SMALL BUSINESS MASTERY
Most businesses prepare for emergencies by buying insurance, backing up a few files and assuming somebody will figure out the rest. That is not a continuity plan. That is optimism with paperwork.
THE PULSE
1. One in four small businesses never reopen after a major disaster.
The U.S. Small Business Administration says roughly 25% of small businesses do not reopen after a major disaster. Its guidance is straightforward: assess your risks, create an accessible response plan, protect critical records, identify backup suppliers and practice the plan before you need it. Source: U.S. Small Business Administration.
What it means for you: Recovery is not something you improvise after the water is already coming through the ceiling. The companies that recover faster have already decided what happens next.
2. Your biggest disruption may never touch your building.
Verizon's 2026 Data Breach Investigations Report found that 48% of breaches now involve ransomware and 31% begin with exploitation of software vulnerabilities. Its SMB analysis covered more than 7,000 confirmed small-business data breaches. Source: Verizon 2026 DBIR.
What it means for you: A disaster does not need smoke, floodwater or a hurricane warning. Your building can be perfectly intact while your company loses access to the systems it needs to manufacture, invoice, communicate, schedule and get paid.
3. Even large companies can lose operations when one system goes down.
Boston Scientific disclosed that an August 25 cybersecurity incident disrupted manufacturing, order processing and shipping globally. The company restored those operations, but said the disruption was likely to materially affect its third-quarter and full-year 2026 results. Source: Boston Scientific.
What it means for you: If a company with dedicated cybersecurity teams, outside experts and enormous resources can have operations interrupted, "we have an IT guy" is not a continuity strategy.
The emergency is not the problem. The scramble is.
Most owners think about business risk in terms of prevention. Prevent the fire. Prevent the cyberattack. Prevent the key employee from leaving. Prevent the server from failing.
Prevention matters. But there is a problem with building your entire risk strategy around it, eventually, something gets through.
A storm closes the building, your CRM goes down, a supplier misses a critical delivery, your payroll person gets sick the morning payroll has to run.
The operational question is not whether you can prevent every disruption, you can't. The question is whether the business knows how to operate when the normal way of operating suddenly disappears.
In a lot of small businesses, the contingency plan quietly revolves around the owner. Critical information lives in their head, important decisions wait for their approval, and the team instinctively looks to them when something goes wrong.
That dependence is easy to overlook during normal operations. A real disruption exposes it quickly, especially when the owner is unavailable, overwhelmed, or dealing with the emergency themselves.
THE VERDICT: a real disruption, graded.
The situation
Boston Scientific identified a cybersecurity incident on August 25 that took certain IT systems offline and disrupted manufacturing, order processing and shipping. By September 9, the company reported that its core operations had been restored and that products were moving through its distribution network at or above normal levels.
The company also warned that the disruption was expected to have a material impact on its third-quarter and full-year financial results, which shows how quickly a technology problem can spread into the rest of an organization.
My verdict
The most important part of this story is how far the disruption traveled once critical systems became unavailable. What began as a cybersecurity incident interfered with the company's ability to manufacture products, process orders and manage shipments, eventually creating consequences significant enough to affect its financial outlook.
For business owners, that progression is worth paying attention to because operational disruptions rarely stay contained within the department where they begin. A problem with technology can become a customer-service problem, a production problem, a cash-flow problem and eventually a financial-performance problem when the company does not have effective ways to keep critical work moving.
Why most people are reading it wrong
Cybersecurity incidents are often discussed primarily as technology problems, which can lead business owners to assume that responsibility begins and ends with whoever manages their IT systems. That view misses the larger operational risk created when employees suddenly lose access to the systems they depend on to perform essential work.
Once an outage begins affecting production, scheduling, customer communication, order fulfillment, invoicing or payroll, the organization is dealing with a business continuity problem. Technology may have caused the disruption, but the company's operating systems determine how effectively the business functions while the technology is unavailable.
Your version
Most small businesses do not operate global manufacturing facilities, but they often have their own critical dependencies concentrated in surprisingly few places. Your company might rely heavily on access to QuickBooks, an estimator who understands how every job is priced, a primary supplier that provides an essential material, one employee who knows how to process payroll, or an owner who still approves most consequential decisions.
Those dependencies tend to disappear into the background while everything is working normally, which makes them easy to underestimate. A disruption exposes them by revealing exactly how much of the business depends on a particular person, system, vendor or piece of equipment remaining available.
That is the operational lesson from Boston Scientific that applies to a company of almost any size. The scale of the disruption may be different, but every business needs to know where its critical dependencies are and how essential work will continue when one of them suddenly becomes unavailable.
Build the plan around what must keep moving.
Forget the 40-page emergency binder for a minute. Start with five questions.
1.) What are the five activities that absolutely must continue for us to serve customers and protect cash?
2.) What person, system, vendor or piece of equipment can stop each one?
3.) If that dependency disappeared tomorrow morning, what is our temporary workaround?
4.) Who has authority to activate that workaround without waiting for the owner?
5.) When did we last test whether the workaround actually works?
That last question is where plans become real.
A continuity plan only becomes useful once you know the alternatives inside it actually work. Having data backed up provides little protection if nobody has tested whether that data can be restored quickly enough to keep the business operating. Listing a secondary supplier does not provide much security if you have never confirmed their capacity, lead times, pricing or ability to deliver what your company needs during a disruption. The same problem applies to emergency procedures that employees have read but never practiced under realistic conditions.
Effective business continuity requires more than documenting what the company intends to do. The alternatives need to be tested, employees need to understand their responsibilities, and the people closest to the situation need enough authority to make necessary decisions when normal systems and processes are unavailable. Testing those plans before an emergency also exposes weaknesses while there is still time to correct them, rather than discovering those weaknesses when the business is already under pressure.
THIS WEEK'S MOVE
Choose one process your business cannot afford to lose for more than a day. It might be scheduling, payroll, estimating, customer communication, order fulfillment or another function that directly affects your ability to operate and generate revenue.
Bring the people responsible for that process together and ask them a simple question: “It is 10:17 tomorrow morning and this system, person or resource is suddenly unavailable. How do we keep the business moving?”
Pay attention to how specific the answers are. Your team should know who takes ownership, what alternative process they will use, what information they need, who has decision-making authority and how customers or employees will be affected. Any part of the response that depends on “we would figure it out” deserves more work.
Once you have an alternative, test it. A continuity plan should give your team enough clarity to keep essential work moving without waiting for the owner to invent the response in the middle of the disruption.
The goal is not to anticipate every emergency your business could face. The goal is to build an organization that can absorb a disruption, make good decisions under pressure and continue operating when the plan for a normal day no longer applies.
Best,
Micah
THE BROWN BOX
The Brown Box is out now, and Realign Staff and Roles is chapter seven of the TURNAROUND method for exactly this reason. Hiring feels like progress because headcount is a number you can point to. Role clarity doesn't show up on a spreadsheet the same way, so it's the fix most owners skip, right up until it's the reason they can't stop hiring. That's the chapter that walks through how to fix the role before you fix the roster.
Grab your copy → https://www.amazon.com/dp/B0H2X4Z85W
Already read it? A two-line review does more for this book than almost anything else you could do for me. Hit reply once it's up, I read every one.