Business Continuity Planning After a Cyber Attack
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
How operational SMEs keep delivering when systems are down, and how to build the plan that makes a 72 hour outage a survivable event rather than a business ending one.
After a cyber attack the question that matters most to your customers is not how fast IT can recover, it is whether you can keep delivering while they do. Business continuity planning answers that question, and most operational SMEs do not have a meaningful plan. The KNP Logistics collapse and the longer tail of less publicised SME closures after ransomware all share a common thread: the operational side of the business could not function without the systems that had just been taken away. This guide is how to build a plan that prevents that.
Start with what cannot stop
Identify the two or three operational outputs your business absolutely must keep delivering during a 72 hour systems outage. For a haulier that is usually dispatch of contracted loads. For a 3PL it is goods in and goods out at agreed accuracy. For a warehouse it is pick and pack rates against the largest customers. For a professional services firm it is client meetings and invoicing. Build everything else around protecting those outputs. Anything that is not on the must keep delivering list is, by definition, deferrable for 72 hours.
Manual workarounds matter more than you think
When systems fail, paper, phones and pre printed forms still work and operational staff are usually very capable of using them if the leadership has set them up in advance. Pre printed run sheet templates, a paper KPI log, printed driver and customer contact lists, manual goods received notes, a printed price list. Store hard copies in the depot safe, the duty manager's office and (for the senior team contact list) the FD's car. Test the workarounds once a year so the team is genuinely ready, not just paper ready.
Roles, authorities and decisions in advance
Write down who makes which decisions during a systems outage. Who authorises agency drivers? Who authorises a hire vehicle? Who approves a £25,000 emergency spend with no purchase order? Who speaks to the largest five customers? Who calls the insurer? The middle of an incident is the worst possible time to discover the answer is ambiguous. Walk through the plan with the people named in it at least annually.
Out of band communications, again
If email and Teams are down, what do you use? Set up a WhatsApp or Signal group on personal phones for the leadership and senior ops team now. Maintain a printed crisis comms tree updated quarterly. For larger operators, a pre booked conference bridge number kept outside Microsoft Teams is standard. The single most common gap we find in SME continuity plans is that the plan itself relies on the systems that may be down.
Suppliers and customers
A good plan covers supplier failure (your TMS vendor, your IT outsourcer, your fuel card provider) and proactive customer communication, not just internal IT outage. Pre agreed customer holding statement templates and an established communications channel with the largest 10 customers speed everything up. We have seen operators retain customer relationships through serious incidents simply because the account manager was on the phone within two hours with a calm, accurate update.
Rehearse the plan annually
A tabletop exercise once a year with the leadership team in the room will surface every weakness in the plan, painlessly and cheaply. Use a realistic scenario (ransomware, TMS vendor outage, depot fire that takes out the server room). Run it for three to four hours. Debrief honestly. Fix what you find. Repeat. Every cycle, the plan gets sharper and the team gets more confident.
Continuity vs disaster recovery: do not conflate them
Disaster recovery is the IT side: RTOs, RPOs, backup restoration, infrastructure rebuild. Business continuity is broader and covers people, premises, process and customer commitments. You need both, and they need to be coordinated, but they are separate disciplines with separate plans. Most SMEs we work with start with a credible BC plan and use it to specify the DR requirements for IT.
What good looks like at 72 hours
Critical operational outputs maintained at 60 to 80 percent capacity. Largest 10 customers proactively contacted within 4 hours and updated every 12. Staff calm and following the plan. Insurer engaged. IR partner active. Recovery path decided by hour 12. Critical systems back into a hardened environment by hour 48 to 72. No surprises in the post incident review.
Frequently asked questions
Is this the same as disaster recovery?+
No. Disaster recovery is the IT side (RTO, RPO, backup restoration). Business continuity is broader and includes people, premises, process and customer commitments. You need both, and they should be coordinated.
How often should we test the plan?+
A full leadership tabletop at least annually, with a lighter desk check every six months. Any time you change a major system, customer base or office location, walk through the relevant section of the plan.
What is the most common gap in SME plans?+
Out of band communications. When email and Teams are down, most teams discover that their plan relies on email or Teams to coordinate. Set up the alternative channel and print the contact tree now.
Can we write the plan ourselves?+
Yes, with the right template and a competent ops lead. The hard part is not writing the document, it is testing it and updating it after the test. External help is most useful for the first tabletop exercise and the first post incident review.
Next step
Want to talk this through?
Book a free 30 minute consultation. No sales pitch, just clear answers.
Book free consultation