• (0)
    ISO-27001-ISO-22301-blog

    ISO 27001 & ISO 22301 Blog

    Business continuity for small businesses – necessity or not?

    Does it make sense to implement business continuity in smaller companies? Why would they need something as costly as this if the owner of the business has all the necessary information in his/her head?

    Let me start with a story I heard recently – a small company (involved in the sales of various equipment to a large customer base) has been robbed – the thief broke into their office during the night and stole all the computers together with other valuable stuff. The problem is – the owner of this company backed up the data, but saved that backup on another computer in the same office. Very soon the company went bankrupt – they simply weren’t able to recover key information about their business.

    This is a classic example of the syndrome “It is not going to happen to me” that the majority of small companies have.

    Business continuity framework

    Does this mean that small businesses need to invest in costly disaster recovery locations with high-availability equipment? Certainly not.

    In some cases business continuity is really not needed because the owner of the business does have all the information in his/her head, but such cases are very rare – how many of those don’t have a laptop with various kinds of important information? Just thinking about how to make this information available in case of a disaster is already part of a business continuity effort.

    Owners of small businesses need to think carefully about which information (and other resources) are important for their business, how to ensure that such information and other resources are available in case of a disaster, and which steps are needed to recover business activities in case a disaster occurs. These steps are nothing else but performing business impact analysis, business continuity strategy, and business continuity plans, like any larger company would do when implementing business continuity. All these are described in a leading business continuity standard – BS 25999-2.


    How to prepare

    Now the difference between small and the large businesses is in the complexity and the price of the preparations small companies need to do for business continuity:

    • Backup of electronic data – small businesses can use some of the tools that backup the data from their computers almost instantly to the cloud. Of course, due care has to be taken that all the necessary data is included.
    • Backup of paper-based documents – small businesses are now in a position to eliminate paper-based documents almost completely from their daily operations and transfer everything to electronic form; for rare cases where paper-based documents must exist, they can be scanned for the purposes of business continuity.
    • Alternative office locations – in most cases it will be enough that employees continue business operations from their homes – the prerequisite would be that they have an Internet connection, laptops/PCs and passwords. If working from home is not appropriate, a hotel room can always be rented in less than an hour.
    • Hardware – unless there is a special kind of computer used for a business, it is very easy to find an alternative – usually there is a private computer at home, or one can be borrowed from a relative; or one can be purchased at the computer shop next door.
    • Workforce – now, this is probably the most difficult one – let’s suppose that an employee is not available, and he is the only one who knows certain information (e.g. administrative passwords, steps that need to be taken in an important project, etc.) – for such cases, the preparation would be to document all this information, so that it can be used without that employee being present. The other case would be if an employee is missing and no one else would have the time or the skills to do her job – in such case the preparation would be to identify upfront who would be available for hiring on a short notice to fulfill the missing employee’s job; of course, the key here is to identify someone with the right skills/qualifications.

    To conclude: there is no difference between large organizations and small with regard to business continuity framework – they both have to think in detail what preparations they need to perform in order to survive a disaster. The difference is in the level of preparations – smaller businesses can make it with very little investment.

    This free webinar will also help you: Writing a business continuity plan according to ISO 22301.

    Advisera Dejan Kosutic
    Author
    Dejan Kosutic
    Dejan holds a number of certifications, including Certified Management Consultant, ISO 27001 Lead Auditor, ISO 9001 Lead Auditor, and Associate Business Continuity Professional. Dejan leads our team in managing several websites that specialize in supporting ISO and IT professionals in their understanding and successful implementation of top international standards. Dejan earned his MBA from Henley Management College, and has extensive experience in investment, insurance, and banking. He is renowned for his expertise in international standards for business continuity and information security – ISO 22301 & ISO 27001 – and for authoring several related web tutorials, documentation toolkits, and books.