A well-designed Business Continuity Plan (BCP) is not a dusty folder gathering cobwebs on a shelf. It is an operational tool that, when a crisis strikes, enables your SME to recover in hours rather than weeks. The approach is framed by the international standard ISO 223011, and ANSSI also publishes highly practical guides2. Here are the four pillars to build, and the annual test that confirms their value.
Pillar 1 — Mapping critical activities
Every BCP begins with a clear identification of what must be restored first. An SME that believes it must save everything at once will, in practice, save nothing in time.
For each business process, ask three questions:
- How long can we stop it without major damage?
- Which tools are essential (software, data, communications)?
- Which staff members are critical to its restart?
This analysis — known as a BIA (Business Impact Analysis) — produces a quantified prioritisation. Without it, you will build an unrealistic plan.
Pillar 2 — The Disaster Recovery Plan (DRP)
The DRP is the technical translation of the BCP. It describes:
- The backup infrastructure (servers, workstations, internet access)
- The restoration procedures for data and applications
- The sequencing: where do we start, and in what order?
- The roles and responsibilities: who does what, under whose authority?
A good DRP is concise — a few pages — and operational. It must be readable and executable by an engineer who did not design your infrastructure.
Pillar 3 — Contractualised RTO and RPO
Two indicators govern any serious BCP:
- RTO (Recovery Time Objective): the maximum acceptable timeframe to restart a critical activity
- RPO (Recovery Point Objective): the maximum volume of data loss that is acceptable
Example for a law firm:
- RTO for email: 2 hours
- RTO for the file server: 4 hours
- RTO for the case management system: 8 hours
- Global RPO: 1 hour (hourly backup)
These figures must be contractualised with your IT provider. Without a written commitment, they are worthless.
Pillar 4 — Crisis governance
When an incident strikes, it is not the moment to improvise a decision-making chain. The BCP must explicitly define:
Roles
- Decision-maker: who validates major actions (isolation, communication, any payment)?
- Technical coordinator: who manages IT operations?
- Communications lead: who speaks to clients, the press, and the authorities?
- Legal contact: who notifies the ICO, relevant authorities, and insurers?
Channels
- Out-of-band: how do you communicate if your email system is compromised?
- Media: a prepared statement for LinkedIn, the company website, and local press
- Clients: a priority contact list and message templates
Triggers
- Which signals activate which phase of the BCP?
- Who contacts whom, in what order, and within what timeframe?
The annual test: the only real proof
An untested BCP is dead documentation. The annual exercise is what separates a useful BCP from a decorative one.
Three levels of exercise are possible:
Level 1 — Tabletop exercise
A 2-hour meeting with key stakeholders. A scenario is simulated, the BCP is walked through, and gaps are identified.
Level 2 — Partial test
A specific element of the DRP is actually triggered (for example, restoring a server to the backup environment), without touching the production environment.
Level 3 — Full-scale test
A controlled half-day outage: the primary IT system is shut down, operations switch to the backup, actual recovery times are measured, and deviations are documented.
Level 3 is demanding. But it is the only one that reveals genuine weaknesses — the outdated procedure, the forgotten password, the cable that does not reach where it should.
The cost of a BCP — indicative figures
For an SME of 20 to 50 people, here are the indicative figures we observe in practice (to be adjusted according to the complexity of your IT systems, the RTO targets, and business criticality):
- BCP and DRP design: 5 to 10 engineer days (in the region of £2,500 to £7,000)
- Backup infrastructure: typically £175 to £700/month ex. VAT (depending on the target RTO)
- Annual exercise: 1 to 3 engineer days
This should be weighed against the cost of a poorly managed crisis, which depends heavily on the company's daily turnover and the duration of the outage, but typically includes:
- Several days of complete disruption, with direct operating losses
- Remediation costs (emergency response, forensic expertise, crisis communications)
- Reputational damage and client losses
- Regulatory penalties where applicable (if personal data is compromised and GDPR obligations are not met)
- Lasting internal strain, sometimes including the departure of key staff
How IMACS SERVICES supports you
Our approach is structured in four stages:
- Continuity audit — mapping + BIA, 5 days
- BCP/DRP design — operational documentation, 5 to 10 days
- Backup infrastructure deployment — aligned with your RTO/RPO targets
- Annual exercise — facilitation and measurement, with a progress deliverable
To quickly assess your current level of business continuity, start with our free 15-question pre-assessment — report delivered within 24 hours, with no obligation.
Sources
Transparency note: all costs indicated are indicative figures observed in the field. They vary according to the complexity of your IT systems, your RTO/RPO targets, and the exact scope covered. Only a personalised audit enables a reliable estimate.
Footnotes
-
ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements. The international reference standard for establishing and improving a business continuity management system (BCMS). See iso.org. ↩
-
ANSSI, Maîtriser les risques de l'infogérance and associated guides on crisis management and business continuity. See cyber.gouv.fr and cert.ssi.gouv.fr. ↩
Keywords
- PCA
- PRA
- Continuité
- Résilience