Published:

If you ask a 10-to-25-seat SME owner what their business continuity plan looks like, they'll probably describe a folder of backup logs or a USB drive in the cupboard. That's not a business continuity plan. It's one component of one.
A genuine business continuity plan is the documented framework that lets a small business keep operating — or recover quickly — when something goes wrong. Ransomware, server failure, flood, loss of a key person. Each scenario demands a different response, and each one requires that you've thought about it before it happens.
For owner-managed SMEs in Sussex and Kent, a business continuity plan isn't optional extras. It's a commercial necessity — especially when your clients expect you to be operational regardless of what happens behind the scenes.
What Makes a One-Page Business Continuity Plan Useful
The word "one-page" sounds reductive. But the constraint is the point. If your continuity plan can't fit on a single sheet of A4, it won't be read during an incident. The best plans are short enough to print, pin to a noticeboard, and hand to whoever is making decisions at 2 a.m.
A one-page plan does not replace detailed runbooks or technical disaster-recovery procedures. It proves six things that most SMEs never document until they need them:
What your critical functions are — the five or six things that keep the business running, ranked by priority.
Who owns each recovery — named individuals with deputies, not "the IT person."
How long each system can be down — your practical Recovery Time Objectives, written in plain English.
How much data you can lose — your practical Recovery Point Objectives, tied to your backup frequency.
Where your backups live — independent storage, tested recently, with documented access procedures.
Who communicates externally — a short contact tree for staff, clients, insurers, and your MSP.
Backup is not recovery. Recovery is not continuity. Continuity is the discipline of proving all three work together before an incident demands it.
Why "We Have Backups" Isn't Enough
Most SMEs have backups. What they lack is a plan that proves those backups serve the business, not just the IT team.
Microsoft 365 has data retention features, not a traditional backup. It protects availability — it does not protect your data from accidental deletion, malicious deletion, or sync failures. The National Cyber Security Centre's own guidance states clearly that organisations must test their backups so they know they can successfully restore data, and that the 3-2-1 rule (three copies, two media types, one off-site) only has value if those copies can actually be restored.
A backup that lives in the same Microsoft 365 tenant, controlled by the same credentials, and subject to the same ransomware propagation path offers limited protection against a tenant-wide compromise — regardless of how fast Microsoft can restore from their own copy.
A one-page plan forces the question: if your primary data store is compromised right now, can you recover it? Not "can we run a restore?" — "can we recover it within the time the business can tolerate, using people who actually know how?"
That distinction is where most SMEs fail.
Why backup alone is not recovery — and the gap that only appears on the worst day — is covered in our guide on backup not being recovery.
The Six Elements Your One-Page Plan Must Cover
1. Critical functions ranked by priority
List your critical business functions — not every system, the things that keep revenue flowing and clients served. For a typical Kent or Sussex SME this might include:
Customer-facing email (Exchange Online)
File storage and shared drives (SharePoint / OneDrive)
Your line-of-business application (CRM, accounting, ERP)
Phone system
Website
Assign each a priority tier: critical, important, deferrable. This ranking drives everything else in the plan.
2. Named owners and decision-makers
Every critical function needs a named owner and a named deputy. Not a job title — a person's name.
This covers:
Who declares an incident and activates the plan
Who makes the call to escalate to the insurer or your MSP
Who communicates with clients if service is disrupted
Ambiguity at this stage costs the first critical hour.
3. Recovery Time Objectives in plain English
RTO is how quickly you must restore operations after an incident. For a 10-to-25 seat SME, a realistic target is four to eight hours for critical systems — email, file access, collaboration platforms.
These are not IT settings. They are management decisions. If you have never defined recovery targets, you still have them in practice. They show up in comments like "email cannot be down all day" or "we could cope without that folder until tomorrow." A one-page plan turns those assumptions into decisions.
For a fuller treatment of the two metrics, see our practical guide to RTO and RPO for SMEs.
4. Recovery Point Objectives tied to backup frequency
RPO is the maximum amount of data loss you can accept — measured in time. If your last backup was two days ago, could you handle losing two days' worth of data?
