Why a Business Continuity Plan Is a Sign of Great Leadership in 2026 — The Buff IT Guy’s Guide
When everything is working, leadership can look easy.
The internet is online. Microsoft 365 is behaving itself. Staff can access their systems. Customers can reach you. Suppliers are delivering. Backups are completing.
Then something happens.
A ransomware attack takes systems offline.
Your main internet connection fails.
Microsoft 365 becomes unavailable.
A critical supplier suffers a cyber incident.
The building loses power.
A server fails.
A key member of staff suddenly becomes unavailable.
And suddenly everyone wants to know:
“What do we do now?”
Great leadership means answering that question before the incident happens.
That is what a good business continuity plan is for.
In 2026, business continuity is no longer just about fires, floods and occasionally working from another office. Modern organisations depend heavily on cloud platforms, connectivity, suppliers, data and digital systems. The UK Government's Cyber Governance Code of Practice makes clear that cyber risk requires ownership at board and director level because serious incidents can disrupt operations, damage customer trust and threaten financial resilience.
Or, as the Buff IT Guy might put it:
You don't build the emergency plan while the server room is already on fire.
What Is a Business Continuity Plan?
A business continuity plan explains how your organisation will continue delivering its most important services when normal operations are disrupted.
It should answer questions such as:
What absolutely has to keep running?
What can temporarily stop?
Who makes decisions during an emergency?
How will employees communicate?
How will customers be updated?
Which systems need recovering first?
Which suppliers are critical?
How will people work if the office, internet or cloud systems are unavailable?
How will the business return to normal?
The NCSC recommends that response and recovery planning prioritises the organisation's essential functions and the systems, assets and information needed to support them.
That means your continuity plan should not begin with technology.
It should begin with the business.
Buff IT Guy Rule #1: Work Out What Actually Matters
Imagine every system in your organisation disappears for 24 hours.
What stops the business?
Email?
Phones?
Accounting?
Customer records?
Production?
Remote access?
A specialist line-of-business application?
Internet connectivity?
Now imagine the outage lasts three days.
The answers may change.
A business impact analysis helps you understand which activities are genuinely critical and how quickly they need to return.
This prevents the common mistake of treating every system as equally urgent.
During a serious outage, trying to restore everything simultaneously can actually slow recovery.
Instead, establish priorities.
For example:
Priority 1: communications, identity and essential customer services.
Priority 2: core business applications and critical data.
Priority 3: supporting systems.
Priority 4: lower-priority services that can wait.
The exact sequence will be different for every organisation.
The important part is deciding it beforehand.
Define Your Minimum Viable Operation
One of the most useful concepts in modern continuity planning is Minimum Viable Operations, or MVO.
Following a major cyber attack, your immediate objective may not be restoring every printer, application, shared folder and historical archive.
It may be getting the company back to the lowest safe level at which it can continue operating, meet its obligations and maintain trust with customers and staff.
The NCSC's newly updated 2026 guidance on recovering from highly disruptive cyber attacks puts considerable emphasis on restoring organisations to minimum viable operations before progressing towards a fuller rebuild.
For a professional-services business, MVO might mean:
Email.
Telephones.
Access to key customer records.
A small number of essential applications.
Basic finance functions.
For a manufacturer, it could be completely different.
Buff IT Guy Rule #2
Recover what the business needs first — not whatever happens to be easiest for IT to restore.
Understand RTO and RPO
Two useful continuity and disaster-recovery terms are:
Recovery Time Objective — RTO
How quickly does something need to be restored?
If payroll can tolerate a 24-hour outage, its RTO might be very different from a system where five minutes of downtime stops production.
Recovery Point Objective — RPO
How much recent data can you afford to lose?
If restoring last night's backup means losing an entire day's orders, is that acceptable?
For some systems it may be.
For others, absolutely not.
NIST's contingency-planning guidance defines RTO around the maximum acceptable time a system resource can remain unavailable before the business impact becomes unacceptable.
You don't need to turn continuity planning into an enormous spreadsheet of acronyms.
But you do need to understand:
How quickly must we recover?
and
How much data can we afford to lose?
Those answers determine the technology and investment required.
Plan for Cyber Attacks, Not Just Traditional Disasters
Older continuity plans often concentrated heavily on:
Fire.
Flood.
Power failure.
Bad weather.
Loss of building access.
All of those remain relevant.
But in 2026, your continuity plan also needs to consider digital disruption.
