A small organisation does not need a heavy manual for every possible crisis. It needs a short plan for protecting the few services, decisions and pieces of information that keep the business operating.
Dans cet article
Identify what must continue first
List the activities that customers, staff or regulators depend on. For each one, record the people, systems, suppliers and information needed to deliver it.
Decide how long the organisation could tolerate disruption and what a minimum workable service would look like. This creates priorities when everything cannot be restored at once.
Plan around effects, not every scenario
A cyber incident, power failure and supplier outage may have different causes but create the same effect: staff cannot access a critical system. Planning for loss of access is simpler than writing a separate manual for every event.
Make decisions and ownership explicit
Name who can declare an incident, contact customers, speak to suppliers and approve emergency spending. Add a deputy for every critical role and keep contact details somewhere available when normal systems are down.
Write the first five actions for each major consequence. During pressure, a short ordered list is more useful than a long policy.
Connect backups to recovery
The NCSC advises making regular backups of essential information and testing that the organisation can restore them. Record where backups are held, who can access them and how long restoration should take.
Include paper or offline copies of the minimum information needed to start recovery, while protecting confidential and personal data appropriately.
Test, learn and update
Run a short exercise using a realistic interruption. Ask the team to work through decisions without fixing the scenario for them. Record delays, missing contacts, unclear authority and assumptions that failed.
- Could the team find the plan?
- Could deputies make decisions?
- Did the backup restore?
- Were customer messages ready?
Update the plan after material changes and after every exercise or incident. Continuity is a maintained capability, not a document stored for inspection.