Build a business continuity plan that would actually hold up
Thirteen sections, Australian hazards, agreed recovery objectives and an honest gap analysis. Download it as Word and keep editing it. No account, and your answers stay in your browser.
Build your continuity plan
Thirteen sections covering what most Australian businesses are asked for by insurers, auditors and enterprise clients. You’ll finish with a documented plan, a risk register and a prioritised gap analysis.
Your answers stay in your browser. A continuity plan lists your critical systems and weak points, so we don’t collect it by default. Progress autosaves locally. If you want to finish on another device you can request a resume link — that’s the only case where anything is stored, and it’s deleted after 90 days.
- A documented plan you can hand to an insurer
- Risk register using Australian hazards
- RTO and RPO per critical function
- Prioritised gap analysis by severity
- Download as Word to keep editing
- Save as PDF straight from your browser
Thirteen sections, in the order they matter
Built around what Australian insurers, auditors and enterprise clients actually ask for — not a generic template.
Business profile
Identifies the entity the plan covers. Insurers and auditors expect a plan to name the business it applies to.
Key people and responsibilities
In an incident, the first failure is usually that nobody knows who decides. This names them in advance.
Critical business functions
Establishes what must keep running and in what order. Everything downstream depends on getting this right.
Systems and applications
Maps each critical function to the technology it depends on — the link most plans are missing.
Recovery objectives (RTO and RPO)
Turns 'as fast as possible' into agreed, testable numbers. Insurers and clients ask for these specifically.
Risk assessment
Rates the hazards that realistically affect your sites, so effort goes where the risk actually is.
Data and backups
The single most common gap we find. A backup nobody has restored from is a hope, not a control.
IT infrastructure and cloud
Records what recovery would actually involve rebuilding.
People and workplace
Covers losing access to a building — and the WHS duty to have emergency plans and practise them.
Suppliers and third parties
Your continuity depends on theirs. Most plans stop at the front door.
Communications plan
Decides in advance who gets told what. Includes the Notifiable Data Breaches obligation if personal information is involved.
Incident response and escalation
Defines what triggers the plan and what happens in the first hour.
Testing, maintenance and review
A plan that isn't tested or reviewed is a document, not a capability. This is what auditors check.
About continuity planning
What the terms mean, what this produces, and what it can't do for you.
What's the difference between business continuity and disaster recovery?
Business continuity is about keeping the business trading — people, premises, suppliers, communications. Disaster recovery is the technical subset: restoring systems and data. A plan that only covers IT recovery is incomplete, which is why this tool asks about people, sites and suppliers as well as backups.
What are RTO and RPO?
Recovery Time Objective is how long a function can be unavailable before the impact becomes unacceptable. Recovery Point Objective is how much data you can afford to lose, measured in time — an RPO of four hours means you accept losing up to four hours of work. Both are business decisions, not IT ones, and insurers and enterprise clients ask for them specifically.
Is my data stored anywhere?
By default, no. Your answers autosave in your own browser and never reach our servers. A continuity plan lists your critical systems and weak points, so we deliberately don't collect it. If you email yourself the summary, we receive your score, the number of gaps and your contact details — not the plan contents.
Will this satisfy my insurer or an auditor?
It gives you a documented plan, agreed recovery objectives and an honest gap analysis, which is considerably more than most small businesses can produce. But it's generated from your own answers, so treat it as a strong starting point rather than assessed evidence. If a specific standard is being asked of you — ISO 22301, a tender schedule, an insurer's questionnaire — that needs a tailored piece of work.
Which hazards does the risk assessment cover?
Australian ones: flood, bushfire, cyclone, severe storm, extended power and telco outages, extreme heat, cyber incidents and ransomware, key person loss, supplier failure, loss of premises and pandemic. You select which are credible for your locations rather than working through a generic global list.
How long does it take?
Around 20 to 30 minutes if you know your systems. You don't have to finish in one sitting — progress saves automatically in your browser, and you can jump between sections in any order.
A plan is only worth what it does under pressure
The gaps this tool finds are usually fixable — untested backups, no deputy, no offsite copy. Book a free 30-minute review and we’ll work through the critical ones with you.
