Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer
Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough.
The Gap Between Confidence and Reality
Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident.
The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services when something goes wrong – a ransomware attack, a supplier outage, a critical system failure, or simply a key person being unavailable at the wrong moment.
Operational resilience is the ability to absorb that disruption and continue operating. It is not IT uptime. It spans people, process, and technology – and the gaps are almost never where organisations expect them to be.
Why Recovery Speed Is the Only Metric That Matters
When an incident occurs, there are two numbers that determine how badly it hurts: how long until normal operations resume (Recovery Time Objective, RTO) and how much data or work is lost in the process (Recovery Point Objective, RPO).
Most SMEs have not formally agreed these with their leadership teams. IT may have a view. The business rarely does. The result is that recovery decisions get made under pressure, without a baseline, and often in ways that do not reflect what the business actually needs to protect.
Consider what an unplanned 48-hour outage costs your organisation. Not just in lost productivity – in customer trust, regulatory exposure, revenue impact, and the reputational cost of communicating a failure you were not prepared for. For mid-market organisations, the numbers are significant. For those in regulated sectors, they can be existential.
The Cyber Resilience Bill, currently progressing through Parliament, will formalise many of these expectations for UK businesses. Organisations that treat resilience as a box-ticking exercise are going to find the compliance bar has moved considerably higher. Those that treat it as a genuine operational capability will be far better positioned – both to absorb incidents and to demonstrate readiness to customers, auditors, and insurers.
The Five Areas Where SMEs Are Most Exposed
Working with mid-market organisations across more than 30 sectors, we consistently see the same gaps appearing in resilience assessments. They are rarely technical failures. They are almost always governance, process, and ownership failures.
1. No named owner for resilience
When resilience sits in IT, it gets treated as an IT problem. But the decision about which services must keep running, what downtime is acceptable, and how the business communicates during an incident – those are board-level decisions. Organisations that have not assigned a business owner for operational resilience typically discover this at the worst possible moment.
2. Backup and recovery are not the same thing
Having backups does not mean you can recover. Recovery depends on tested restore procedures, documented RTO/RPO targets the business has actually agreed, and verified ability to access those backups even if your primary admin accounts are compromised. Most organisations test backups. Very few test recovery under realistic failure conditions.
3. The first 60 minutes are unplanned
Incident response plans that only cover IT steps are not incident response plans – they are runbooks. A real incident response plan covers who makes decisions, who communicates externally, how you reach your team if email and Teams are down, and who your external contacts are for legal, insurance, and forensics support. The first hour of any serious incident is the most consequential. Most SMEs have not rehearsed it.
4. Third-party dependencies are invisible risks
Many organisations do not have a complete picture of which suppliers are critical to their operations and what happens if one of them fails. Cloud providers, payroll platforms, line-of-business applications, and managed service providers all represent potential single points of failure. If your MSP or cloud provider is unavailable for 24 hours, do you know exactly what that means for your operations and how you would respond?
5. Continuity lives in one person’s head
In many SMEs, the person who knows how everything works – the systems, the processes, the workarounds – is a single individual. If that person is unavailable during an incident, the organisation is in serious difficulty. Resilience requires that critical knowledge is documented, shared, and tested by people who do not already know it.
The Cyber Resilience Bill: Why the Compliance Landscape Is Shifting
The UK Cyber Resilience Bill introduces a more structured set of expectations around how organisations manage, document, and test their ability to withstand and recover from cyber incidents. While the full legislative detail is still developing, the direction is clear: regulators and government expect mid-market organisations to move beyond reactive security toward proactive, evidenced resilience.
For many SMEs, this represents a meaningful shift. Resilience has historically been viewed as the domain of large enterprises and regulated financial services firms. That is changing. The Bill signals that the standard of care expected of all UK organisations – particularly those operating critical supply chains or handling sensitive data – is rising.Organisations that begin building genuine resilience capability now will have a considerable advantage: in compliance readiness, in customer and partner confidence, and in their ability to respond when, not if, an incident occurs.
