Business Continuity: Turning a Paper Plan into a Practised Response

Business Continuity: Turning a Paper Plan into a Practised Response
News 8th May, 2026

Most organisations have a business continuity plan. Rather fewer have a continuity capability. The difference shows up in the first hour of a real disruption, when people either know what to do or start reading.

Start with dependencies, not scenarios

Scenario planning has a natural limit: the disruption you eventually face will not be on your list. Dependency mapping is more durable. Identify the processes that must run, then trace what each one actually needs — people, systems, suppliers, premises, data — and plan around the loss of those inputs regardless of cause.

Set recovery objectives that survive contact with reality

A four-hour recovery time objective written in a workshop means nothing if the supporting contract offers next-business-day support. Reconcile every objective against the contracts, staffing and technology that would have to deliver it, and correct whichever side is wrong.

Exercise in three tiers

  • Desktop walkthrough — ninety minutes, once a quarter, one scenario, no technology required.
  • Functional test — twice a year, actually restore something or fail over to a secondary site.
  • Full simulation — annually, with executives, communications and a clock running.

Write the plan for a bad day

Plans are drafted by people who are calm, well rested and fully informed, and used by people who are none of those things. Keep the front page to a single sheet: who to call, what to decide, and what not to do. Detail belongs in appendices.

Close the loop

Every exercise should generate a short list of fixes with owners and dates, and the next exercise should open by reviewing them. Continuity capability is built through that loop, not through the length of the document.