A natural disaster, ransomware attack, or major hardware failure can halt your business overnight. A business continuity plan ensures you can keep operating — or recover quickly — when the unexpected happens.
On a Tuesday afternoon, a ransomware attack encrypts every file on your server. Or a severe thunderstorm knocks out power to your Chicago-area office for 36 hours. Or your file server simply fails — and you discover that the last good backup is three weeks old.
These aren't hypothetical scenarios. They happen to businesses in the Chicago area regularly. The difference between a company that survives these events and one that doesn't often comes down to a single factor: preparation.
BCP vs. DRP: Understanding the Difference
These two acronyms are often used interchangeably, but they mean different things:
- Business Continuity Plan (BCP): The comprehensive plan for how your organization will continue operating during and after a disruption. It covers people, processes, facilities, and technology.
- Disaster Recovery Plan (DRP): A subset of the BCP focused specifically on recovering IT systems and data after a technical failure or disaster.
Think of it this way: the BCP answers "how do we keep serving customers?" while the DRP answers "how do we get our systems back online?"
Both documents are necessary. Most small businesses start with the DRP (because IT failure is their most likely disruption) and build toward a broader BCP over time.
Identifying Your Critical Systems
The first step in any continuity planning process is an honest inventory of what you can't live without. For most Chicago-area small businesses, critical systems include:
- Email and communications (Microsoft 365, Google Workspace, phone system)
- Customer-facing systems (website, e-commerce, booking/scheduling)
- Core business applications (ERP, CRM, accounting, industry-specific software)
- File storage and shared drives
- Payment processing
Document each critical system and answer:
- What happens if this system is unavailable for 1 hour? 4 hours? 24 hours? 1 week?
- What is the minimum functional version of this service we could operate on?
- Who is responsible for restoring it?
RTO and RPO: The Two Numbers That Drive Your Plan
Two metrics define your recovery requirements:
Recovery Time Objective (RTO): How long can you afford to be down? This is the maximum acceptable outage duration before the business suffers critical harm. An e-commerce company might have an RTO of 2 hours. A professional services firm might tolerate 24 hours.
Recovery Point Objective (RPO): How much data can you afford to lose? This determines how frequently you need to back up. An RPO of 4 hours means you can tolerate losing up to 4 hours of data — and your backup frequency needs to match.
Your RPO directly determines how often you must back up. If your RPO is 1 hour, daily backups are completely inadequate.
| Business Type | Typical RTO | Typical RPO |
|---|---|---|
| E-commerce | 1–4 hours | 15–60 minutes |
| Professional services | 4–24 hours | 4–8 hours |
| Manufacturing/Operations | 2–8 hours | 1–4 hours |
| Healthcare | 1–4 hours | Near-zero |
Setting realistic RTO and RPO goals then drives every technology and process decision: what backup technology to use, whether to invest in redundant internet, whether to move to cloud infrastructure.
Vendor and Supplier Dependencies
Many business continuity plans overlook third-party dependencies. Your plan should document:
- Critical vendors: What happens if your primary supplier can't deliver for two weeks?
- SaaS applications: What is the uptime SLA for your cloud software? What's their disaster recovery policy?
- Internet provider: Do you have a backup connection if your primary ISP goes down?
- Key personnel: Is there a single employee whose absence would cripple a critical process?
For IT systems specifically, TechniWorx recommends clients review the Terms of Service and SLAs for every cloud application they depend on. Many do not guarantee the uptime that users assume.
Power Outages and UPS Protection
The Chicago area averages significant storm-related power outages every year. An Uninterruptible Power Supply (UPS) protects your server room and network equipment from:
- Sudden power loss (which can corrupt open database files)
- Power surges and spikes
- Brief brownouts during storms
A properly sized UPS gives you 10–30 minutes of runtime — enough to save open files, gracefully shut down servers, and fail over to backup power sources. For critical operations, a generator provides extended coverage.
At minimum, every Chicago business should have a UPS protecting:
- File servers and NAS devices
- Core networking equipment (firewall, switches, key access points)
- Phone system equipment
Tabletop Exercises: Testing Your Plan Without a Real Disaster
A plan that's never been tested is a plan that won't work when you need it. Tabletop exercises simulate a disaster scenario in a conference room setting — no actual systems are touched, but teams walk through their response step by step.
A basic tabletop exercise might pose: "It's 8:00 AM Monday. You arrive at the office and discover your file server is offline and not responding. What do you do in the next 15 minutes? The next hour? The next day?"
These exercises reveal gaps in your plan before they matter. Conduct them at least annually, or after any significant change to your IT environment.
Your Communication Plan During an Outage
When systems are down, communication becomes critical — and ironic, because the systems you normally use to communicate may also be down. Your plan should include:
- Out-of-band communication method: A text message chain or phone tree that doesn't depend on company email or your internal collaboration platform
- Employee notification: Who tells employees what's happening and what they should do?
- Customer notification: A pre-written template for notifying clients of an outage, ready to send from a personal email if needed
- Vendor contact list: Printed or stored outside your primary systems — because searching your email for a vendor's phone number while your email is down is a real problem
When to Test Your Full Recovery
Beyond tabletop exercises, schedule an annual full recovery test where you actually restore from backup to a test environment and verify that critical systems come back online and data is intact. Many businesses discover their backups are incomplete or corrupted only during an actual disaster.
Quarterly, at minimum, test restoring a sample of files from backup. Monthly, verify that your backup jobs are completing successfully.
Need Help? TechniWorx helps Chicago-area businesses build practical, tested business continuity and disaster recovery plans — and implements the backup and infrastructure to support them. Get started with a free IT assessment at techniworx.com.
