Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status
Stressed business owner during an IT outage, laptop showing a system error warning

What Would Happen If Your IT Went Down Today?

Most people never think about their business continuity plan until the moment they need one – and by then it is too late to write it.

A flood, a ransomware attack, a server failure, a key team member leaving and taking their laptop password with them. Any of these can bring your operations to a halt. The question is not whether something will go wrong; it is how long you can afford to be offline when it does.

The difference between business continuity and disaster recovery

The two terms are often used interchangeably, but they mean different things.

Business continuity is the broader plan: how does the whole organisation keep functioning when something goes wrong? That covers people, processes, premises, suppliers and communications – not just the computers.

Disaster recovery (DR) is specifically about your IT systems: how quickly can you restore servers, data and applications after a failure?

Both matter, and for most UK SMBs they are closely linked. If your data disappears or your systems go offline, very little else keeps running.

Why UK SMBs are more exposed than they realise

Research published in 2025 found that only around one in four UK small businesses had a formal disaster recovery plan. More telling: organisations without one faced an average of 18 days of downtime after a ransomware attack, compared to a handful of hours for those that had tested their recovery processes.

Eighteen days is not an inconvenience. It is an existential threat.

Cyber insurers have noticed. Where policies used to focus almost entirely on technical controls such as firewalls and antivirus, insurers now routinely ask about tested backup and recovery procedures before they will offer cover – or before they will pay out on a claim. If you want cyber insurance that actually pays, you need to show you have done the work.

ISO/IEC 27001, the international information security standard that System Force IT holds as a certified organisation, requires both a business continuity plan and regular testing of it. If you work with clients who ask for ISO 27001 alignment or similar assurances, your disaster recovery posture is part of what they are assessing.

The two numbers that define your risk

Every DR plan is built around two straightforward questions:

Recovery Time Objective (RTO) – how long can your business survive without its IT systems? An hour? A day? A week? If you do not know your RTO, you cannot design a recovery plan that is fit for purpose.

Recovery Point Objective (RPO) – if you lost everything right now, how much data could you afford to lose? Yesterday’s backup? Last week’s? If your RPO is “nothing,” you need near-real-time replication rather than a nightly backup that ran at 2am.

Getting honest answers to these two questions is usually the most valuable thirty minutes a business spends on its IT risk review.

What a sensible plan looks like for an SMB

For most small and medium-sized businesses, a practical DR plan includes:

  • Immutable backups – copies of your data that cannot be altered or deleted, even by ransomware. Traditional backups can be encrypted or wiped by attackers; immutable copies cannot.
  • Offsite or cloud storage – at least one copy of your backups should be held somewhere physically separate from your office and separate from your primary cloud tenant.
  • A documented recovery process – who does what, in what order, and where to find the things they need. If your IT person is unavailable, can someone else follow the steps?
  • Regular, tested restores – a backup that has never been tested is not a backup; it is a false sense of security. Recovery tests should happen at least once a year, and preferably more often.
  • A communication plan – staff, customers and suppliers all need to know what is happening. Silence during an outage damages trust faster than the outage itself.

What about cloud services – are they automatically safe?

A common misconception is that storing files in Microsoft 365 or another cloud platform means they are backed up. They are not. Microsoft retains deleted items for 30 to 93 days depending on the application and your plan, but it does not protect you against accidental bulk deletion, ransomware that targets OneDrive sync, or an admin account being compromised and data wiped.

Cloud platforms need backing up just as on-premises systems do. This is something we cover as part of our managed IT support service.

Making a start without the jargon

You do not need a hundred-page document to have a workable plan. Start with the essentials:

  1. Know where your data is and who has access to it.
  2. Check when your last backup was taken and whether you can actually restore from it.
  3. Identify the three or four systems your business genuinely cannot function without.
  4. Find out whether your cyber insurance requires a tested DR plan – and if so, whether you have one.

If you have not done this recently, you are not alone. Most businesses we speak to have never formally reviewed their DR posture. We help them identify gaps, put the right backup and recovery tools in place, and run tests so they can be confident that recovery will work when it matters.

If your business holds or processes personal data – which almost every business does – a robust backup and continuity plan is also relevant to your Cyber Essentials and GDPR obligations. The ICO expects organisations to have measures in place to restore data availability after an incident.

How System Force IT can help

As a UKAS-certified ISO/IEC 27001 managed IT provider, business continuity and disaster recovery planning is part of the service we deliver for our clients – not an afterthought. We can review your current backup and recovery setup, help you understand your RTO and RPO, and put a tested plan in place that meets your operational needs and any compliance or insurance requirements.

If you would like help with any of this, get in touch or call us on 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name