delays)
  • Data breaches and cyber attacks (malware, ransomware, phishing)
  • Utilities disruption (power, water, gas failures)
  • Reputational crises (bad publicity, social media incidents)
Risk Matrix Explained

A risk matrix scores each risk by the likelihood of it occurring and the severity of its impact. Focus first on risks that are both likely and have a high impact.

Building Your Business Continuity Team and Assigning Roles

A continuity plan is only as good as the people who implement it. You need a clear chain of command for crisis situations, with defined roles and responsibilities. For small businesses, this doesn’t mean creating new job titles, but you do need to decide who will lead the response, who will communicate with staff, customers, and suppliers, and who will handle specific tasks like IT recovery or liaising with insurers.

In many micro-businesses, the owner/founder will take on several roles. But you must have named deputies in case the primary contact is unavailable. You should also consider involving trusted advisers—like your accountant, HR consultant, or IT provider—in planning and response. Everyone in your business should know who to turn to in a crisis.

Responsibilities should be documented in your plan, with up-to-date contact details and alternates. This is especially important if you rely on part-time or remote staff, or if your business has high turnover. Don’t forget to review and update these assignments regularly—people move on, and roles change.

  • Appoint a continuity lead (usually the owner or MD)
  • Assign deputies for key roles (including communications)
  • Include IT, HR, finance, and operational contacts
  • List external contacts (insurers, landlords, key suppliers)
  • Keep contact lists up to date and accessible (paper and digital copies)
Deputy Cover is Critical

Always have at least one named deputy for each key continuity role, in case the primary contact is unavailable during a crisis.

Documenting Your Business Continuity Plan: What to Include

A business continuity plan should be a concise, practical document—not a lengthy policy gathering dust. The goal is to create a plan that staff can follow under pressure. It must be easy to access, simple to understand, and regularly updated. For most SMEs, 10-20 pages is typical, but the focus should be on quality, not quantity.

Essential sections include a statement of purpose, a summary of key risks, a contact directory, clear step-by-step procedures for different scenarios, and recovery checklists. Avoid jargon and keep instructions actionable. For regulated sectors, you may need to follow specific templates—check FCA, NHS, or government guidance where relevant.

Store your plan securely, but make sure it’s accessible even if your IT is down—printed copies in multiple locations and secure cloud access are best practice. Regularly test and update the plan, especially after any significant business change.

SectionWhat to Include
Purpose & ScopeWhat the plan covers, who it applies to, key objectives
Key RisksSummary of main threats (tailored to your business)
Continuity TeamNames, roles, up-to-date contact details, deputies
Incident Response ProceduresStep-by-step actions for each scenario
Communication PlanHow to contact staff, customers, suppliers, media
Recovery ChecklistActions to restore full operations, IT, data, premises
Review & TestingSchedule for drills, updates, and lessons learned

Step-by-Step: Building Your Business Continuity Plan

Creating an Effective Business Continuity Plan for Your Small Business

1
1. Map Your Critical Functions
List all the processes and activities essential to delivering your core product or service. Consider what you couldn’t do without, even for a day or two—this might include order processing, customer support, manufacturing, or fulfilling regulatory duties.
2
2. Identify and Prioritise Risks
For each critical function, brainstorm what could realistically disrupt it. Prioritise based on likelihood and potential impact, using a risk matrix. Focus your plan on the top risks rather than trying to cover every possible scenario.
3
3. Assign Roles and Gather Contacts
Appoint a continuity lead and deputies for each key role. Compile a contact directory, including staff, key suppliers, service providers, landlords, and emergency services. Make sure this list is regularly updated and accessible during a crisis.
4
4. Write Response Procedures
For each priority risk, set out clear, step-by-step actions to take if it happens. Include immediate response (e.g., evacuation, IT shut-down), communication steps, and incident management. Avoid jargon—make it easy for someone under stress to follow.
5
5. Plan for Recovery
Detail how you’ll restore operations, systems, and premises after the disruption. Include IT/data recovery, alternative work locations, and how you’ll inform customers and suppliers that you’re back up and running.
6
6. Store, Test and Review
Save your plan in secure digital and printed formats. Schedule regular reviews (at least annually or after major changes). Test your plan with scenario drills—update it based on lessons learned and changes in your business.

Managing IT, Data and Cyber Risks

For most UK small businesses, IT systems and data are now business-critical. A ransomware attack, server failure, or even a lost laptop can halt operations. The National Cyber Security Centre (NCSC) recommends that all SMEs include cyber threats in their continuity planning. This means not just having antivirus software, but preparing for what you’ll do if your systems are actually compromised.

