All training
SystemsStrategic Masterclasses· 66 min· Free and open to all

Why Your Business Needs a Contingency Plan

A practical framework for surviving outages, cyberattacks, and the loss of key people without descending into chaos.

Contingency planning gets skipped because nothing bad has happened yet. This session with George Mayfield covers what happens to businesses that skip it, and what the ones that survived a bad week did differently before the bad week arrived.

The first exercise is naming your real vulnerabilities instead of the generic ones. For most small businesses the list is short and uncomfortable: a single person who knows how something works, a single vendor with no backup, credentials that live in one inbox, a payment processor that could freeze, a building that could lose power, and a data set that isn't backed up anywhere you've tested.

A usable response plan answers 4 questions for each of those risks:

  • Who owns the response, by name, and who covers if that person is unreachable.
  • What the first 3 actions are, in order, within the first hour.
  • How customers and staff get told, on which channel, and with what message.
  • What “back to normal” means, so somebody can declare the incident over.

Then it moves to simulation. Reading a plan proves nothing; running one surfaces the gaps immediately: the phone list that's out of date, the backup nobody can actually restore, the 2 people who both assumed the other was handling notifications. A tabletop walkthrough of an hour or 2 per quarter is enough to keep a plan honest.

The session also covers the specific risks that hit hardest right now: ransomware and account takeover, extended outages at a platform you depend on, and the sudden loss of a key employee who carried undocumented process in their head. Each one has a preventive layer and a response layer, and the preventive layer is almost always cheaper.

It closes on culture. The plan matters less than the practice of it, and how leadership behaves in the first hour sets whether the team stays coordinated or fragments. Calm is a procedure, not a personality trait. It comes from people knowing their role before the pressure arrives.

Questions people ask about this

Answers pulled from the session itself. Where a number or an outside claim shows up, the reference is footnoted to the source list on this page. Last reviewed August 20, 2026.

What does this masterclass decide for my business?
This session establishes a clear operational fallback so your business survives outages, cyberattacks, or key staff departures without chaos. In fact, 95% of business leaders expect a crisis at least once a year. The masterclass gives a service business operator a framework to name real risks, assign response owners, and maintain coordination during a disruption.[2]
How do I start creating a contingency plan?
Begin by identifying your specific vulnerabilities, such as key staff members, single vendors, or untested data backups. For each risk, answer 4 core questions: who owns the response, what the first 3 actions are in the first hour, how to notify customers and staff, and what defines a return to normal. Documenting these specific steps ensures your team moves quickly instead of scrambling during a crisis.[1]
What does contingency planning cost in time and money?
Attending this live training session is completely free. Developing and maintaining your plan requires a modest time investment of a 1 or 2 hour tabletop simulation per quarter. Investing in this preventive preparation is significantly cheaper than responding to an active emergency, especially considering the average global cost of a data breach is $4.4 million.[3]
What is the most common mistake when making a plan?
The most common mistake is assuming that simply reading or storing a written document is sufficient. Plans fail in practice when phone lists are outdated, backups cannot be restored, or multiple people assume someone else is handling notifications. Running quarterly tabletop simulations surfaces these operational gaps before a real crisis hits.
How can I tell if my contingency plan worked?
You know your contingency plan worked when a disruption occurs and leadership responds calmly using established procedures within the first hour. Your operations remain coordinated while customer communication, revenue, and reputation stay protected. For instance, major platform outages can impact over 70,000 businesses at once, but a tested plan keeps your business functioning.[3]

The class, mapped

Original diagrams built from this session: the order the work runs in, what each stage owes the next, and the list to work against once the video ends.

Crisis Response and Recovery Process

Fig. 1 · Workflow map
  1. 1Lead Responder

    Identify the Incident

    Identify the failure point and confirm the active outage or breach.

  2. 2Response Owner

    Execute First Hour Actions

    Perform the 3 preplanned immediate containment steps in order.

  3. 3Communications Lead

    Notify Staff and Clients

    Deliver standardized communications across preassigned channels.

  4. 4Operations Team

    Run Operational Workarounds

    Switch to manual processes, backup systems, or secondary vendors.

  5. 5Technical Lead

    Restore and Verify Systems

    Recover primary data sets and test operational stability.

  6. 6Lead Responder

    Declare End of Incident

    Confirm back to normal criteria are met and close the response.

Follow this order when an outage or incident occurs to maintain operational control.

Contingency Readiness and Simulation Checklist

Fig. 2 · Checklist

Audit Vulnerabilities and Assign Owners

  • Document single points of failure including key staff, sole vendors, and processors.
  • Store backup credentials in an accessible, secure secondary location.
  • Assign primary response owners and alternate backups by name for each risk.
  • Define specific back to normal criteria for each core business system.

Simulate and Refine Response Plans

  • Schedule 1 to 2 hour quarterly tabletop walkthroughs with the team.
  • Audit phone lists, access permissions, and notification roles.
  • Test data restores to confirm backups function properly.
  • Log identified gaps during simulations and update procedures immediately.
Complete these actions to audit vulnerabilities and test response readiness.

Operational Risk Assessment Matrix

Fig. 3 · Decision map

↑ Low Prevention Cost

12345
← Low Operational ImpactHigh Operational Impact →

↓ High Prevention Cost

  • 1Undocumented Key Staff Process Low Prevention Cost, High Operational Impact
  • 2Untested Data Backups Low Prevention Cost, High Operational Impact
  • 3Single Payment Processor Freeze Low Prevention Cost, High Operational Impact
  • 4Extended Platform Outage High Prevention Cost, High Operational Impact
  • 5Local Facility Power Outage High Prevention Cost, Low Operational Impact
Map business risks by operational impact and the ease of preventive action.

Share the library

Send it to the one person on your team who needs it.

The training is free and open to all. Sharing is how the operator beside you stops guessing too.

Browse free training

Share the site

No login, no email gate. Watch, use it, pass it on.