A DVG Systems Toolkit  ·  Edition 2026

The Business Continuity Planner

The plan your cyber insurer, your funders, and your biggest clients will ask to see — not something that lives in a binder no one ever opens. Built for Canadian small businesses and nonprofits.

www.dvgsystems.com   ·   (807) 700-0061
v2026.04

Who actually audits your continuity plan

A common myth: CRA audits IT and continuity controls for charities and small businesses. It doesn't. CRA looks at T3010 filings, receipting, governance, and financial records. IT and cyber resilience are not on the CRA audit scope.

The people who do ask — and decide whether you keep operating — are these:

This planner gives you a 6-section framework a board, insurer, or funder will recognise — and it's short enough to actually finish.

Section 1 — Critical process inventory

List every process the organization cannot go more than 72 hours without. Rate each by RTO (recovery time objective — how fast you must be back) and RPO (recovery point objective — how much data loss is tolerable).

Template
ProcessOwnerRTORPODepends on
PayrollFinance Lead< 48h< 24hM365, bank portal, ADP
Client billing    
Donor database access    
     
     

Section 2 — Data and system inventory

Where does each category of important data live, and who has access?

Template
Data / systemHosted whereBackup locationAccess controlled by
Email & filesMicrosoft 365M365 backup toolEntra ID / MFA
AccountingQuickBooks / SageVendor native + local export 
Donor / CRMSalesforce / Raiser's Edge / HubSpot  
Production data   
    

Section 3 — Dependency map

Which third parties would take your operation down if they failed? Name the vendor, the failure scenario, and your fallback.

Template
DependencyFailure impactFallback planWorkaround lead time
Internet (primary ISP)All cloud services offlineMobile hotspot tier / secondary ISP / failover router< 1h
Microsoft 365Email, files, Teams all downPersonal Gmail for staff; SMS/call tree for clientsImmediate
Phone systemInbound calls failForward DID to mobile; SMS banner15 min
PowerOffice unusableRemote-work posture; UPS on critical gearImmediate
    

Section 4 — Roles, contacts, and the call tree

In a crisis, nobody should be looking up contact details.

Template

Internal response team

RoleNameMobileAlt email
Incident CommanderUsually the Owner / ED  
IT / MSP Lead   
Communications Lead   
Board Chair   
Legal counsel   

External hotlines (put these on a laminated card)

Section 5 — Incident playbooks (the top 4 for Canadian SMBs)

Playbook A — Ransomware

  1. Isolate: disconnect affected devices from the network (pull cable or disable Wi-Fi). Do NOT power down — volatile memory holds evidence.
  2. Escalate: call the cyber insurance hotline first. They appoint the breach counsel and the forensic team — calling your MSP first can invalidate coverage.
  3. Communicate: staff are told what to say (and what not to say). Clients get the templated breach message within the timeframe your contracts require.
  4. Recover: restore from immutable backup under the supervision of forensic investigators, not before.
  5. Learn: within 14 days of recovery, run a post-incident review. Update this plan.

Playbook B — Microsoft 365 outage

  1. Check status.office.com (tenant) and admin.microsoft.com service health.
  2. Staff switch to the pre-established fallback (personal Gmail for client communications; phone for urgent internal).
  3. Communications Lead posts status to clients — default channel: your website banner + SMS.
  4. Log the outage in the continuity journal for insurance and post-incident review.

Playbook C — Key person loss (sudden)

  1. Recover access to accounts through the break-glass path (password manager emergency access, Entra ID break-glass account, IT administrator escalation).
  2. Notify clients and vendors who had a direct relationship with the person.
  3. Reassign in-flight work through the owner list in Sections 1 and 4.
  4. Begin offboarding / knowledge-transfer within 5 business days.

Playbook D — Prolonged ISP or power outage

  1. Trigger remote-work posture (staff work from home or a cafe with hotspot).
  2. Forward office phone lines to mobile or a secondary number.
  3. Post status update for clients on website and social.
  4. Log outage in continuity journal. Notify insurer if business interruption coverage is in play.

Section 6 — Test schedule and evidence log

A plan you haven't tested isn't a plan. Build the habit below.

TestFrequencyEvidence kept
Tabletop exercise (one playbook)Twice a yearAttendance, notes, action items, closure dates
Restore-a-file drill from backupQuarterlyScreenshot of restored file with timestamp
Full VM / server restore to alternate hardwareAnnuallyRunbook + screenshots + time-to-recover log
Phone / communications fail-overAnnuallyTest call log with before/after screenshots
Contact-tree pingAnnuallyRecord of who confirmed within the target window
The evidence log matters more than the plan itself. Insurers and funders don't read the binder. They ask for the most recent test log. Keep the last 24 months of evidence in the same folder as the plan.

The one-page summary (for funders, insurers, and enterprise clients)

When a request for your BCP arrives, send this one-pager first. It answers the 10 questions they ask in a format they can copy into their files.

One-page BCP summary — fill and sign

Organization:  

Plan date / version:  

Plan owner:     Board reviewer:  

Critical processes documented: yes / no — count:  

RTO on highest-priority process:  

Primary continuity scenarios covered: ransomware · cloud outage · key-person loss · ISP/power outage ·  

Cyber insurance carrier:     Policy #:  

Last tabletop exercise:     Next scheduled:  

Last restore test:     Next scheduled:  

Signed by:     Title:     Date:  

Sources
  1. Canadian Centre for Cyber Security, "Baseline cyber security controls for small and medium organizations" — cyber.gc.ca
  2. Canadian Centre for Cyber Security, ITSAP.40.003 "Developing your IT recovery plan" — cyber.gc.ca
  3. Office of the Privacy Commissioner of Canada, "Privacy breach guidelines" — priv.gc.ca
  4. Ontario Trillium Foundation, Grant governance requirements — otf.ca
  5. Coalition, 2026 Cyber Claims Report — coalitioninc.com/claims-report/2026

Want help turning this into a finished, tested plan?

DVG Systems runs a free 45-minute BCP review for Northern Ontario businesses and nonprofits. We help you fill the template, run your first tabletop, and hand you the one-page summary and evidence pack your insurer and funders are asking for.

Talk to us
(807) 700-0061
Email
solutions@dvgsystems.com
Book online
www.dvgsystems.com/contact