Key actions include regular, secure data backups (ideally off-site or cloud-based), clear procedures for restoring systems, and knowing who to call for urgent IT support. You must also inform the Information Commissioner's Office (ICO) within 72 hours if a personal data breach occurs under UK GDPR rules. Document the steps staff should take if they suspect a breach—time is of the essence in limiting damage and regulatory exposure.

Don’t assume your IT provider has all the answers—many SMEs discover too late that their backups weren’t working or that their provider’s response times are slow. Make sure your plan includes a data recovery checklist and contact details for all IT vendors. Test restoring data from backup at least twice a year, not just assuming it will work.

Cyber ThreatContinuity Action
Ransomware AttackIsolate infected systems, restore from clean backup, notify ICO if data breach
Phishing/Email CompromiseChange passwords, check for unauthorised activity, alert customers if needed
Server/Cloud OutageSwitch to backup systems, communicate with provider, update customers
Lost DeviceRemotely wipe data, change access credentials, notify ICO if data lost
  • Back up critical business data daily, using at least one off-site/cloud method
  • Document who is responsible for IT recovery and how to reach them 24/7
  • Provide staff training on cyber risks and how to report incidents
  • Test your backup and recovery process at least twice a year
  • Ensure your cyber insurance is up to date and covers likely risks
72-Hour Rule

Under UK GDPR, you must report personal data breaches to the ICO within 72 hours. Failing to do so can result in significant fines.

Planning for People: Staff, Safety and Communication

People are at the heart of every small business, and disruption often hits staff hardest. Your continuity plan must address staff safety, welfare, and clear communication. Under the Health and Safety at Work Act 1974, you are legally required to plan for emergencies—this includes evacuation procedures, assembly points, and first aid provision. Review your plans with input from staff and, if you have five or more employees, record your emergency arrangements in writing.

Communication is critical in a crisis. Make sure you have up-to-date contact details for every employee, including emergency contacts. Decide in advance how you’ll communicate if normal channels are down—consider SMS alerts, WhatsApp groups, or an emergency phone tree. If you have remote staff, set expectations about how and when they should check in during a disruption.

Your plan should also cover staff absence. What if a key person is off sick, stranded by transport disruption, or unable to access IT? Identify critical roles and develop simple handover notes or cross-skilling, so someone else can step in if needed. ACAS provides templates for emergency absence policies and communication plans.

  • Maintain a confidential, regularly updated staff contact list
  • Agree emergency communication channels and test them annually
  • Develop handover notes for critical roles (even if brief)
  • Review fire/evacuation plans and ensure all staff know their responsibilities
  • Plan for staff support (e.g., Employee Assistance Programmes) after a major incident
Remote Work Considerations

If remote work is part of your continuity strategy, ensure staff have secure access to systems and are trained in remote working protocols.

Supply Chain and Third-Party Risks

For most UK small businesses, supply chain disruption is a growing risk. Brexit, Covid-19 and the Ukraine conflict have all exposed the fragility of global and domestic supply lines. Your continuity plan must address what happens if a key supplier fails, deliveries are delayed, or essential services (like couriers, IT providers, or utilities) are disrupted.

Start by identifying your most critical suppliers—those whose failure would halt your business. Check their own continuity arrangements (many UK public sector contracts now require suppliers to provide evidence of BCPs). Where possible, have alternative suppliers on file or agree contingency arrangements in advance. Don’t forget to consider single points of failure: if your business relies on one person or provider, you are especially vulnerable.

Document how you will communicate with suppliers in a crisis, including alternative contacts and escalation paths. Build flexibility into contracts where you can (such as alternative delivery options or service credits for disruption). Keep records of your business-critical supplier contacts both digitally and in print.

Supplier TypeContinuity Action
Product SupplierIdentify backups, maintain emergency stock, monitor financial health
IT/Cloud ProviderCheck SLAs, have local backups, know escalation contacts
Courier/LogisticsHave alternative couriers, inform customers of delays
UtilitiesKnow emergency contacts, plan for temporary outages
  • List all business-critical suppliers and their key contacts
  • Request a copy of major suppliers’ continuity plans (where practical)
  • Identify backup suppliers for essential goods and services
  • Monitor supplier health (news, financials, delivery performance)
  • Include supplier communication in your incident response procedures

Testing, Maintaining and Improving Your Plan

A business continuity plan is only useful if it works in practice. Too many UK SMEs write a plan and then file it away, never testing whether it actually helps in a crisis. Best practice—recommended by the British Standards Institution (BSI) and the UK Government—is to test your plan at least annually, and after any major business change (merger, new premises, IT overhaul, etc.).

