How to Write a Business Continuity Plan for Schools

How to Write a Business Continuity Plan for Schools

A burst pipe over the summer holidays, a ransomware attack on your MIS, a flu outbreak that keeps a third of your staff at home. None of these wait for a convenient time, and none of them care whether you’ve got a plan ready. A business continuity plan for schools is what separates a two-day disruption from a two-week crisis that lands on the front page of the local paper and in a difficult conversation with the DfE or your local authority.

If you’re searching for how to actually build one, you want less theory and more structure: what to include, how to prioritise critical functions like exams administration and safeguarding records, and how to test the plan so it works when you need it. This guide walks through each step in order, so you finish with a working document rather than a folder of good intentions.

We’ll cover risk assessment specific to school settings, data and IT recovery priorities, communication plans for parents and staff, and how to build in review cycles so the plan stays current. We work with schools on incident response and recovery daily, and this guide reflects what actually gets tested when things go wrong, not just what looks good in an audit.

youtube placeholder image

Why schools need a business continuity plan

Schools sit on a unique concentration of risk that most businesses never face. You’re responsible for the safety of hundreds of children during the school day, you hold sensitive safeguarding records that can’t simply be recreated, and you’re bound to statutory deadlines like exam boards and Ofsted inspections that don’t move because your server room flooded. A school business continuity plan turns that exposure into something manageable, giving staff a clear playbook instead of a scramble when disruption hits.

Governors and trustees are also under growing pressure to demonstrate that this planning exists. Local authorities and academy trusts increasingly ask for evidence of a business continuity plan for schools as part of risk audits, and insurers now routinely check for one before renewing cover. Without a plan, a single incident, whether that’s a cyber attack on your MIS or a burst pipe over half term, can escalate into weeks of disrupted teaching, lost data, and reputational damage that outlasts the original event.

The risks worth planning for tend to repeat across the sector:

  • Fire, flood, or structural damage to buildings
  • Cyber attacks and ransomware affecting pupil data or the MIS
  • Extreme weather closures and travel disruption
  • Staff shortages from illness or industrial action
  • Safeguarding data breaches or loss of critical records
  • Utility failures, including power and heating outages

A school without a continuity plan isn’t gambling on if something goes wrong, only on when.

Getting this right isn’t about producing a document for the shelf. It’s about giving your senior leadership team the confidence to make fast, sound decisions under pressure, and giving parents and staff the reassurance that someone is in control even on the worst day of the school year.

Step 1. Identify critical services and risks

Start by listing every function your school couldn’t operate without: teaching delivery, exam administration, safeguarding record access, catering, transport, and payroll. For each one, ask how long you could survive without it before pupils, staff, or statutory duties are affected. This exercise, often called a business impact analysis exercise, gives you the priority order that shapes everything else in your plan.

A school office desk with a locked filing cabinet and a server rack beside a wall clock.

Next, map the risks most likely to hit those services, following the same cyber risk assessment steps you would use for any other threat. Don’t just copy a generic list from another sector; think about what’s actually plausible for your site, your buildings, and your local area.

Critical service Realistic threat Maximum tolerable downtime
MIS and pupil records Ransomware or server failure Under 24 hours
Safeguarding files Data breach or fire Immediate
Exam administration Staff absence or IT outage A few hours
Building access Flood, fire, structural damage 1-3 days

If you don’t know your maximum tolerable downtime, you don’t yet have a plan, just a list of worries.

This step also flags gaps early, such as safeguarding data with no offsite backup, before they become the incident itself.

Step 2. Assign roles, responsibilities and triggers

Once you know what matters most, decide who acts when things go wrong. A plan without named owners just creates confusion at the worst possible moment, with everyone assuming someone else has picked up the phone. Build a response team with clear incident response roles and responsibilities: a plan owner (usually the headteacher or business manager), a communications lead, an IT and data lead, and a site or facilities lead.

A hub diagram showing the plan owner at the centre connected to comms, IT, and site leads.

Set clear activation triggers

Don’t leave activation to judgement calls made under pressure. Write down the specific conditions that trigger the plan, such as:

  • Building inaccessible for more than half a day
  • Confirmed cyber incident affecting the MIS or safeguarding systems
  • Staff absence above a set threshold, for example 25% off in one day
  • Formal notice from the fire service, police, or utility provider

A plan only works if everyone knows the exact moment to use it.

Build a role and contact table

Role Who Primary responsibility
Plan owner Headteacher/Business manager Declares the incident, authorises decisions
Comms lead Office manager Parent, staff, and press updates
IT lead IT manager/provider System recovery, data restoration
Site lead Site manager Building safety, access, contractors

Keep this table current; a business continuity plan for schools with outdated contact details is little better than no plan at all.

Step 3. Write your response and recovery procedures

With roles and triggers set, write down exactly what happens in the first hour, first day, and first week of an incident. Vague instructions like "assess the situation" are useless under pressure. Your response procedures need to read like a checklist for responding to an incident that someone can follow even if they’ve never opened the plan before.

First-hour actions

  • Confirm the incident and notify the plan owner
  • Activate the response team and comms lead
  • Isolate affected systems (for cyber incidents, disconnect the network before anything else)
  • Contact emergency services or your IT provider as needed

The first hour decides whether you’re managing an incident or reacting to one.

Recovery procedures

For each critical service identified in Step 1, write the specific recovery steps: where backups are stored, who holds the keys to alternative premises, and how you’ll communicate closures to parents, ideally using pre-written incident communications drafted in advance. A school business continuity plan should specify recovery time targets, not just intentions, so link each procedure back to the maximum tolerable downtime you set earlier.

Don’t forget data recovery specifically. Note where MIS backups sit, how often they run, and who can restore them, since safeguarding records and pupil data are usually the hardest thing to recreate from scratch.

Step 4. Test, exercise and keep the plan current

A plan that sits in a drawer is worse than useless because it gives false confidence. Test the plan with a tabletop exercise at least once a year, walking the response team through a realistic scenario, such as a ransomware attack the night before exam week, and see where the plan breaks down. You’ll usually find gaps in contact details, unclear triggers, or recovery steps nobody actually tested.

Staff members sitting around a table with notepads and a whiteboard during a practice drill.

Build a review cycle

Schedule reviews around fixed points, not vague good intentions:

  • After every real incident, however minor
  • Annually, alongside your risk register update
  • Whenever staff roles named in the plan change
  • After any change to IT systems, buildings, or suppliers

A business continuity plan for schools only earns its keep if it’s tested before you need it, not during.

Get outside eyes on it

Internal reviews miss things because you’re too close to your own systems. An external audit, or a walkthrough with a cybersecurity partner, will spot weaknesses your senior leadership team won’t see, particularly around data recovery and MIS resilience. Treat this step as ongoing maintenance, not a one-off project you tick off and forget.

Keeping your school prepared for disruption

A finished plan isn’t the end goal, it’s the starting point for how your school handles the next disruption with confidence instead of panic. You now have a structure: identify what matters, assign clear ownership, write procedures people can actually follow, and test everything before a real incident forces the question. Schools that treat this as ongoing maintenance, not a one-off document, are the ones that recover in days rather than weeks when something goes wrong.

Getting a business continuity plan for schools right takes more than a template, though, especially around data recovery, MIS resilience, and safeguarding record protection. That’s where specialist support pays for itself, catching gaps your senior leadership team won’t spot from the inside. If you’d rather have experienced hands review your plan, test it properly, or step in when an incident actually hits, talk to TrustedIA about round-the-clock cyber incident response and business continuity support before you need it, not during.