How to Test a Business Continuity Plan: A Practical Exercise for UK SMEs

Yorkshire business team rehearsing an IT continuity and incident recovery plan

A business continuity plan can look perfectly sensible until something actually goes wrong.

During a genuine outage, people may discover that an important password is unavailable, the nominated decision-maker is on holiday, a supplier cannot be reached or the backup does not contain what everyone expected. These are expensive problems to uncover while customers are waiting and staff cannot work.

A tabletop exercise gives your team a safe way to rehearse an incident before it happens. It does not require anyone to disconnect live systems or simulate a technical attack. Instead, the people involved work through a realistic scenario, discuss what they would do and record the gaps that need attention.

What is a business continuity tabletop exercise?

A tabletop exercise is a structured discussion based on an unfolding incident. A facilitator introduces the situation in stages. Participants explain how they would respond, who they would contact, what decisions they could make and what information they would need.

The National Cyber Security Centre provides a free Exercise in a Box service covering scenarios including ransomware, phishing, supply-chain compromise and vulnerable systems. It is designed for organisations of different sizes and does not require participants to be cybersecurity experts.

The objective is not to catch people out. It is to find assumptions, unclear responsibilities and missing information while there is still time to correct them.

Choose one believable disruption

Begin with a scenario that could materially affect your organisation. Keep it specific enough to prompt decisions without turning the exercise into a technical examination.

  • Staff cannot access Microsoft 365 after several accounts are compromised.
  • A server or important cloud application becomes unavailable.
  • A ransomware warning appears on multiple computers.
  • The main internet connection fails during a busy working day.
  • A laptop containing business information is lost.
  • A critical supplier reports that its own systems have been breached.
  • Your premises cannot be accessed following a power, fire or security incident.

Choose the scenario that would have the clearest effect on customers, revenue, safety or essential operations.

Bring the right people together

A useful exercise normally needs more than the IT contact. Include people who understand how the organisation operates and who would have responsibilities during a disruption.

  • A senior decision-maker.
  • The person responsible for IT or the managed service provider.
  • Operations or service-delivery staff.
  • Finance or payroll.
  • Communications or customer service.
  • HR or data-protection responsibilities.

Nominate one person to facilitate the exercise and another to record decisions, unanswered questions and follow-up actions.

A practical 60-minute exercise

You can run a useful first exercise in approximately one hour.

1. Introduce the incident

It is 9:15 on Monday morning. Several employees cannot open shared files. Two computers display an unexpected ransom message, and a customer says an email from your finance team asked them to use a different bank account.

Ask who should be contacted first, how staff would report the problem, who has authority to make urgent decisions and whether any equipment or accounts should be isolated.

2. Add uncertainty

The main administrator account cannot be accessed. Your usual IT contact is unavailable, and it is not yet clear whether backups have been affected.

Discuss where emergency access details are kept, whether there is a second authorised contact, who can reach key suppliers and which services should be restored first. This stage often reveals that a technical control exists but nobody is certain who owns it or how it would be used.

3. Consider customers and communications

Telephone enquiries are increasing, and an important customer wants to know whether its information has been affected.

Decide who approves internal and external updates, how employees receive instructions if email is unavailable, and which customers, suppliers or insurers may need to be contacted. The NCSC recommends keeping a careful incident record, including decisions, actions and missing information. It also stresses the importance of clear communication with customers and other stakeholders during an incident. Read the NCSC incident-management guidance.

4. Work through recovery

  • Which data and systems are the highest priority?
  • What is the most recent acceptable recovery point?
  • Has the relevant backup ever been restored?
  • Are recovery credentials separate from everyday accounts?
  • Can the business operate from another location or connection?
  • Who decides when normal service can resume?

A green backup status is reassuring, but it is not proof that the required information can be restored within an acceptable time. Restoration testing should form part of the exercise where it can be performed safely. Our backup and business continuity service explains how recovery priorities and testing fit together.

Include personal-data decisions

A cyber incident does not automatically mean that a report must be made to the Information Commissioner’s Office. However, the team should know who will determine whether personal data has been affected and whether the reporting threshold is met.

For a notifiable personal-data breach, organisations must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Organisations must also keep records of personal-data breaches, including those that are not reported. See the ICO personal-data breach guidance.

Your exercise should identify who starts the incident record, who assesses the risk and where legal or specialist advice would be obtained.

Turn the discussion into an action plan

The exercise is only valuable if its findings lead to improvements. For every gap, record the required action, the person responsible, the completion date, the affected service and how completion will be checked.

Typical actions might include creating a second emergency administrator account, updating supplier contacts, testing a Microsoft 365 or server restoration, documenting call-diversion instructions or agreeing who can authorise emergency expenditure.

How often should an exercise be run?

There is no single schedule suitable for every organisation. As a practical starting point, consider an exercise at least annually and after significant changes to systems, premises, suppliers or senior responsibilities.

Use different scenarios over time. A ransomware discussion tests different decisions from a broadband failure, lost device or unavailable cloud supplier. Repeating an exercise after improvements have been made is an effective way to confirm that the original weaknesses have genuinely been addressed.

Make continuity something you can use

Business continuity should not be a document that is written once and forgotten. It should give people clear priorities, dependable contact routes and recovery arrangements they have seen work.

MSP247 helps organisations across Yorkshire review critical systems, backup arrangements, connectivity dependencies and incident responsibilities. We can also help structure a practical exercise and turn the results into a prioritised improvement plan.

Call 0330 301 0500 to discuss your current arrangements.

A practical technology partner

Clear ownership across your whole IT environment

MSP247 brings day-to-day support, security, connectivity and planning together so your team has one accountable route for help.

Whole-environment support

Windows, Mac, iPhone, iPad, Chromebook, servers, networks and cloud services supported as one working environment.

Yorkshire coverage

Responsive remote support with planned on-site assistance across York, Leeds and the wider Yorkshire region.

A clearly agreed scope

Responsibilities, priorities, escalation routes and available response arrangements are explained before service begins.

Security and continuity

Accounts, devices, backups and connectivity resilience are reviewed together instead of as isolated products.

This site uses analytics.