Most continuity plans fail the same way: they're 40 pages, written for an auditor, stored on the server that just went down. A useful plan is five pages, written for a stressed-out human, and printed. Here's the five-page version we build, section by section.
Page one: the contact tree
Who calls whom, in what order, with actual phone numbers. Owner, key staff, IT provider, insurance agent, landlord, key vendors, and the bank. Include after-hours numbers, because outages read calendars and pick weekends. This page alone earns the plan's keep: in a real incident, half the first hour is normally spent hunting for phone numbers.
Page two: the systems list, in priority order
Every system that matters, ranked by how fast you need it back. The ranking is the important part, because recovery is a queue, and arguing about the queue during the outage is how you lose a day. A typical ranking:
- First hour: phones and email, because they're how you coordinate everything else.
- Same day: the system that takes money (POS, invoicing, the booking system).
- Day two: the operational apps: files, accounting, project tools.
- This week: everything else, honestly including the thing the loudest person insists is critical.
For each system: where it runs, where backups are, who can restore it, and the vendor support number.
Page three: workarounds
How you operate while systems are down. Card reader down: the paper form and the phone-a-payment number. Email down: the group text. File server down: the deal-with-it-later folder that someone reconciles after. Workarounds feel obvious in a meeting and are impossible to invent mid-crisis. Write them down.
Page four: the recovery details
Where backups physically and digitally live, credentials location (the password manager, plus emergency access instructions), RTO and RPO expectations per system so nobody expects magic, and the decision points: at what hour of outage do you activate the backup office plan, notify clients, or engage the insurer. If ransomware is on your risk list, and it is, cross-reference the decisions to make before the bad day and the sequence in the first 24 hours after a breach.
Page five: after
The after-action habit: what happened, what worked, what didn't, what changes. Twenty minutes, within a week, while it's fresh. Plans improve through incidents or through drills. Incidents charge more.
The rules that keep it alive
- Print it. Three copies: office, owner's house, one more offsite. A plan on the dead server is a paperweight with no paper.
- Name an owner. One person keeps it current. Update on every staff change, vendor change, or new system, and review it twice a year on a calendar reminder.
- Feed it from the audit. Your single-points-of-failure list is the plan's input. New findings become new pages, or better, become fixes so the page isn't needed.
Want this handled instead of homeworked? That's the job.
Email us →