Every year, Pakistani businesses lose weeks to disruptions that everybody knew were coming. Water reaches a warehouse. The grid goes down for longer than the generator was sized for. Connectivity drops in a region and a delivery team cannot be dispatched. A road closure strands stock between a supplier and a customer.
The striking part is not the disruption. It is that each one is handled as an emergency by businesses that have been through the same thing before. The knowledge exists; it just lives in people's memories rather than in a document, so every event costs the full price again.
A continuity plan is not a corporate document with an appendix. For a business of five to two hundred people it is one page, it takes an afternoon to write, and it is the highest return per hour of any operational work we do with clients.
One standing note. Nothing below is a forecast, and no dates or figures appear. For actual warnings and current conditions use the primary sources: the National Disaster Management Authority, the Pakistan Meteorological Department and your provincial disaster management authority. Put those links somewhere your operations lead checks, not somewhere you will look after an event.
The short version
- Plan by consequence, not by cause. You do not need a flood plan, a grid plan and an internet plan. You need a plan for "we cannot reach the premises", "we have no power", "we have no connectivity" and "goods cannot move".
- One page, four scenarios, named people, phone numbers. Anything longer will not be read at the moment it is needed.
- Your data should already be somewhere else. This is the cheapest control and the one most commonly missing.
- Cash is the real constraint. Most businesses that fail after a disruption fail on cash weeks later, not on the day.
- Tell customers early and specifically. Silence costs more relationships than the delay does.
The four consequences worth planning for
Skip the hazard list. Work backwards from what actually stops.
1. Nobody can reach the premises
Flooding, a road closure, civil disruption, a security incident. The questions are the same in each case.
- Which roles can work from elsewhere today, without anyone setting anything up?
- Who holds the keys, and who is the backup when that person cannot travel?
- What is physically in the building that the business cannot operate without, and why is it still only there?
- How do you account for staff safety and confirm everyone is accounted for?
The last point comes first in practice. Have a roll-call method, usually a group message with a required reply, and a named person who runs it.
2. No power, for longer than you planned
Every business has a generator or an inverter story, and most of those stories involve discovering the actual runtime during the outage.
- How long does your backup genuinely run under load, tested, not per the specification?
- What is on it? Servers, lights and the payment terminal matter more than air conditioning.
- Where does the fuel come from when a wider outage means everyone else wants fuel too?
- If you run solar, do you know what happens to your load when the grid is down rather than merely expensive? That is a different question from the economics, which we covered in solar and net metering for business.
3. No connectivity
For any business with an online storefront, a dialler, a cloud accounting system or a remote team, this is the outage that stops everything at once.
- Is your backup on a genuinely different network, or a second connection from the same infrastructure?
- Can staff work from mobile data, and is there a policy that pays for it rather than making people quietly absorb it?
- What is the manual fallback for taking an order, recording a sale or dispatching a delivery on paper, and does anyone under two years of service know it exists?
- If you run a call centre, latency and uptime are commercial variables rather than IT ones, which is the argument in starting a call centre in Pakistan.
4. Goods cannot move
- Which single supplier would stop you, and is there a second one you have ever actually bought from?
- How much stock is sitting in one location, and what would it cost to hold some elsewhere?
- What do you tell a customer whose order is stuck, and after how long?
- Is your stock insured for the way it is actually stored right now?
The one-page plan
Write this, print it, and give a copy to everyone who might have to use it. It is deliberately not a document management project.
| Section | What goes in it |
|---|---|
| Who decides | One name, one deputy, with the authority to close a site or stop dispatch without calling a meeting |
| How we reach each other | A channel that works on mobile data, plus phone numbers on paper. Not only the office email |
| Roll call | Who runs it, how people confirm they are safe, how long before escalation |
| Work from elsewhere | Which roles, what they need, tested at least once |
| Power | Runtime under load, what is on backup, fuel source |
| Connectivity | Backup connection, and the paper fallback for orders and dispatch |
| Data | Where the backup is, who can restore it, when it was last tested |
| Customers | Who tells them, within how long, in what words |
| Money | Who can authorise payments if the usual person is unreachable, and the callback rule that still applies |
| Restart | The order in which things come back on, and who confirms each one |
Two lines on each. If it does not fit on a page, it will not be used.
The two controls that matter most
Data that already lives somewhere else. Cloud accounting, cloud file storage, a database backup in a different location, and a restore you have actually tested. Untested backups fail at roughly the rate you would expect from something nobody has ever checked. A business that loses its records loses its receivables, which is the loss it usually does not recover from. This sits alongside the wider baseline in cybersecurity for growing businesses.
A cash buffer and a current forecast. The pattern is consistent: the disruption interrupts revenue, costs continue, receivables slip because your customers were disrupted too, and the failure arrives six to ten weeks later looking like a cash problem rather than a flood. Know your fixed monthly cost, know how many weeks of it you hold, and maintain a thirteen-week cash flow forecast. During an event, the forecast is the document you run the business from.
One addition that costs nothing: during a disruption, the fraud attempts increase, because urgency and broken routine are exactly the conditions payment fraud needs. The payment callback rule does not get suspended because the building is flooded. That is precisely when it matters, and we set out the rest of it in deepfake payment fraud controls.
What to say to customers
Early, specific, and once per change rather than continuously.
Say what happened in one sentence, what it means for their order or service, when you will next update them, and what you are doing. Do not promise a recovery date you are guessing at; give the next update time instead and then hit it.
Customers forgive disruption, particularly in a market where everyone understands the conditions. What they do not forgive is finding out from someone else, or being told a date three times that does not happen. Exporters have a sharper version of this problem because the buyer is far away and has other options, which we covered in how to export from Pakistan.
Frequently asked questions
We are a small business. Is this really worth the time?
It is an afternoon, once, reviewed annually. Compare that to a single week of stopped trading, which is the normal cost of not having it. Small businesses benefit more than large ones, because they have less slack to absorb a surprise.
How often should we review it?
Once a year, and after any real event while the details are fresh. The post-event review is the valuable one, and the honest question is short: what did we not know that we needed to know.
Should we buy business interruption insurance?
Get a quote and read the exclusions carefully, particularly around flood and around the way your stock is actually stored. Insurance is a useful transfer of some risk and is not a substitute for the plan, because the plan is what determines how much you lose before any policy responds.
What is the single most common gap you find?
Untested backups, followed closely by a generator whose real runtime nobody has measured. Both are discovered at the worst possible moment and both are checkable this week.
Where to go next
If you want this written properly, tested, and turned into something your team will actually use during an event rather than after it, that is standard business operations consulting work and it is usually a short engagement. For businesses where the exposure is mostly in moving goods, the sector view is logistics and supply chain. If you would like it looked at before the next season, talk to us.