Boston Scientific, the Marlborough-based medical device maker, needed roughly two weeks to fully restore manufacturing, order fulfillment and shipping after a cyberattack on August 25, 2026, even with a full internal security team and outside incident response firms on the job. If a company that size needed that long, a 20-person accounting firm or a dental practice in Quincy needs a written recovery plan in place before an attack happens, not during one.
- Boston Scientific detected the attack on August 25, 2026, and did not confirm full restoration of order and shipping systems until September 9, 2026, roughly two weeks later.
- Even a company with dedicated security staff and outside forensics help could not avoid a multi-week disruption to ordering and shipping.
- A written business continuity plan, not just backups, is what determines whether a small business reopens in days or closes for good.
- Vendors and suppliers to larger companies face their own exposure when a partner’s systems go down for weeks.
- Testing a recovery plan on paper, twice a year, catches gaps that only show up during a real outage.
What happened to Boston Scientific?
According to the company’s own public incident update, Boston Scientific detected the cyberattack on August 25, 2026, and immediately began containment. Independent security assessments found no evidence that product development systems, cloud platforms, or email were compromised, but manufacturing, order processing, and shipping were disrupted for weeks. Shipping for most products at major distribution centers did not resume until roughly a week in, and the company did not announce full restoration of manufacturing and order fulfillment until September 9, according to MedTech Dive’s coverage of the incident.
Why does a large company’s outage matter to a small Boston business?
Scale usually cuts the other way. A company with Boston Scientific’s resources has a security operations center, cyber insurance, and contracts with incident response firms on standby. A small business typically has none of that. If a well-resourced manufacturer needed two weeks, a business running on a single file server and no documented recovery process should assume its own outage would run longer, not shorter.
There’s also a supply chain angle worth noting locally. Verizon’s 2026 Data Breach Investigations Report found that ransomware was involved in 48% of confirmed breaches in its dataset, and that third parties or supply chain relationships now factor into a large share of incidents. Boston has a dense network of small vendors, medical suppliers, and professional service firms that work with larger regional employers. When one link in that chain goes dark, downstream businesses feel it in missed orders and delayed payments even if their own systems were never touched.
What should a business continuity plan actually include?
A business continuity plan is different from a backup policy. Backups protect your data. A continuity plan protects your ability to operate while systems are down: who calls customers, who authorizes a manual invoicing process, which vendor gets called first, and how employees keep working if the office network is offline. At minimum, the plan should name a decision-maker for the first 24 hours, list the systems that must come back first, and include contact information that isn’t stored only on the network you just lost access to. We built a free business continuity plan generator for exactly this reason: most small businesses have never written any of this down.
How fast could your business actually recover?
Ask three questions. First, if your primary server or cloud tenant went offline right now, who is the first call, and do they have a phone number that isn’t stored in your email? Second, how old is your last tested backup restore, not just your last backup? Third, what does a week of downtime cost in missed billing and lost customers? We wrote about the real dollar impact of unplanned outages in our piece on the true cost of downtime for Boston-area businesses, and the numbers tend to surprise owners who have never run the math.
Frequently asked questions
Do small businesses really need a formal business continuity plan?
Yes. Attackers don’t check company size before hitting a network, and a plan costs nothing to write beyond the time to sit down and document it. The businesses that recover fastest from an outage are almost always the ones that rehearsed the process before they needed it.
Isn’t a good backup enough?
No. A backup gets your data back. It doesn’t tell your staff who’s in charge during the outage, which vendor to call first, or how to keep taking orders while systems are down. Those decisions need to be written down ahead of time.
How often should a business continuity plan be reviewed?
At least twice a year, and after any major change to your systems, vendors, or staff. A plan that names an employee who left the company six months ago is not a plan you can rely on.
What’s the first step if we don’t have a plan at all?
Start by listing the systems your business cannot operate without for more than a day, then write down who is responsible for restoring each one and how to reach them without relying on the systems that might be down.
The Boston Scientific incident is a reminder that recovery time, not just prevention, decides how much an outage costs you. If your business has never tested how it would operate during a multi-day outage, that gap is worth closing before an attacker finds it for you. Boston Managed IT offers a free 15-minute Microsoft 365 and security review to help Boston-area businesses find that gap. Call (617) 322-5155 or visit bostonmit.com/contact to schedule one.
— Boston Managed IT