Skip to content
Skip to article text

Business Emergency Plan: What to Do When Payment or Your Order System Is Down for 48 Hours

SME leadership and IT lead reviewing an emergency plan for payment failure and order system outage on a laptop in the office

What really happens in 48 hours — beyond "IT is down"

When payment or the order system fails, many think of technology first. In the first 48 hours several damages run in parallel:

  • Lost revenue: No checkout, no card payment, no automatic invoicing — daily revenue drops close to zero while fixed costs continue.
  • Open orders: Customers paid or ordered, shipments wait in the queue — without clear handling you risk double bookings or forgotten orders.
  • Trust loss: A silent website or aborted checkout looks like insolvency to new customers — even when everything is under control internally.
  • Support overload: The team answers the same question a hundred times instead of escalating in a structured way.
  • Liquidity pressure: With a high online share, incoming payments stop immediately — a topic the cashflow analysis in risk management article covers in depth.

An emergency plan that only says "check the status page and wait" does not cover these follow-on damages.

Technical outage or account freeze — two different plans

Many companies confuse the two. In practice they are different crises:

Aspect Technical outage Account freeze / compliance review
Typical cause Hosting, API failure, network, DDoS Stripe review, bank compliance, policy violation, fraud suspicion
Typical duration Hours, rarely 1–2 days Days to weeks — no guaranteed timeline
What still works? Often back office, email, manual processing Often no access to the merchant dashboard at all
First action Activate backup payment, inform customers Gather documents, open support ticket, switch on parallel payment route
Communication "Technical issue, we are working on it" "Payment route temporarily limited — alternative options active"

Real-world example: On 22 July 2026 Shopify reported checkout errors for stores using the Stripe payment gateway — affected shops either saw no credit card form or processing errors. According to the status incident, the disruption lasted about two hours. That is a classic technical outage — short, but expensive at peak time.

An account freeze looks different: the dashboard is locked, payouts stop, support demands evidence — and revenue still stalls because customers cannot pay. You need a plan B that does not depend on the locked provider.

Five things that must be clear beforehand

Before anything happens, these five points should be written down — not only in the CEO's head:

  1. Backup payment route: Which alternative do you activate immediately (PayPal, bank transfer with manual confirmation, second payment provider, invoice purchase for existing customers)? Who holds the credentials — and are they stored outside the primary system?
  2. Decision-maker in hour one: Who may put the shop in maintenance mode, trigger refunds, or enable the backup route? Without a named role, three people decide in parallel — slowly and inconsistently.
  3. Customer communication: Ready text blocks for website banner, email reply, and social media — factual, no panic, with a concrete next step for the customer.
  4. Order handling: What happens to paid but unshipped orders? Who maintains an offline list when the ERP is unreachable?
  5. Liquidity buffer: How many days of fixed costs do reserves cover if no payments arrive? For a 48-hour worst case: daily revenue × 2 as a guide for euro valuation.

This list is not an ISO document — it is the core of a business emergency plan you can actually read in a crisis.

Mini role map: who decides in the first hour?

Role Task in hour 1 Backup
Crisis lead (CEO or delegate) Decide: maintenance mode yes/no, enable backup payment Name a deputy
Tech / IT Check status, contact provider, isolate if attack suspected External IT number on paper
Customer communication Banner, email template, social post — one channel, one voice Marketing or executive assistant
Finance Liquidity check, inform insurer if business interruption relevant Accountant / bookkeeper
Operations / orders List open orders, start manual processing Second person with ERP access

Backup matters — key-person risks hit emergency plans too when only one person knows all passwords.

What not to do in a crisis

These mistakes typically enlarge the damage:

  • Only watching the status page — activate backup route and inform customers in parallel.
  • Panic posts on social media — vague claims ("We were hacked!") without facts do more harm than the outage itself.
  • Refunds without a list — chaotic repayments without order overview create double payments.
  • Trying to fix everything alone — if a cyber attack is suspected: isolate and call experts (see Cyber attack — what to do?).
  • Reading the plan for the first time — if the emergency plan only lives in SharePoint and SharePoint is down, you have no plan.

