Skip to content
Coverwright
← Notes
August 16, 2026 · 6 min read

The business continuity plan that’s actually one page

Most business continuity plan templates run twenty pages and get written once, then never opened again. What actually has to be decided — in what order, with which two numbers — to make a plan someone will still have read by the time it matters.

Search for a business continuity plan template and most of what comes back runs fifteen to twenty pages: a scope section, a governance section, a business impact analysis, a risk register, an appendix of forms. Thorough, and also exactly the kind of document that gets filled in once, saved somewhere, and never opened again — which makes it worth less than no plan at all, because it creates the impression that continuity has been handled.

The alternative isn’t doing less thinking. It’s writing down only the decisions that actually change what someone does in the first hours of a bad day, and keeping everything else out.

What actually has to be decided, in order

A continuity plan’s only job is to answer, before it’s needed, the question everyone will otherwise ask in the moment: what do we get working first? For most small businesses that order is the same three things — the ability to communicate (email, phone), access to the files people are actively working on, and the ability to take payment. That last one is easy to underrate: a business that can’t invoice or accept payment for a week has a cash problem stacked on top of the outage itself, and the fix — a way to take payment that doesn’t depend on the main systems being up — is worth deciding now rather than mid-incident.

The two numbers most plans skip

Two questions matter more than anything else in the document, and most templates never force a real answer to either: how long can the business actually function without its main systems before the damage is serious, and how much recent work can it afford to lose and redo. Both deserve an honest number rather than a hope — a working starting point for a lot of small businesses is one business day for each, adjusted up or down for what the business actually depends on. Writing the number down is what turns “we’ll figure it out” into something that can actually be planned against.

Why it has to be tested to be real

A continuity plan that has never been walked through is a document, not a capability — the two target numbers above are only as good as the backup and restore process behind them, and the first time anyone finds out how long a real restore takes shouldn’t be the day it matters. The fix costs almost nothing: a fifteen-minute walkthrough once a year, timed to the insurance renewal so it actually happens, asking one question — if the main systems were down right now, what would each person actually do — and correcting anything that turns out to be untrue.

What it doesn’t do

A one-page plan is deliberately narrow: it doesn’t replace the incident response plan that covers an actual attack, and recovery targets in it are decisions the business records, never a capability it’s claiming to have without having tested it. What it does is exist in a form someone will actually have read by the time it’s needed, which is the entire property a twenty-page version usually fails to have.

Coverwright’s Complete document set generates this as a genuine one-pager from the same answers as everything else — the restoration order, the two targets, and the annual test commitment, sized to fit on a page someone keeps rather than a binder nobody opens.