For example:
Ransomware encrypts your servers.
Microsoft 365 accounts are compromised.
Your identity platform is unavailable.
A cyber attack takes your main supplier offline.
Your ISP has a major outage.
Your MSP suffers an incident.
A cloud service becomes unavailable.
Critical laptops are lost or compromised.
The NCSC explicitly recommends integrating cyber incident scenarios into wider business continuity and disaster-recovery plans and testing that those plans actually work together.
That distinction matters.
You can have an excellent ransomware-response document and an excellent business continuity document.
If the two contradict each other during a real incident, you still have a problem.
Business Continuity, Disaster Recovery and Incident Response Are Different
These terms often get mixed together.
Business Continuity
How do we keep the organisation operating?
Disaster Recovery
How do we restore our technology, systems and data?
Cyber Incident Response
How do we contain, investigate and manage the security incident?
During ransomware, all three may happen simultaneously.
IT may be isolating systems.
Forensic specialists may be investigating.
Management may be deciding which services can operate.
Employees may need alternative working arrangements.
Customers may need communications.
Insurers, legal advisers or regulators may need contacting.
The NCSC's board guidance specifically says senior leaders should seek assurance that incident planning, response and recovery are effectively managed, because these capabilities underpin the organisation's ability to maintain continuity.
This is why continuity planning belongs in the boardroom as well as the server room.
Make Sure Your Backups Can Survive the Incident
A continuity plan saying:
“Restore from backup.”
is not enough.
Can you actually restore from backup?
And can the attacker delete those backups first?
The NCSC warns that neither cloud nor onsite backups are automatically resistant to ransomware. Its ransomware-resistant backup principles recommend capabilities such as isolating backup infrastructure, protecting backups from destructive actions, retaining earlier recoverable versions and generating alerts for significant or privileged changes.
Your continuity planning should therefore establish:
Where important backups are stored.
Who controls them.
Whether backup credentials are separate.
Whether destructive actions require strong authentication.
How frequently backups occur.
How long versions are retained.
How quickly data can be restored.
When restoration was last tested.
Because this sentence:
“The backup completed successfully.”
does not necessarily mean:
“We can recover the company.”
Buff IT Guy Rule #3
A backup isn't impressive until you've successfully restored something from it.
Green ticks do not rebuild servers.
Don't Forget Microsoft 365 and Cloud Services
Moving services to the cloud changes continuity planning.
It doesn't eliminate it.
Suppose your business relies heavily on Microsoft 365.
What happens if employees temporarily cannot access:
Outlook?
Teams?
SharePoint?
OneDrive?
Entra ID authentication?
A line-of-business SaaS application?
You might not control Microsoft's infrastructure, but you absolutely control how your organisation prepares for disruption.
Think about alternative communications.
Offline access where appropriate.
Emergency contact information.
Critical documents.
Independent backups where justified.
Administrator access.
Supplier escalation procedures.
And manual workarounds for genuinely critical processes.
Cloud services reduce some infrastructure risks.
They do not remove the need for continuity planning.
Know Which Suppliers Could Stop Your Business
Most companies are interconnected.
Your ability to operate may depend on:
An internet provider.
Cloud platforms.
Payroll providers.
Payment processors.
An MSP.
Software vendors.
Logistics partners.
Telecommunications providers.
Manufacturers.
A major cyber incident affecting one of them can become your continuity incident even when your own network is perfectly secure.
The NCSC's current supply-chain principles encourage organisations to understand their dependencies and establish appropriate control and oversight across important suppliers.
Ask:
Which supplier failure would hurt us most?
Then:
What is our alternative?
If the answer is:
“We don't have one.”
at least you now know the risk exists.
Give People Clear Roles
An emergency is a terrible time to decide who is in charge.
Your continuity plan should define responsibilities beforehand.
That may include:
Incident lead
Coordinates the overall response.
IT or cyber lead
Manages technology, containment and recovery.
Senior decision-maker
Approves major business decisions.
Communications lead
Coordinates messages to employees, customers and potentially the media.
Operations lead
Keeps essential services functioning.
Legal/compliance contact
Handles legal, contractual and regulatory considerations.
You should also identify deputies.
If your entire continuity plan depends on Dave answering his mobile while he is somewhere in Spain with no reception, the plan has a slight design flaw.
The NCSC recommends incident plans contain key contacts, escalation criteria and alternative contacts because the people you expect to be available may not be.
