Business Continuity 15 July 2026

Backups Aren't a Business Continuity Plan. Here's the Gap Most Firms Miss

Most firms believe they're covered because they back up to the cloud. The gap between that assumption and a real Business Continuity and Disaster Recovery plan is exactly where businesses get into trouble.

Two professionals reviewing a business continuity and disaster recovery plan in a modern office

Posted on

15 July 2026


 

Related Topics

More about Blue Saffron Data Backup and Disaster Recovery Services

 

Read our blog: Top 8 Data Backup and Recovery Mistakes to Avoid

 

Download our Backup Buyers Guide

 

More about Blue Saffron


 

Get In Touch

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Ask most business owners if they have a business continuity and disaster recovery plan, and they’ll say yes. Ask what’s actually in it, and the answer is usually the same thing: “we back everything up to the cloud.” That’s a good start. It is not a plan.

The difference matters more than it used to. Recruitment agencies, accountancy firms, HR consultancies and business consultants now run almost entirely on digital systems, from candidate databases and client ledgers to email and shared documents. When those systems go down, the business doesn’t just slow down. It stops.

What Is the Difference Between Business Continuity and Disaster Recovery?

Business continuity is about keeping the business running while something is wrong. It covers people, communication, and how staff keep serving clients even if the office, the network, or a key system is unavailable.

Disaster recovery is about getting the technology back. It covers restoring servers, applications, cloud environments and data after something has gone wrong, with a clear target for how fast and how completely.

You need both, and they need to work together. A firm that can restore its servers in six hours but has no plan for how staff communicate with clients in the meantime hasn’t solved the problem. Neither has a firm with a slick internal communications plan and no way to actually get its systems back online.

The Gap Most Firms Don't See: Why "We Have Backups" Isn't a Plan

Having backups tells you your data exists somewhere. It doesn’t tell you how quickly you can get it back, who’s responsible for making that happen, or whether the process has ever actually been tested under pressure.

That gap became painfully clear in the collapse of KNP Logistics, a 158 year old UK haulage firm that went into administration in 2023 after a single guessed employee password let the Akira ransomware gang into its network. The attackers didn’t just encrypt the company’s live systems. They also destroyed its backups and disaster recovery infrastructure, leaving nothing to restore from. With a ransom demand estimated at £5 million and no viable way to recover, the firm ceased trading and around 700 people lost their jobs (Weightmans).

That’s an extreme case, but the underlying lesson applies to businesses of every size. A backup sitting in the same environment as your live systems is often exposed to exactly the same attack. If it isn’t tested, isn’t isolated, and isn’t part of a documented plan, it may not be there when you need it most.

Real World Example: KNP Logistics

In 2023, a single guessed employee password gave the Akira ransomware gang access to KNP Logistics. Attackers encrypted every system and destroyed the backups. With no way to recover, the 158 year old firm collapsed. Around 700 people lost their jobs.

What This Looks Like in Recruitment and Professional Services

The scenarios don’t need to be dramatic to be damaging. An accountancy practice locked out of client tax records during the January filing rush faces a very different kind of pressure than a firm that loses access in a quiet month. A recruitment agency shut out of its applicant tracking system during an active placement can lose candidates and client trust within days, not weeks. A consultancy that loses shared project files right before a client deadline has no time to improvise a fix.

None of these require a headline grabbing cyberattack. Ransomware, accidental deletion, a hardware fault, or a misconfigured system change can all trigger the same outcome: staff who want to work, but can’t.

What an Actual Business Continuity and Disaster Recovery Plan Includes

A proper BCDR plan answers four questions in advance, not during a crisis. How fast do systems need to come back (your recovery time objective, or RTO)? How much data loss can the business tolerate (your recovery point objective, or RPO)? Who is responsible for what during an incident? And has any of this actually been tested, rather than just documented?

