Ask yourself the question calmly, on an ordinary morning: if tomorrow your premises are inaccessible or your server is down, how long can your business keep invoicing, collecting payments and delivering? Few owners have ever written the answer down. Yet that is exactly what a business continuity plan is for: deciding in advance what must survive, with what means and within what timeframe, so that nothing has to be improvised on the day.
In short: a continuity plan comes down to a few decisions taken calmly — which processes must survive, how quickly, with what data, what access credentials and what tools. It fits on one page, gets tested, and is reviewed every year.
What a continuity plan is (and what it is not)
The phrase sounds intimidating: one pictures a large corporation's binder of procedures and weeks of work. For an SME of ten or fifty people, the reality is far more modest. A continuity plan is a list of decisions taken calmly, while everything is fine, about what will be done when something goes wrong.
It is not a document meant to be read from cover to cover on a crisis day — nobody will. It is a memo: where the backups are, who holds which access credentials, how to keep invoicing without the office server, who to alert and in what order.
Nor is it insurance against incidents. A plan prevents neither the outage, nor the disaster, nor the attack: it shortens the downtime and limits what disappears for good. Two questions shape everything else:
- How long can I stay at a standstill? An hour without a till on a Saturday does not cost the same as a day without invoicing at month-end.
- How much work am I willing to redo? If the last backup dates from yesterday evening, you are accepting that a full day of sales may have to be re-entered.
Answering these process by process guides every technical decision that follows. Without them, you buy equipment at random; with them, you know what you are protecting first.
Mapping your risks
Before investing, list what can genuinely stop your business. The exercise takes an hour, around a table, with the people who know the ground. It is not about imagining improbable disasters, but about facing the incidents every company eventually meets:
- a prolonged power cut — and a local server shutting down abruptly, with the risk of a corrupted database if no UPS takes over;
- an internet outage, at the operator or on a single site, isolating a branch, a warehouse or a point of sale;
- a hardware failure: the server, the accountant's workstation, the disk that gives out without warning;
- a cyberattack, in particular ransomware encrypting the files — and, too often, the backups left plugged in;
- a theft or a fire on the premises, taking away equipment as well as paper documents;
- the unavailability of a key person: the owner, the accountant, or "the one who knows" how the software runs;
- an inaccessible site — building work, water damage, an outside event blocking access to the building.
For each line, fill in four columns. The table below gives the framework; the timeframes depend on your business and are yours to set.
| Risk | Immediate consequence | Acceptable downtime (to be set) | Countermeasure to prepare |
|---|---|---|---|
| Power cut | Server and workstations down, till out of service | How many hours without collecting payments? | UPS, clean shutdown procedure, applications reachable on mobile |
| Internet outage | No access to online applications or mail | Half a day? A full day? | Mobile tethering, second operator on sensitive sites |
| Hardware failure | A workstation or a server unavailable | The time needed to find a replacement machine | Restorable backup, spare workstation, no data stored locally |
| Ransomware | Files encrypted, business blocked | None: the backup decides | Disconnected copies, separate accounts, updates, awareness |
| Theft or fire | Equipment and paperwork lost | The time needed to re-equip | Off-site copy, paperless documents, equipment inventory |
| Key person away | Decisions and access blocked | An unplanned absence can last | Named accounts, a trained back-up person, written procedures |
| Inaccessible site | Teams outside, stock out of reach | How many days without the premises? | Remote work made possible, fallback location, up-to-date contacts |
This grid turns a vague worry into a short list of concrete actions, ranked by real urgency.
Data: backing up, and above all knowing how to restore
Most businesses back up. Far fewer check that they know how to restore. Yet that is the only thing that counts on the day: a backup that cannot be restored is not a backup, it is a file.
Four principles are enough to cover the most expensive scenarios:
- several copies, never just one: a single disk sitting next to the server disappears with it in a theft or a fire;
- at least one off-site copy: another building, or online hosting;
- at least one disconnected or non-modifiable copy, because ransomware encrypts everything it reaches, including the backup disk left permanently plugged in;
- an automatic, monitored backup: the one that depends on a daily human gesture ends up forgotten, and the one that fails silently is only discovered on the day of the outage.
A restore test is planned like any other task: pick a file and a database, restore them onto another machine, and time it. The exercise almost always reveals two things: the real recovery time, often far longer than estimated, and the existence of something nobody was backing up — software settings, document templates, attachments, the till database.
Protecting data does not stop at copying it: it also covers access rights, updates and vigilance against fraudulent messages, all detailed in our guide to cybersecurity in business.
Access: what happens if one person holds the keys?
This is the most common blind spot in small organisations, and the easiest to fix. Take an inventory of the access credentials without which the business stops: online banking, mail, domain name, management software, tax and social security portals, telecom operator account. For each of them, one question: how many people can log in today? If the answer is "only one", that is a risk in the same way as a single disk.
Three habits are enough to defuse it: create named accounts rather than shared ones, so an access can be revoked in a minute when someone leaves; centralise credentials in a password manager rather than in a notebook or a spreadsheet; appoint a second trusted person who knows the recovery procedure.
The keyring test: what would happen if your work phone were lost tonight? Are banking codes, two-factor authentication and recovery access all concentrated on it? If so, a single pocket holds the continuity of the business.
Working outside the premises
Once the data is protected and the access shared, the most concrete question remains: where do people work when they can no longer enter the office?
