What is the smallest useful continuity runbook?

A useful runbook lets a qualified responder stabilise operations without guessing. Start with one scenario: the primary owner of a critical service is unreachable for a defined period. Name the service, the business impact, the people who may respond, and the point at which the continuity procedure begins.

The runbook should open with a one-page first-hour checklist. Put verification before mutation: confirm the owner is genuinely unavailable, identify any active security incident, check system health, preserve logs, and notify the designated business owner. Avoid instructions such as “log in and change everything” without a decision gate; indiscriminate changes can turn an absence into an outage.

What should the runbook contain?

Use five short sections:

  1. Scope: the systems, accounts, data, and vendors covered.
  2. Activation: who confirms the event and when the procedure starts.
  3. Access path: where controlled recovery material is held and how its use is recorded.
  4. Stabilisation: health checks, communications, backup verification, and immediate customer obligations.
  5. Recovery and close-out: credential rotation, access review, evidence preservation, and lessons learned.

List dependencies in the order responders will encounter them: identity provider, email, DNS, cloud control plane, source repository, deployment platform, database, monitoring, payments, support, and key vendors. Do not place a live secret in a diagram or ticket merely because the runbook mentions it.

How does this relate to formal contingency planning?

The runbook is one operational component, not the whole continuity program. NIST SP 800-34 Rev. 1 describes contingency planning as coordinated preparation for recovering information systems and operations after disruption. Organisations may also have incident response, disaster recovery, crisis communication, succession, insurance, and legal obligations.

Map the ZeroLatch delivery to those existing documents. Record an owner and review date. Run a tabletop exercise before relying on it. The goal is a tested bridge between “the key person is unavailable” and the organisation's established response process—not a parallel process that nobody else knows exists.