AEO Answer

What Is a Business Continuity Plan and Does My Business Need One?

A business continuity plan (BCP) is a documented, tested process for keeping your essential operations running during and after a disruption — a cyberattack, power cut, supplier failure or lost premises. It defines what must stay up, how fast, and who does what.

Quick answer

A business continuity plan (BCP) is a documented, tested process for keeping your essential operations running during and after a disruption — a cyberattack, power cut, supplier failure or lost premises. It defines what must stay up, how fast, and who does what. AMVIA builds tested continuity into managed cybersecurity: one accountable provider, security-first.

Key Points

What you need to know.

The Short Answer

As of March 2025, there are 12,867 active MSPs in the UK, employing 343,762 individuals.

For UK Businesses

The UK MSP sector generates an estimated £51 billion in annual revenue.

Cost Considerations

The UK managed services market is expected to grow at CAGR of 9.7% from 2026 to 2033.

Next Steps

SMEs account for 99% of UK businesses and are the backbone of the UK economy.

Quick Comparison

Feature
Option A
Option B

What does a business continuity plan actually do?

A business continuity plan keeps your business trading when something breaks. It identifies your critical systems and processes, sets recovery time targets, and documents exactly how people, data and communications carry on while the primary environment is unavailable. The goal is simple: limit downtime, protect revenue, and reach customers and staff fast.

Downtime is where the money goes. Small businesses lose an estimated £350–£450 per minute of downtime (typical UK 2026 range), and only 22% of UK businesses have a formal incident management plan in place (2025 UK data) — which means most are improvising during the exact hours when improvisation is most expensive. A BCP turns a panicked scramble into a rehearsed sequence.

A good plan answers four questions before disaster strikes:

  • What must stay running? The handful of systems and processes the business cannot trade without.
  • How quickly must each recover? Your recovery time objective (RTO) and recovery point objective (RPO).
  • Who decides and who acts? Named roles, deputies, and an escalation chain that works at 2am.
  • How do people keep working? Failover connectivity, manual workarounds, and alternative access to data.

What should a business continuity plan include?

At a minimum a BCP should cover critical-system identification, recovery time and recovery point objectives, backup and restore procedures, a communications protocol, defined roles and deputies, and alternative working arrangements. It must be written down, owned by a named person, and tested — an untested plan is a guess, not a control.

The components that separate a real plan from a shelf document:

  • Business impact analysis — which functions hurt most, and how fast, when they stop.
  • Tested backups — verified restores, not just "the backup ran". Backups that have never been restored fail at the worst moment.
  • Failover connectivity — a second route to the internet so a single line cut does not close the office. This is where a business continuity service earns its keep.
  • Incident communications — a contact tree, holding statements, and a channel that works when email is down.
  • An incident response runbook — the technical steps to contain, eradicate and recover from a security event.

The UK's National Cyber Security Centre publishes detailed incident management guidance that pairs well with a BCP and is worth reading alongside your own plan (ncsc.gov.uk).

How is a BCP different from a disaster recovery plan?

A disaster recovery (DR) plan is the IT-restoration half of the picture: getting systems, servers and data back online after a failure. A business continuity plan is the wider organisational view — how the whole business keeps serving customers during the disruption, including people, premises, communications and manual workarounds. You need both, and they must reference each other.

AspectBusiness Continuity Plan (BCP)Disaster Recovery Plan (DR)
ScopeWhole organisation — people, process, premises, ITIT systems, data and infrastructure only
Core questionHow do we keep trading?How do we restore the technology?
OwnerLeadership / operationsIT or managed IT provider
Typical contentsImpact analysis, roles, comms, workaroundsBackups, failover, restore runbooks, RTO/RPO
When it activatesAny major disruptionSpecifically a systems/data outage

The practical takeaway: DR is a subset of continuity. A business that has invested in Microsoft 365 backup and failover but never wrote down who calls customers, who authorises spend, or where staff work has a recovery plan, not a continuity plan.

Why do UK businesses need a business continuity plan now?

Because disruption is no longer rare. 43% of UK businesses experienced a cyber breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey 2025 (gov.uk). When the worst breach lands, the average cost is around £3,550 — and that headline figure excludes the operational losses that downtime piles on top.

Three forces make continuity planning a board-level issue for SMEs in 2026:

  • Ransomware stops operations, not just data. A single ransomware attack can freeze every endpoint at once. Recovery time, not ransom payment, is the real cost.
  • Cloud dependence concentrates risk. When Microsoft 365 or your primary line is the whole business, a single failure is an existential one without failover.
  • Customers and regulators expect resilience. Buyers ask about continuity in due diligence; supply-chain questionnaires now treat a tested BCP as table stakes.

A plan does not stop incidents. It decides whether one costs you an hour or a fortnight.

How often should you test a business continuity plan?

Test your BCP at least annually, and again after any significant change to systems, premises or staffing. Testing should verify backup restores, run a failover simulation, and walk the communication chain end to end. Most failures — corrupted backups, stale contact lists, a deputy who left last year — only surface in a test, which is exactly why you run one before an incident finds them for you.

A sensible testing cadence:

  • Quarterly — verify a real restore from backup, not just the backup job status.
  • Annually — a full tabletop exercise walking the team through a realistic scenario.
  • After major change — new ERP, office move, merger, or a switch of IT provider.

Pair testing with continuous 24/7 security monitoring so the events your plan is built for are detected early, when they are cheapest to contain.

How does AMVIA build business continuity into managed IT?

AMVIA bakes continuity into the day job rather than selling it as a separate document. Tested backups, failover connectivity, a documented incident runbook and clear recovery objectives sit inside the managed service, monitored by an in-house 24/7 SOC using Microsoft Defender for Endpoint. One provider, security-first, Microsoft-certified — so the people who run your systems also own your recovery.

That single-accountability model matters during an incident. There is no finger-pointing between a backup vendor, an IT contractor and a connectivity reseller — the same team that detects the event also restores the service and keeps you informed.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.