Software installed on a server at the office ties the business to the building: if the premises are inaccessible or the server is down, there is no fallback, you have to wait. Applications opened from a browser move the problem onto ground where the answer already exists — any connected computer becomes a workstation again. The Covid crisis, in 2020, demonstrated this on a large scale, but a flooded corridor or three days of building work produce the same effect at the scale of an SME.
The subject goes beyond tooling: it touches organisation, as detailed in our guide on how to manage your business remotely. For teams who do not work behind a desk — drivers, sales reps, technicians — it is offline synchronisation that guarantees sales and deliveries keep being recorded even without a network.
The cloud does not remove every risk: it shifts some of them onto the quality of your connection and the seriousness of your host, two points to examine before signing — we compare them in our analysis of the cloud for SMEs.
Stay in control of your business, wherever you are
Discover in 30 minutes how to steer sales, stock and cash flow from the office, home or the field.
Request a demoThe critical processes to protect first
You do not protect everything with the same intensity: a plan that treats the archiving of old files as carefully as invoicing will never be completed. Four processes concentrate the stakes in an SME.
Invoicing
An invoice not issued is a payment delayed, and a few days of standstill at month-end shift the whole chain. Invoicing and sales tracking therefore come top of the list, with one precise question: from which workstation, with which numbering, could an invoice be issued tomorrow morning if the usual system were unavailable?
Collecting payments and tracking cash flow
During an incident, expenses carry on, revenue does not always. Knowing where the balance, the due dates and the unpaid invoices stand shapes the decisions of the following weeks: our guide on how to master your cash flow in times of uncertainty details the indicators to follow.
Paying salaries
Payroll has a legal deadline that does not negotiate with circumstances. The plan must say where the employee data is, who can run the payroll in place of the usual manager, and how transfers can be issued if the usual banking access becomes impossible.
Delivering and serving customers
An untracked delivery turns into a dispute a few weeks later. If the system is unavailable, a deliberate fallback mode is needed: notes numbered by hand, photographed, then re-entered as soon as things return to normal — with a designated person, failing which the re-entry will never happen.
For each of these four processes, write a single sentence: "if we are at a standstill, we do this, with whom, and we regularise like that". That is precisely what is missing on the day.
Writing your plan on one page
A long plan will be neither read nor kept up to date. One page known to two or three people is worth more than a forty-page report archived somewhere. Here is what it should contain:
- the three to five vital processes and, for each, the acceptable downtime;
- where the data is, how it is restored, how long that takes and who knows how to do it;
- the list of critical access credentials and the names of the people who hold them;
- the useful contacts: IT provider, host, operator, bank, insurer, accountant;
- the fallback mode of each vital process, in one sentence;
- the fallback location and the conditions for remote work;
- who decides, who informs customers, who informs the teams;
- the date of the last review, so an outdated document can be spotted at a glance.
One detail that matters: keep a copy outside the system it protects. A plan stored only on the server that has failed is of no use. A printed version and a copy on the phones of two people are enough.
Testing, then reviewing
A plan that is never tested remains an intention. The test does not need to be spectacular, but it must be real. Three exercises are enough.
- The annual restore: genuinely restore a database or a folder onto another machine and check the content.
- The tabletop exercise: thirty minutes, one assumption ("the server died this morning"), and everyone describes what they would do. The gaps show up quickly.
- The access review: at every arrival or departure, check who holds what.
The review is scheduled once a year and at every structural change: a move, new software, opening a site, the departure of a key person. The owner carries the subject; a designated person keeps the document up to date. Without an owner, a plan quietly ages and becomes wrong again.
Finally, bear in mind that continuity is not primarily an IT project: it is a way of organising information so that it depends neither on a building, nor on a machine, nor on a single person. Centralising sales, purchasing, stock, finance and payroll in a single system accessible online — that is the role of an ERP — removes a good share of the blocking scenarios. Swifto was built on this principle for Tunisian SMEs, with mobile apps that work offline and dashboards that give an up-to-date view of cash flow and stock, even in disrupted times.
Frequently asked questions
Where should I start on a limited budget?
With what costs nothing: listing the processes the business cannot stop, writing down who holds which access credentials, and checking that backups exist and can actually be restored. Those three actions already cover the essentials. Investments — a UPS, a second internet connection, online hosting — come next, starting with the risk whose consequences would take longest to repair.
Is the cloud enough to ensure continuity?
No, but it removes several major weak points. With applications hosted online, a stolen workstation or a failed server no longer stops the business: work resumes from any connected device. What remains to be handled is internet access, password management, team training and everything that still lives on paper.
How often should backups be tested?
At least once a year for a full restore, and at every significant change: new software, new server, new provider. The test means actually restoring a file or a database onto another machine, then checking that the data is readable and up to date. A backup that has never been restored is only an assumption.
Does a company with fewer than ten people need a written plan?
Yes, and it is even quicker to produce. In a small organisation, knowledge is concentrated in one or two people: that is precisely what makes the absence of a document dangerous. A single page stating where the data is, who holds the access credentials and how to keep invoicing is enough to avoid paralysis.
What if one person holds all the access credentials?
Create named accounts rather than shared ones, appoint a second trusted person and store critical credentials in a password manager whose recovery access is known to the owner. The point is not distrust, but making sure that a departure, an illness or a simple holiday cannot block the bank, the mailbox or the management software.