For Commercial and Operations Leaders

This is increasingly a client relationship issue as much as a technical one. Procurement teams, auditors and cyber insurers are asking firms to evidence their continuity plans before they’ll sign contracts or renew cover. According to IBM’s 2025 Cost of a Data Breach Report, the average UK data breach now costs £3.29 million, and firms without tested response processes recover markedly slower than those with one in place (IBM). For most professional services firms, the real cost of an incident isn’t the ransom. It’s the client relationships damaged while the business scrambles to catch up.

For IT Decision Makers

The detail matters here. Backups need to be tested on a defined schedule, not left to run silently in the background. They should be immutable or isolated from the primary environment, since attackers increasingly target backup systems directly, as the KNP case shows. Datto’s State of BCDR Report 2025 found that 84% of MSPs report clients with a proper BCDR solution in place fully recovered from a ransomware attack within 24 hours, compared to those relying on backups alone. (Datto). Configured is not the same as tested, and untested is not the same as ready.

£3.29m

The average cost of a data breach for UK organisations in 2025. Firms without tested response processes recover significantly slower than those with a plan in place.

Source: IBM Cost of a Data Breach Report 2025

Where Microsoft 365 Helps, and Where It Stops Short

Microsoft 365 gives you a strong starting point. Built in version history, retention policies and geographic redundancy across Exchange, SharePoint and OneDrive genuinely reduce risk. But Microsoft’s shared responsibility model means the platform protects its own infrastructure, not your specific configuration, your retention settings, or your recovery from accidental deletion or a targeted attack. Most firms we speak to have never checked where that line actually sits, or assumed Microsoft 365 covers ground it doesn’t. That’s a gap worth closing before it’s tested by an incident rather than a conversation. You can see how we approach data backup and disaster recovery for a sense of what a properly configured setup looks like in practice.

How Often Should a Business Continuity Plan Be Reviewed?

At least once a year, and again whenever something significant changes, whether that’s new systems, new premises, a change in headcount, or a shift in regulatory requirements. A plan written two years ago for a team half the size, using software you no longer run, isn’t protecting the business you have today.

Getting an Honest Picture of Where You Stand

Most firms don’t know whether their current setup would actually hold up until something goes wrong, and by then it’s too late to find out gently. If you’re not sure whether what you have is a backup or a genuine continuity plan, that’s worth a conversation before it’s tested by circumstance. We’ve also written about the most common data backup and recovery mistakes we see firms make, which is a useful place to start if you want to check your own setup against them.

FAQs: Data Backup and Recovery Services

What is Business Continuity and Disaster Recovery?

BCDR is a combined strategy that keeps a business operating during a disruption while restoring IT systems and data as quickly as possible. One half covers people and process, the other covers technology.

What is the difference between Business Continuity and Disaster Recovery?

Business Continuity keeps the business functioning: staff, communication and client service during an incident. Disaster Recovery restores the technology itself, including servers, applications and data, within an agreed timeframe.

Does Microsoft 365 automatically back up my data?

It includes strong resilience features like version history and geographic redundancy, but under Microsoft’s shared responsibility model, your organisation remains responsible for its own configuration, retention and protection against deletion or attack.

How often should a Business Continuity plan be reviewed?

At least once a year, and again after any significant change, such as new systems, new premises, or a shift in team size or regulatory requirements.

What should a Disaster Recovery plan for a professional services firm include?

Clear recovery time and recovery point objectives, named responsibility during an incident, coverage of client facing applications like CRM or case management software, and a tested recovery process rather than an assumption that backups alone will suffice.

Why is Data Backup and Recovery important?

It protects client records, financial data and case files against deletion, hardware failure and cyberattack. On its own, though, it only answers part of the question. A full plan also covers how quickly systems come back and whether that’s been tested.

Are ransomware attacks on UK businesses actually increasing?

Yes. The National Crime Agency has described 2025 as on track to be the worst year on record for UK ransomware attacks, with high profile incidents hitting Marks & Spencer, Co-op and Harrods, alongside thousands of smaller businesses that receive far less attention (Weightmans).

Not sure if your data is fully protected? Get in touch today to book your free backup readiness review and we’ll identify the gaps and give you a clear, practical plan to secure your recruitment data before it’s too late.