How to estimate damage in euros

Risk management without a number is gut feeling. For payment outage a simple calculation is often enough:

Damage ≈ (daily revenue × outage days) + (support hours × hourly rate) + (estimated trust loss with key customers)

Example: €12,000 daily revenue, 2 days outage, 20 support hours at €45 → €24,900 direct and near-indirect damage — regardless of whether the company is "profitable" on paper.

That makes comparison easier: does a second payment provider cost €200 per month — or do you risk €25,000 in one weekend? The Beraterium method evaluates such scenarios in the hazard catalogue and prioritises measures by euro, not gut feeling.

Five-question checklist before the next peak season

Answer honestly — if more than two questions end with "No" or "Don't know", your emergency plan has gaps:

  1. Do we have a backup payment route we can activate in under 30 minutes?
  2. Are credentials and contact numbers (provider, IT, insurer) stored outside the primary system?
  3. Do we have text blocks for customers we can post without coordination?
  4. Does the team know who decides in hour one — and who acts as backup?
  5. Do we have liquidity for at least 14 days without expected incoming payments?

Blindspot Check: where your plan still has gaps

The checklist above is a start. The Blindspot Check goes further: it walks through typical what-if scenarios — payment freeze, website down, key person unavailable — and delivers a prioritised short report by email.

It does not replace a full SME risk analysis — but shows in minutes which blind spots you have not addressed yet. For digital dependencies (Shopify, Stripe, bank, ERP) the self-test is worth running before the next incident hits the news.

Conclusion: the first step this week

An emergency plan does not need 40 pages. It must exist before the crisis, be reachable outside the failed system, and pre-decide five things: backup payment, decision-maker, communication, orders, liquidity.

Concrete first step: Take 45 minutes, calculate your 48-hour revenue loss in euros, and agree with one person on the team who picks up the phone in hour one if payment fails. Then run the Blindspot Check — and note which question you could not answer.

If you want to see how payment, IT, and liquidity risks fit in one portfolio: In a free initial consultation we clarify in 30 minutes which three risks should top your list.

Note: This article is not legal, tax, or insurance advice. Beraterium is not a payment service provider or IT company — we structure risks and measures for businesses.

This text was created with AI assistance and editorially reviewed.

Frequently asked questions

What must a business emergency plan for an SME include?

A robust plan names: (1) critical processes without which the company cannot operate, (2) key people per process and their backups, (3) the communication chain in a crisis, and (4) immediate actions for likely scenarios — payment outage, account freeze, or ERP failure. Beraterium develops such plans as part of the measures roadmap — as a living tool, not a document to file away.

What is the difference between a technical outage and an account freeze?

In a technical outage (hosting, API, network), the service is temporarily unavailable — often hours, sometimes one to two days. In an account freeze (Stripe review, bank compliance, policy violation), the account stays locked until the provider releases it — that can take days to weeks. Both require different immediate actions and customer communication.

How long does a payment outage typically last?

Short disruptions at major platforms (Shopify, Stripe, PayPal) often last two to four hours — in July 2026 a Shopify-Stripe incident affected multiple shops for about two hours according to the status page. Account freezes have no fixed duration. Beraterium therefore plans internally for a 48-hour revenue standstill worst case plus separate planning for longer freezes.

Do I need an emergency plan if I only have a small team?

Especially then. In teams under ten people, roles are often unclear: Who decides in the first hour? Who talks to customers? Who activates the backup payment route? A written plan with three to five decision points is enough — it must exist before the crisis and be reachable outside the affected system.

What does 48 hours without working payment cost?

The formula is simple: average daily revenue × number of days plus indirect costs (refunds, support effort, trust loss with key customers). For an online shop with €15,000 daily revenue, 48 hours can mean €30,000 in lost sales — regardless of accounting profit. That is why Beraterium evaluates such scenarios in euros, not traffic-light colours.

How do I find blind spots my emergency plan still misses?

Beraterium's free Blindspot Check walks through typical what-if scenarios — from IT failure to payment freeze to key-person loss — and delivers a prioritised short report. It does not replace a full risk analysis but shows in minutes where your plan still has gaps.

Clarify risks in your business?

Book a free intro call – 30 minutes, no obligation.

Book a free intro call