Testing can be as simple as a desktop walkthrough: gather your team and simulate a disruption, working through your plan step by step. For higher-risk businesses, consider live drills (e.g., fire evacuations, IT failovers). After each test, debrief on what worked, what didn’t, and update your plan accordingly. Involve new starters and deputies, so everyone is familiar with their roles.

Don’t forget to review and update contact lists, supplier details, and procedures regularly—at least every six months, or immediately after any significant business change. Keep a log of all revisions, tests and lessons learned, as this is often requested by insurers and major clients.

  • Schedule at least one continuity test or drill per year
  • After each test, hold a debrief and update your plan
  • Log all plan updates, tests, and lessons learned
  • Review plan after major business changes (new IT, staff, premises)
  • Circulate updates to all staff and relevant suppliers
Keep It Simple

A concise, well-practised plan is far more effective than a long, unread manual. Focus on clear instructions and up-to-date contacts.

Common Mistakes and How to Avoid Them

Even the best-intentioned small businesses can fall into traps when building their continuity plan. One of the most frequent mistakes is creating a plan that’s too generic—using a template without tailoring it to your actual operations. This results in a document that looks good on paper but is useless in a real crisis. Make your plan business-specific: use real names, locations, suppliers, and processes.

Another common error is forgetting to test or update the plan. Staff leave, suppliers change, new risks (such as cyber threats) emerge. A plan written two years ago is unlikely to reflect your current reality. Build regular reviews and testing into your calendar—tie this to other business processes, like annual insurance renewals or staff training.

Many SMEs also overlook communication—both internal and external. In a crisis, confusion and silence can make disruption worse. Plan in advance how you’ll communicate with staff, customers, and the media. Prepare holding statements for likely scenarios (e.g., IT outage, delivery delay) so you’re not caught on the back foot.

  • Don’t rely solely on digital copies—have at least one printed plan
  • Avoid single points of failure (one person, supplier, or system)
  • Tailor the plan to your actual business, not just a template
  • Test procedures, not just policy—walk through real scenarios
  • Keep plans and contacts up to date, not just annually
Insurance Gaps

Some business interruption policies require evidence of continuity planning. Failing to keep your plan up to date could invalidate your cover.

Templates, Tools, and Further Resources

Several UK organisations offer free or low-cost resources to help SMEs build and maintain business continuity plans. The Federation of Small Businesses provides members with sample templates and checklists. The British Business Bank’s website has a simple BCP tool, while the National Cyber Security Centre offers a cyber incident response template.

For regulated sectors or those with complex needs, the British Standards Institution (BSI) publishes BS EN ISO 22301:2019, the international standard for business continuity management. While certification is usually only relevant for larger firms, the standard’s principles are a solid starting point for any SME. ACAS, the Health and Safety Executive, and GOV.UK also provide sector-specific advice and templates.

If you need outside help, many local authorities, enterprise agencies, and insurance brokers can connect you with continuity planning consultants. Make sure any advisor understands the realities of UK SME life—avoid over-engineered, costly plans that don’t fit your business.

ResourceProviderAccess
Business Continuity Planning GuideFederation of Small BusinessesFSB Members Area
SME BCP TemplateBritish Business BankFree Online
Cyber Incident Response PlanNational Cyber Security CentreFree Online
Continuity Policy TemplatesACASFree Online
Risk Assessment ToolsHealth and Safety ExecutiveFree Online
Key Takeaways
  • Continuity planning is essential for UK SMEs. Disruption is common and can threaten survival if you don’t plan ahead.
  • Tailor your plan to your business. Use your own risks, contacts, and processes—not a generic template.
  • Focus on practical, actionable steps. Clear instructions and up-to-date contact lists are more valuable than policy statements.
  • Test and update your plan regularly. Set reminders for reviews and drills, and update after any major business change.
  • Include IT, suppliers, and people in your plan. Cover cyber threats, supply chain risks, and staff absence, not just premises or fire.
  • Know your legal and insurance obligations. Some contracts and insurers require evidence of up-to-date continuity planning.
  • Communication is critical. Plan how you’ll reach staff, customers, and suppliers in a crisis, and prepare holding statements.
  • Use UK resources and guidance. Tap into support from FSB, British Business Bank, NCSC, and sector bodies for templates and advice.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.