Where to Start: A Practical 30-Day Framework
Resilience improvement does not require a large programme. It requires clarity, ownership, and a disciplined focus on the highest-impact gaps. A structured 30-day approach typically delivers more value than a lengthy strategy exercise:
- Week 1. Identify your three most critical services and assign a named business owner for each. Define what maximum tolerable downtime looks like in business terms.
- Week 2. Confirm RTO and RPO targets with leadership. Validate that your backup coverage actually reflects those targets.
- Week 3. Test a restore for your two most critical systems. Document the results. If you cannot complete a restore cleanly, you have found your most important gap.
- Week 4. Run a 60-minute tabletop incident exercise with IT, operations, and a senior leader present. Use a realistic scenario: ransomware, supplier outage, or key-person unavailability. Agree the three improvements that come out of it.
This is not a compliance exercise. It is a practical test of whether your organisation can answer the question: if something goes wrong today, what happens next?
Use Our Operational Resilience Reality Check
To help IT leaders and senior teams identify where their resilience gaps are before an incident forces the issue, we have developed The Operational Resilience Reality Check, a structured 28-question assessment covering governance, backup and recoverability, incident readiness, security controls, third-party dependencies, and people risk.
It takes 10 minutes to complete and is designed for managing directors, COOs, CFOs, and CIO-level leaders who want an honest picture of where they stand. The scoring is straightforward: Mostly Green means you are in a strong position and should focus on continuous improvement. A mix of Amber and Red means you are exposed and need to prioritise. Mostly Red means you are relying on hope.
Download the Operational Resilience Reality Check and find out where your gaps are. If you would like a second pair of eyes on the results, Espria can run a short Resilience Review Workshop to validate your priorities, identify quick wins, and map a practical improvement plan. Call us on 0303 003 3579 or visit espria.com.
You may be interested in
The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste
Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…
Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations
For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…
Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan
Moving from box‑ticking compliance to real‑world cyber readiness Written by Richard Puckey Cyber security has a confidence problem For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure. The problem? Cyber threats don’t operate on an annual cycle. The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…
How Housing Associations Can Transform Tenant Experience with Modern OmniChannel CX
Written by Russell Hallam, CX Consultant at Espria In today’s housing landscape, tenants expect fast, seamless and personal interactions, no matter which channel they use. Phone, digital, web chat, video, email, messaging: it all needs to feel connected, consistent and effortless. But for many teams, the reality is different. Disconnected systems slow down responses, important information is buried across platforms and frontline staff shoulder the burden of manual processes. At Espria, we’ve helped housing associations modernise their customer experience with cloud-enabled omnichannel solutions designed for efficiency, visibility and compliance. Here’s what that looks like in action. 1. RealTime CRM Integration: Context at the Exact Moment You Need It When a tenant calls,…
Elevating Human Risk Management: A Boardroom Must for Cyber Resilience in 2026
Written by Richard Puckey As organisations move through 2026, cybersecurity has firmly established itself as a core business risk. Regulatory scrutiny is increasing, threat actors are more capable than ever and the operational and reputational impact of cyber incidents continues to escalate. In response, businesses have invested heavily in security technology such as advanced detection platforms, zero trust architectures, AI-driven analytics and automated response capabilities. These controls are considered essential and non-negotiable. However, are they sufficient? The reality facing security leaders today is clear, the majority of material cyber incidents still involve a human decision…
Beyond Copilots: Why AI Agents Are the Next Competitive Advantage
Written by Stephen Cook AI is no longer a tactical tool, it’s becoming the engine of enterprise transformation. While copilots and other generative AI tools have helped teams work faster, the real breakthrough is happening with AI agents: autonomous systems that don’t just assist but act, learn and orchestrate entire workflows across the business. The question every executive should be asking is: “How will we harness AI to create value at scale before our competitors do?” High-performing organisations aren’t waiting. They’re embedding AI agents into daily operations and seeing measurable impact; accelerated decision-making, leaner processes and stronger financial outcomes. When markets move at digital speed, standing still means falling behind. Here’s why: So, the question isn’t “Should…