Your RPO determines how frequently you must snapshot. Your backup strategy must match your RPO, not the other way round. A plan that states "we back up nightly" without stating "we can lose one day's worth of data and that is acceptable" is incomplete.
5. Backup location and access procedure
Where does your backup live? Is it independent of your primary environment? When was the last time you restored from it?
A one-page plan should state:
What is backed up (mailboxes, files, line-of-business data)
Where the backup is stored (third-party provider, off-site, immutable)
When it was last tested and by whom
Who holds the credentials to perform a restore
If the answer to any of these is "I don't know," your plan has a gap.
6. External communication contacts
A continuity plan is useless if nobody knows who to call or tell. Your contact tree should include:
Staff (mobile numbers, not just office extensions)
Key suppliers and cloud providers
Your MSP or IT support provider
Cyber insurance broker
Key clients (if service disruption affects them directly)
Keep it current. Stale contacts are the most common decay point in any continuity plan.
How often a plan like this should be exercised, and what a realistic testing cadence looks like for a 10–25 seat business, is set out in our guide on how often SMEs should test backups.
How to Build Yours This Week
You do not need a consultant to start. Here is the practical sequence:
List your top five critical functions. What keeps the business running? Rank them critical, important, deferrable.
Name an owner and a deputy for each. One person per row.
Write your RTO and RPO targets. Four to eight hours for critical systems. One day of data loss acceptable? State it.
Confirm where your backups live. Independent storage, tested within the last quarter.
Write a six-contact communication tree. Staff, supplier, MSP, insurer, key client.
Print it. Pin it. Test it once a year.
That is not a sophisticated BC programme. But it is better than nothing, and it is a foundation you can build on.
How This Connects to Your IT Security Baseline
A business continuity plan that has never been tested is a theoretical document. But testing it is not just an IT task — it is governance. The records should show what was tested, what worked, what failed, and how issues were tracked to remediation.
Cyber Essentials v3.3 (the Danzell update, in force from 27 April 2026) expects organisations to demonstrate backup and recovery capability. The scheme does not prescribe a specific template, but it does expect evidence that you can recover your data. A one-page plan with named owners, tested backups, and documented communication contacts is the simplest form of that evidence.
If you cannot evidence your recovery capability, you have a baseline gap. Repeated test failures, unclear ownership, missing datasets, and changes that invalidate recovery paths are not "technical inconveniences" — they indicate that your security baseline is not being maintained. That is the point where a structured baseline review becomes appropriate: to restore scope clarity, decision rights, and evidence-led assurance.
For the wider picture — planning, testing and recovery guidance in one place — see our business continuity hub.
FAQs
Does Cyber Essentials require a business continuity plan?
Cyber Essentials does not explicitly require a formal business continuity plan. The scheme focuses on technical controls — firewalls, secure configuration, access control, malware protection and patch management. However, backup testing is expected under the scheme, and a documented continuity plan is the simplest way to evidence that you can recover your data when needed.
How often should a one-page business continuity plan be tested?
At minimum, test it once a year through a tabletop exercise — walk through a realistic scenario with the team and see where the plan breaks. Quarterly spot checks (restoring from backup) are recommended for critical systems. Any material change to your environment — new systems, staff changes, migration — should trigger an out-of-cycle test.
What is the difference between RTO and RPO?
Recovery Time Objective (RTO) is how quickly you must restore operations after an incident. Recovery Point Objective (RPO) is the maximum amount of data loss you can accept — measured in time. RTO is about downtime; RPO is about data lost between the last good backup and the incident.
Do we need offsite copies for our backups?
Yes. A backup stored in the same environment as your primary data — whether that is Microsoft 365 retention features or a local NAS — offers limited protection against a ransomware event that compromises the entire tenant. Independent, offsite storage (preferably immutable) is essential for genuine recovery resilience.
---
If you would like an independent view of your current business continuity posture, Book a Security Triage Call.

Backup & Disaster Recovery
First 24 Hours of a Cyber Incident: SME Playbook

Cyber Security
Cyber Essentials Support for Kent SMEs

Modern Workplace
Invoice Fraud Checks UK SMEs: 5 Verification Steps

Backup & Disaster Recovery
One-Page Business Continuity Plan Template for UK SMEs

Modern Workplace