Keep an Offline Copy of the Plan
Imagine your continuity plan is stored here:
SharePoint → Management → Business Continuity → Final Plans
Excellent.
Then your Microsoft 365 environment becomes inaccessible.
How do you read the plan?
Important emergency information should be available through a method that does not depend entirely on the systems potentially affected by the incident.
That might include securely maintained offline copies of:
Emergency contacts.
Supplier numbers.
Cyber-insurance information.
Key procedures.
Critical system inventories.
Escalation details.
Recovery priorities.
You don't need 200 printed pages sitting in everyone's desk drawer.
But the core plan needs to remain accessible during the event it is designed to manage.
Communication Needs Its Own Continuity Plan
Communication can become chaotic during disruption.
Employees need to know:
What has happened.
Whether they should work.
Which systems are safe to use.
Who they should contact.
What they should tell customers.
What they should not do.
Customers may also need updates.
And there may be circumstances where regulators, insurers, suppliers or law enforcement need to be involved.
Prepare basic communication processes beforehand.
Also think about what happens when your normal communication method is unavailable.
If Microsoft Teams is your emergency communication system and Microsoft 365 is the thing that's down, congratulations — you have discovered another problem.
Test the Plan
This may be the most important part.
A continuity plan that has never been tested is a theory.
Run exercises.
For example:
“It is 8:15 Monday morning. Ransomware has affected several servers and users cannot access Microsoft 365. What happens now?”
Then work through it.
Who makes the first decision?
Who calls IT?
Can you access the contact list?
Can people work?
How do you contact staff?
Which service is restored first?
When do customers get told?
Who contacts your insurer?
What happens if your managing director is unavailable?
The NCSC provides Exercise in a Box, a free service designed specifically to help organisations practise responses to realistic cyber scenarios, including tabletop exercises.
Testing exposes assumptions while you still have time to fix them.
Buff IT Guy Rule #4
The first time you test your disaster plan should not be during the disaster.
That's not testing.
That's improvising.
Review the Plan When the Business Changes
Your continuity plan isn't finished forever because somebody added:
Version 1.0 — FINAL
Businesses change.
You recruit staff.
People leave.
Systems move to the cloud.
Suppliers change.
New offices open.
Applications are replaced.
Telephone numbers change.
Responsibilities change.
Threats change.
Review the plan periodically and whenever a significant business or technology change occurs.
An old continuity plan containing telephone numbers belonging to employees who left three years ago is more archaeology than resilience.
Why Continuity Planning Is a Leadership Issue
Great leaders don't need to know how to rebuild Active Directory or restore a SQL database.
But they should know enough to ask:
What could seriously disrupt this company?
How long could we survive without our critical systems?
Which services must recover first?
Are our backups genuinely recoverable?
Who makes decisions during an incident?
When did we last test the plan?
What did the test reveal?
Cyber resilience is increasingly recognised as a board-level responsibility in the UK. The Government's Cyber Resilience Pledge, launched in April 2026, specifically encourages organisations to make cyber security a board responsibility and implement the Cyber Governance Code of Practice.
Leadership isn't about guaranteeing nothing will ever go wrong.
Nobody can promise that.
Leadership means making sure the organisation is prepared when something inevitably does.
The Buff IT Guy Verdict
Business continuity isn't a dusty document written to satisfy an insurance questionnaire.
It is your answer to:
“How do we keep going when normal stops working?”
A strong 2026 continuity plan should identify your critical services, define your minimum viable operation, understand recovery objectives, protect backups, account for supplier and cloud dependency, allocate responsibilities and provide alternative ways of operating.
Then you test it.
Find the weaknesses.
Fix them.
And test it again.
The Buff IT Guy spends plenty of time building resilience.
Usually with dumbbells.
Your business should do the same with its IT.
Business Continuity and Disaster Recovery With Hamilton Group
Hamilton Group can help organisations improve the technology behind their business continuity, disaster recovery and cyber resilience plans.
That can include reviewing critical systems and dependencies, improving backup and recovery, implementing ransomware-resistant backup strategies, managing Microsoft 365, protecting endpoints and identities, monitoring servers and networks and helping businesses plan for technology failures before they become emergencies.
We can also help identify areas where a business relies too heavily on a single system, supplier or piece of ageing infrastructure and develop a more resilient IT environment around it.
And when your organisation does need IT support, our aim is to make first contact on support requests within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.