What Is a Business Continuity Plan and Does My Business Need One?
A business continuity plan (BCP) is a documented, tested process for keeping your essential operations running during and after a disruption — a cyberattack, power cut, supplier failure or lost premises. It defines what must stay up, how fast, and who does what.
Quick answer
A business continuity plan (BCP) is a documented, tested process for keeping your essential operations running during and after a disruption — a cyberattack, power cut, supplier failure or lost premises. It defines what must stay up, how fast, and who does what. AMVIA builds tested continuity into managed cybersecurity: one accountable provider, security-first.
Key Points
What you need to know.
The Short Answer
As of March 2025, there are 12,867 active MSPs in the UK, employing 343,762 individuals.
For UK Businesses
The UK MSP sector generates an estimated £51 billion in annual revenue.
Cost Considerations
The UK managed services market is expected to grow at CAGR of 9.7% from 2026 to 2033.
Next Steps
SMEs account for 99% of UK businesses and are the backbone of the UK economy.
Quick Comparison
| Feature | Option A | Option B |
|---|
What does a business continuity plan actually do?
A business continuity plan keeps your business trading when something breaks. It identifies your critical systems and processes, sets recovery time targets, and documents exactly how people, data and communications carry on while the primary environment is unavailable. The goal is simple: limit downtime, protect revenue, and reach customers and staff fast.
Downtime is where the money goes. Small businesses lose an estimated £350–£450 per minute of downtime (typical UK 2026 range), and only 22% of UK businesses have a formal incident management plan in place (2025 UK data) — which means most are improvising during the exact hours when improvisation is most expensive. A BCP turns a panicked scramble into a rehearsed sequence.
A good plan answers four questions before disaster strikes:
- What must stay running? The handful of systems and processes the business cannot trade without.
- How quickly must each recover? Your recovery time objective (RTO) and recovery point objective (RPO).
- Who decides and who acts? Named roles, deputies, and an escalation chain that works at 2am.
- How do people keep working? Failover connectivity, manual workarounds, and alternative access to data.
What should a business continuity plan include?
At a minimum a BCP should cover critical-system identification, recovery time and recovery point objectives, backup and restore procedures, a communications protocol, defined roles and deputies, and alternative working arrangements. It must be written down, owned by a named person, and tested — an untested plan is a guess, not a control.
The components that separate a real plan from a shelf document:
- Business impact analysis — which functions hurt most, and how fast, when they stop.
- Tested backups — verified restores, not just "the backup ran". Backups that have never been restored fail at the worst moment.
- Failover connectivity — a second route to the internet so a single line cut does not close the office. This is where a business continuity service earns its keep.
- Incident communications — a contact tree, holding statements, and a channel that works when email is down.
- An incident response runbook — the technical steps to contain, eradicate and recover from a security event.
The UK's National Cyber Security Centre publishes detailed incident management guidance that pairs well with a BCP and is worth reading alongside your own plan (ncsc.gov.uk).
How is a BCP different from a disaster recovery plan?
A disaster recovery (DR) plan is the IT-restoration half of the picture: getting systems, servers and data back online after a failure. A business continuity plan is the wider organisational view — how the whole business keeps serving customers during the disruption, including people, premises, communications and manual workarounds. You need both, and they must reference each other.
| Aspect | Business Continuity Plan (BCP) | Disaster Recovery Plan (DR) |
|---|---|---|
| Scope | Whole organisation — people, process, premises, IT | IT systems, data and infrastructure only |
| Core question | How do we keep trading? | How do we restore the technology? |
| Owner | Leadership / operations | IT or managed IT provider |
| Typical contents | Impact analysis, roles, comms, workarounds | Backups, failover, restore runbooks, RTO/RPO |
| When it activates | Any major disruption | Specifically a systems/data outage |
The practical takeaway: DR is a subset of continuity. A business that has invested in Microsoft 365 backup and failover but never wrote down who calls customers, who authorises spend, or where staff work has a recovery plan, not a continuity plan.
Why do UK businesses need a business continuity plan now?
