IT continuity answers one simple question: if your IT stops today at 9am — server failure, ransomware, fire, outage — how long before your SME works again, and how much data has it lost? In 2026, the answer rests on four pillars: genuinely tested backups, quantified recovery objectives (RTO/RPO), redundancy on critical elements and a written plan that someone other than your IT person can execute. Here is how to put them in place at the scale of an SME.
What actually stops SMEs
The scenarios that immobilise an SME are not exotic: a server dying on a Monday morning, ransomware encrypting the shared files overnight — the Swiss NCSC records a steady increase among SMEs, as detailed in our 2026 cybersecurity guide —, water damage in the server room, a prolonged Internet outage when the whole business runs through the cloud, or the departure of the only person who knew the passwords.
What these scenarios have in common: their cost does not come from the repair, but from the stoppage. Salaries paid without production, lost orders, disappointed clients, overtime to catch up. For a 20-person SME, a complete ransomware incident frequently exceeds CHF 50,000 — without even paying a ransom.
Pillar 1: backups that actually restore
The 3-2-1 rule remains the standard: three copies of your data, on two different media, one of them off-site — physically separated from your offices, and out of reach of ransomware that would encrypt everything it touches. Do not forget cloud data: Microsoft 365 does not back up your data in the true sense, as explained in our article on managing Microsoft 365.
Pillar 2: quantified objectives (RTO and RPO)
Two figures dimension your whole strategy. The RTO — how fast must we be working again? — and the RPO — how many hours of work can we afford to lose? These figures belong to management, not to IT: they are a trade-off between cost and risk. Tolerating 24 hours of stoppage costs little; demanding 2 hours requires redundancy. The classic mistake is never asking the question and discovering the implicit trade-off on the day of the failure.
Pillar 3: redundancy of critical elements
Hunt for single points of failure: the server without virtualisation, the single Internet link when the whole business runs through the cloud, the backup NAS sitting next to the server it backs up, the single person holding the credentials. Each critical point calls for a proportionate response: a backup 4G/5G Internet link (a few dozen francs per month), a virtualised server restorable on other hardware, credentials documented in a shared vault.
Pillar 4: a written, executable plan
On the day of the incident, stress is maximal and memory fails. The recovery plan fits in a few pages: the scenarios covered, who decides and who executes, step-by-step restoration procedures, contacts (provider, insurance, suppliers), and the restart order of the systems. Quality criterion: a competent person who does not know your company must be able to execute it. Test it once a year, in realistic conditions.
The role of the IT provider
Continuity is not a one-off project: backups must be monitored daily, tests run quarterly, documentation maintained at every change. That is typically what a serious managed IT contract includes by design — verified backups, monitoring and up-to-date documentation are part of the standard scope of AlpenCare. For the initial drafting of the plan or the upgrade of a fragile infrastructure, a one-off IT project with a documented deliverable is the right format. And if your ageing servers are themselves the risk, migrating to a Swiss cloud removes part of the problem at the source.
Frequently asked questions
What is IT continuity for an SME?
The ability to keep working when IT breaks: server failure, ransomware, fire, prolonged outage, or the departure of the only person who knew the systems. Concretely, it rests on tested backups, a written recovery plan with quantified objectives (RTO/RPO), redundancy on critical elements and up-to-date documentation.
What is the difference between RTO and RPO?
RTO (Recovery Time Objective) is the maximum acceptable time to restart after an incident: 'we must be able to work again within 4 hours'. RPO (Recovery Point Objective) is the maximum amount of data you accept to lose: 'at worst, the last 24 hours of work'. These two figures, set by management, dimension the whole continuity strategy — and its budget.
Is a backup enough to ensure continuity?
No. A backup protects the data, not the activity: if your server burns, restoring the data is useless without replacement hardware, without documentation to rebuild the systems and without a plan that says who does what. Backup is the foundation of continuity, not continuity itself.
How much does an IT continuity plan cost for an SME?
For an SME of 20 to 50 people: off-site backup costs CHF 50 to 150/month, redundancy of critical elements (second Internet link, virtualisation) a few hundred francs per month, and drafting the documented recovery plan CHF 2,000 to 6,000 as a one-off service. Compare with the cost of a stoppage: several days of inactivity quickly exceed CHF 50,000.
How often should you test your continuity plan?
A data restoration at least quarterly, and a full-scenario test (rebuilding a critical server, switching to the backup link) once a year. A plan that was never tested is a hypothesis, not a plan: it is precisely during tests that you discover the missing password, the incomplete backup or the obsolete procedure.
Written by
David Cunha
Co-founder · Technical director, AlpenData
A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.
More about AlpenData →