Business Continuity Planning
Brisbane & Gold Coast
When ransomware hits, a server dies or a key person walks out, how fast can you get back to work? We help you answer that in advance, in a plan your team can follow under pressure.
- Written in plain English
- Linked to your backups
- Reviewed every year

Our business-hours response time for critical incidents such as systems down or a security breach.
Response to critical incidents, business hours
Onsite for critical issues across South East Queensland
Achieved through CyberCert
Businesses supported
Small businesses have less room to absorb a disruption
Large companies have spare systems and people. A small business usually has one server, one finance person and one copy of the password list.
Without a plan, people make rushed calls, the wrong things get switched off, and a few hours of disruption stretches into weeks.
- Ransomware encrypts files and locks systems
- A server or key laptop fails
- Microsoft 365 or Google Workspace is down for hours
- The person who holds the passwords leaves suddenly
- Flood, fire or a power outage closes the office
Start with what your business can't do without
A business impact analysis sounds formal, but it’s a working session with you and the people who run each area. We list what the business does every day, such as quoting, invoicing, payroll or dispatch, and the systems behind each task.
Then we ask how long you could manage without each one before clients, cash flow or legal obligations suffer. The answers decide what comes back first and where faster recovery is worth paying for.

- Which systems and data do you need to trade today?
- How long can each be down before it really hurts?
- How much work could you afford to redo?
- Who makes the calls during an incident?
Recovery time and recovery point, in plain words
Two numbers drive every continuity plan, and they decide what kind of backup and recovery you need.
Recovery time objective
How long a system can be down before it seriously hurts the business. Your booking system might need to be back within hours, while an archive of old jobs could wait days.
Recovery point objective
How much work you can afford to lose, counted back to the last good backup. With daily backups, a late-day failure could mean redoing that day’s work. If that’s too much, we back up more often.
We set targets for each system, not one number for everything. See how data backup and recovery supports them.
The plan documents we write with you
Business continuity plan
Your critical functions, the systems behind them, recovery targets and the order of recovery.
Incident response plan
Who does what in the first hours of a cyber incident, outage or data breach, and who gets called.
Communication plan
Who tells staff, clients and suppliers, with draft messages written in advance.
Data breach response steps
How to assess whether a breach must be reported under the Notifiable Data Breaches scheme.
IT recovery steps
How to restore each key system in the right order, so we or anyone else can follow them.
Contacts and access register
Key contacts, with critical passwords in a business password vault so no one person is a single point of failure.
How long could you trade without your systems?
If you don’t know, start there. We’ll review your backups, security and existing plans and show you the gaps.
How we build your plan
Quoted before we start. Managed IT clients already have much of the groundwork in place.
Review what you have
We check your backups, security, documentation and any existing plans.
Business impact analysis
A working session to rank your critical functions and set recovery targets for each system.
Write the plan
We draft the continuity, incident response and communication plans, then refine them with you.
Close the technical gaps
If your backups or security can’t meet the targets, we recommend and quote the changes.
Test and review
We test restores against your recovery targets, fix what the test exposes and set a yearly review date.
A plan is only real once it has been tested
We test the parts of the plan that depend on IT. We restore your critical systems from backup and time how long it takes, so you know the recovery targets hold before you need them.
Say it’s Monday morning and there’s a ransom note on the reception PC. The plan says who isolates the machines, who calls us and who tells clients. The restore test shows whether the systems you need first come back in time, and the review catches an outdated contact list or a password only one person knows.
We then update the plan. Review it yearly, and after any big change.

Continuity ties your IT and compliance together
Backups that match the plan
Your recovery point sets how often we back up, and your recovery time sets how you restore. Test restores prove the targets.
Answers for your insurer
Cyber insurance applications often ask whether you have a documented, tested incident response plan. This work lets you answer yes.
SMB1001 and the Essential Eight
Regular backups are one of the Essential Eight strategies, and SMB1001 Gold asks for a cyber incident response plan. Continuity work counts towards both.
Business continuity: common questions
What is a business continuity plan?
A business continuity plan sets out how your business keeps running, or gets running again, after a disruption such as ransomware, a system failure, a flood or the loss of a key person. It lists your critical functions, recovery targets, who does what and how you communicate.
What is the difference between business continuity and disaster recovery?
Disaster recovery is the IT part: restoring systems and data after a failure. Business continuity is broader: how the whole business keeps serving clients meanwhile, including people, communication and manual workarounds. A small business needs both, linked in one plan.
What is the difference between RTO and RPO?
The recovery time objective (RTO) is how long a system can be down before it seriously hurts the business. The recovery point objective (RPO) is how much recent work you can afford to lose. RTO shapes how you restore, and RPO shapes how often you back up.
Does a small business need a business continuity plan?
Yes. Small businesses have fewer spare systems and people, so a disruption hits harder. Insurers, clients and frameworks such as SMB1001 increasingly expect a documented incident response plan. It can be short, as long as it’s specific and tested.
How do you test a continuity plan?
We test the parts that depend on IT: restoring critical systems from backup against your recovery targets, and checking the recovery steps and contact lists are current. We review the plan with you every year and after any big change, such as new systems or an office move.
How much does business continuity planning cost?
It depends on your size and how many critical systems you run. For clients on our managed IT services, much of the groundwork is already in place. Otherwise we deliver it as a standalone project, quoted before we start.
Build resilience into your IT
Data backup and recovery
The technical foundation of any continuity plan.
Cyber security services
Stopping incidents is the cheapest form of continuity.
Governance and compliance
Where continuity fits in your wider compliance work.
Managed IT services
Continuity built into how we run your IT.
Healthcare IT support
Continuity for practices where downtime affects patients.
Is your business ready for a bad day?
We’ll look at your backups, security and any plans you already have, then show you what a practical continuity plan would involve.
- Where your biggest recovery risks are
- Which systems need the fastest recovery
- A quoted plan, written in plain English
Prefer to talk? Call 1300 619 750, Monday to Friday.
Tell us what you need. We’ll get back to you within one business day.