Because disruption is no longer rare. 43% of UK businesses experienced a cyber breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey 2025 (gov.uk). When the worst breach lands, the average cost is around £3,550 — and that headline figure excludes the operational losses that downtime piles on top.
Three forces make continuity planning a board-level issue for SMEs in 2026:
- Ransomware stops operations, not just data. A single ransomware attack can freeze every endpoint at once. Recovery time, not ransom payment, is the real cost.
- Cloud dependence concentrates risk. When Microsoft 365 or your primary line is the whole business, a single failure is an existential one without failover.
- Customers and regulators expect resilience. Buyers ask about continuity in due diligence; supply-chain questionnaires now treat a tested BCP as table stakes.
A plan does not stop incidents. It decides whether one costs you an hour or a fortnight.
How often should you test a business continuity plan?
Test your BCP at least annually, and again after any significant change to systems, premises or staffing. Testing should verify backup restores, run a failover simulation, and walk the communication chain end to end. Most failures — corrupted backups, stale contact lists, a deputy who left last year — only surface in a test, which is exactly why you run one before an incident finds them for you.
A sensible testing cadence:
- Quarterly — verify a real restore from backup, not just the backup job status.
- Annually — a full tabletop exercise walking the team through a realistic scenario.
- After major change — new ERP, office move, merger, or a switch of IT provider.
Pair testing with continuous 24/7 security monitoring so the events your plan is built for are detected early, when they are cheapest to contain.
How does AMVIA build business continuity into managed IT?
AMVIA bakes continuity into the day job rather than selling it as a separate document. Tested backups, failover connectivity, a documented incident runbook and clear recovery objectives sit inside the managed service, monitored by an in-house 24/7 SOC using Microsoft Defender for Endpoint. One provider, security-first, Microsoft-certified — so the people who run your systems also own your recovery.
That single-accountability model matters during an incident. There is no finger-pointing between a backup vendor, an IT contractor and a connectivity reseller — the same team that detects the event also restores the service and keeps you informed.
Frequently Asked Questions
A business continuity plan is a written, tested set of instructions for keeping your essential operations running through a disruption such as a cyberattack, outage or loss of premises. It names your critical systems, sets how quickly each must recover, and assigns who does what — so the business keeps trading instead of grinding to a halt.
At minimum: a business impact analysis, recovery time and recovery point objectives, tested backups, failover connectivity, a communications plan, and named roles with deputies. Keep it short enough to actually use under pressure. A two-page plan people have rehearsed beats a fifty-page binder nobody has opened since it was written.
Disaster recovery restores IT systems and data after a failure. Business continuity is broader — it covers how the whole organisation keeps operating during the disruption, including staff, premises, communications and manual workarounds. Disaster recovery is effectively the IT chapter inside a complete business continuity plan, and the two should cross-reference each other.
Test it at least once a year, and again after any major change to your systems, premises or staffing. Verify a genuine backup restore quarterly, run a full tabletop exercise annually, and update the plan whenever contacts or infrastructure change. Untested plans routinely hide corrupted backups and out-of-date contact details that only appear during a real incident.
Yes. 43% of UK businesses suffered a cyber breach or attack in the last 12 months (Cyber Security Breaches Survey 2025), and smaller firms are least likely to have a formal plan. Downtime costs mount by the minute, and customers and insurers increasingly expect evidence of a tested plan before they trust you with their data.
A named senior person should own the plan, with the technical recovery elements run by your IT or managed IT provider. Ownership cannot be vague — someone must be accountable for keeping it current, scheduling tests, and making the call to activate it. AMVIA takes ownership of the technical recovery layer as part of its managed IT support.
Related Questions
Managed IT Support
AMVIA's managed IT service includes tested backups and recovery procedures as standard.
What Is Ransomware?
Ransomware is the most common trigger for business continuity plans — and why tested backups matter.
Cybersecurity Guide for UK SMEs
Business continuity planning fits within a broader cybersecurity and resilience programme.
Protect your business → Get Cybersecurity Assessment