Business Continuity Plan Template
What your business does on the day the server dies, the key person doesn't show up, or the supplier goes dark.
Why SMEs need one more than big companies do
Large organisations survive disruptions because they have redundancy — spare people, spare systems, spare cash. Most SMEs have none of those buffers, which means a single event (ransomware, a warehouse fire, the founder in hospital) can stop revenue entirely. A business continuity plan doesn't prevent the event; it shortens the gap between "everything stopped" and "we're operating again", and it turns a panicked scramble into a checklist someone can follow at 6am without you.
How the template is organised
1. Critical functions and tolerable downtime
Start by listing what the business must keep doing — taking orders, paying staff, serving existing clients — and how long each function can stop before damage becomes serious. This ranking drives everything else: you protect the functions with the shortest tolerable downtime first.
2. IT disaster recovery
For each critical system (accounting, email, job management, phones, website), record where the data lives, how it's backed up, how quickly it can be restored, and who does the restoring. The template prompts you to note the last time a restore was actually tested — an untested backup is a hope, not a plan. Aligning your controls with the Australian Cyber Security Centre's Essential Eight is a sensible baseline for the prevention side.
3. Key person absence
The scenario SMEs plan for least and suffer from most. For each person whose absence would hurt within a week, document: what only they do, where the passwords and authorities sit (banking, ATO and government portals, supplier accounts), who acts in their place, and what that delegate is authorised to decide. If the honest answer is "nothing works without the owner", the plan has found its first project — our owner absence test is built for exactly this, and reducing founder dependency is the longer fix.
4. Supply chain disruption
For each critical supplier or input: the alternative source, the switching time, and any stock or capacity buffer you hold. Include concentration risk — a single customer can be as dangerous as a single supplier.
5. Premises and equipment
Where the team works if the site is unusable, what equipment is essential, and what your insurance actually covers (business interruption cover is worth confirming with your broker rather than assuming).
6. Communication protocols
Who tells whom, in what order, through what channel: staff first, then customers, suppliers, your bank and insurer. The template includes a contact tree and pre-drafted holding messages, because composing calm messages mid-crisis is when mistakes happen.
7. Activation and roles
Who declares an incident, who leads the response, and where the plan itself is kept — including a copy that survives the disaster (printed and off-site or in independent cloud storage, not only on the server that just failed).
Filling it in without boiling the ocean
- Do the top three scenarios first — usually IT outage, key person absence, and premises loss. A plan covering three real risks beats a binder covering twenty hypothetical ones.
- Write for a stressed reader. Short steps, names, phone numbers. No paragraphs.
- Pull details from the people who do the work, not just management — they know the real dependencies.
Keeping it alive
A continuity plan decays quickly: people leave, systems change, suppliers churn. Diarise a review at least annually and after any significant change, and run one small test a year — restore a backup, or have the owner stay unreachable for a day and see what breaks. The businesses that handle disruption well aren't lucky; they've simply rehearsed. A documented, systemised operation recovers faster by default — see how to systemise your business.