24/7 Support Available
Skip to main content
Intermediate
4 to 8 weeks

Business Continuity Planning

How to build a continuity plan that holds up during a cyber incident: work out what the business cannot do without, set honest recovery targets, write the plan down, and test it before you need it.

Prerequisites

  • Input from every part of the business, since each team knows what it cannot work without.
  • A list of your critical systems, suppliers and the data each process depends on.
  • Senior ownership, because continuity decisions involve real trade offs about cost and risk.
  • A willingness to test the plan for real, not just file it and hope.

Step-by-Step Instructions

Run a business impact analysis

Start by working out what really matters. For each business process, ask what the impact would be if it stopped, and how that impact grows with every hour and day of downtime. This analysis tells you which systems to recover first, so your effort during an incident goes where it protects the business most.

Set recovery targets you can defend

For each critical process, agree two numbers. The recovery time objective is how quickly it must be back, and the recovery point objective is how much data you can afford to lose, measured in time. These targets shape your backup schedule and your investment, so be honest. A one hour target needs very different arrangements from a one day target.

Tip

Test your targets against reality. Plenty of organisations set a four hour recovery goal, then discover a full restore actually takes two days. It is far better to learn that in a rehearsal than during a live incident.

Get your backups right

Backups are the backbone of recovery, so follow the 3-2-1 approach: three copies of your data, on two different types of media, with one kept offline or otherwise beyond the reach of an attacker. Ransomware deliberately seeks out and encrypts connected backups, so an isolated copy is what lets you recover without paying.

Write the plan for a bad day

Document the plan so a stressed person can follow it. Include who does what, how you will communicate if email and phones are down, the order in which systems come back, and the contact details for key staff and suppliers. Keep a copy offline and off site, because a plan trapped on an encrypted server is no plan at all.

Plan how you will communicate

During an incident, people need to know what is happening: staff, customers, suppliers, and sometimes regulators. Decide in advance who speaks for the organisation, through which channels, and roughly what you will say. Clear, calm communication protects trust, while silence and mixed messages do lasting damage.

Test, review and keep it current

A plan you have never tested is a guess. Run through realistic scenarios at least once a year, from a tabletop discussion to a full recovery rehearsal, and fix what you find. Review the plan whenever the business changes, because staff, suppliers and systems move on, and an out of date plan can be worse than none.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our strategic security advisory team is here to help. Talk to us about your requirements.