What a real plan contains, how to write one that works under pressure, and the mistakes that make plans fail on the day they are needed.
A business continuity plan (BCP) is the documented, rehearsed set of procedures that keeps an organisation's critical activities running through disruption. It is one output of a wider business continuity management programme, and it is only as good as the analysis behind it and the exercises that test it.
Do not start by writing procedures. Identify the activities whose interruption hurts most, the resources each depends on (people, systems, premises, suppliers, data), and two numbers for each: the recovery time objective, how quickly it must be back, and the recovery point objective, how much data loss is tolerable.
For each critical activity decide how continuity will actually be achieved: alternative premises or homeworking, manual workarounds, alternative suppliers, system failover, or accepting a defined outage. The plan documents decisions already made, so nobody designs a strategy at 03:00.
Short numbered actions, named roles, current contact details, and clear invocation criteria that state who may activate the plan and on what triggers. If a page cannot be followed by a capable deputy who has never seen it, rewrite it.
A desktop walkthrough finds gaps cheaply; a scenario exercise finds the ones that matter. Every exercise ends with a corrective action list and an owner for each item. Our exercising programmes, including Operation HELVETIA, are built for exactly this.
The most common failure is not a missing section. It is a plan written to satisfy an auditor rather than to be executed, left unexercised, with contact lists eighteen months old.
A business continuity plan (BCP) is the documented set of procedures an organisation follows to keep its critical activities running during a disruption and to recover them to normal within defined timeframes. It states who acts, in what order, with what resources and to what recovery objectives.
A disaster recovery plan is usually the IT component: how systems and data are restored. A business continuity plan covers the whole business: people, premises, suppliers, communications and processes, of which IT recovery is one part.
Review it at least annually, after every exercise, and after any significant change: new premises, new critical supplier, reorganisation, new system, or an actual incident. A plan that has not been exercised in the last twelve months should be treated as unproven.
A named senior owner accountable for the plan's currency, with each recovery action owned by a named role, not a person's name alone, so the plan survives staff changes. Continuity is a leadership responsibility, not an IT document.
We write, test and maintain continuity plans for organisations across Switzerland, the EU and the UAE. Tell us where you are and we will respond within 24 hours.
Book a consultation