How to Create a Business Resilience Plan

Briony Kennedy

A business resilience plan is the practical answer to one question: if something important stops working, how will the business protect people, continue critical activity and recover?

1. Identify critical outcomes

List the products, services, payments, communications and obligations that must continue. Set a tolerable interruption period for each. This helps separate essential recovery from “restore everything immediately.”

2. Map dependencies

For every critical outcome, identify the people, suppliers, systems, locations, equipment, data and approvals it depends on. Include concentration risk: one person, one platform, one major customer or one supplier.

3. Assess the risks

Score likelihood and consequence, then prioritise treatment. The Australian Government’s risk management guidance recommends owners, time frames, resources and regular review—not a risk list that sits in a folder.

4. Create continuity options

Define how critical work could continue at a reduced but acceptable level. Options might include a second supplier, temporary manual process, cross-trained team member, alternative payment method, remote workspace, offline contact list or secure data backup.

5. Define response and recovery

Record who declares an incident, who communicates, who makes operational decisions and what sequence protects customers, staff and cash. The Government’s emergency management plan separates continuity, immediate action and recovery—a useful structure.

6. Prepare communications

Create short templates for staff, customers, suppliers and advisers. State what happened, what is known, what customers should do and when the next update will come. Do not improvise sensitive facts under pressure.

7. Test the plan

Run a simple scenario: the founder is unavailable, the ecommerce platform is down, the main supplier cannot deliver or the office cannot be used. Time the response and record gaps. Cyber.gov.au also provides Business Continuity in a Box for interim critical communications and applications after a cyber incident.

Keep it usable

Your plan should show critical contacts, first actions, decision rights, alternatives and recovery priorities. Store it somewhere accessible during the event and review it after team, supplier, system or location changes.

Use the Australian business continuity checklist and key-person risk guide to build the detail. Then connect it to the complete sustainable growth framework.

General information only. Every business is different; use your own figures and seek professional advice where appropriate.

Back to blog