DRP and BCP
What is a BCP?
A business continuity plan (BCP) aims to keep essential services running during an outage, with an interruption short enough that users barely notice it. The standby is ready before the incident: you do not order it on the day the server goes down.
Updated October 20263 min read6 sources cited
Key points
- A company BCP covers premises, people, suppliers and IT; the IT component is only one part of it.
- On the IT side, it requires a second instance that is already being fed and a mechanism that sends traffic to it when the first stops responding.
- The point most often forgotten: switching back to the original server without losing the data entered on the standby.
- A BCP deals with outages; it does not remove the need for a backup with version history against ransomware and deletion.
A reference definition
The ISO 22301 standard defines business continuity as an organisation’s capability to continue delivering products and services within acceptable timeframes at a predefined level during a disruption. The BCP brings together the measures that ensure this, temporarily in degraded mode if necessary, then the planned resumption of activities. Two ideas stand out: you accept a reduced service, and continuity includes recovery.
NIST likewise distinguishes the continuity plan, which sustains business processes during and after the disruption, from the recovery plan, which focuses on restarting systems. ISO 22301 is also the international reference standard for a business continuity management system.
Business continuity, not just IT continuity
A company’s BCP goes beyond servers: premises, people, suppliers, telephony, the ability to invoice. The IT component is only one part of it. This page deals with that component. A perfect IT BCP will not save a business where nobody knows how to take a customer’s payment any more.
How the IT standby is built
- A copy of the critical systems runs, or is kept up to date, in another location.
- Something monitors production (an agent, a load balancer, an address witness).
- In the event of a clear failure, traffic fails over. Workstations keep calling the same address, or a standby address that is already known.
- When the original comes back, you fail back in the opposite direction, without losing the data entered on the standby in the meantime. This point is the one most often forgotten, and it is what makes BCPs fail on paper.
The cost is permanent: you pay for the standby on the days when everything is fine. That is the price of a takeover in minutes rather than hours. The details are in How much does a BCP cost?.
What a BCP requires of applications
- A possible network failover (same IP address on site, or DNS with an accepted propagation delay).
- Consistent data on the standby. A database copied in the middle of a transaction may start and still be wrong.
- Licences that allow running on the standby.
- Enough bandwidth between the site and the standby for remote users to work.
- A person authorised to declare ‘this is an outage’, to avoid phantom failovers. CERT-MU’s incident handling guideline places this preparation of roles before any incident.
- A level of security maintained in degraded mode: the appropriate security measures required by section 31 of the Data Protection Act 2017 also apply to the standby.
If any of these points is missing, the advertised BCP is in fact a DRP: you will be able to restart, later.
BCP and backup
A BCP does not remove the need for backup. The standby can also be compromised if replication is too faithful and too fast (it copies the ransomware). The backup history, ideally immutable, remains the way back to a clean state. The BCP deals with outages. Backup deals with corruption and deletion.
For ransomware, CERT-MU, Mauritius’s national incident response team, publishes a dedicated guideline; the principle remains to activate the business continuity and disaster recovery plans, then restore data from a backup taken before the attack. The two tools work together: see Ransomware has just been triggered.
At WeDoBack
The WeDoBack BCP keeps cloud instances running permanently. An agent installed on the customer’s network handles the takeover by these instances over an IPsec VPN, with no change of IP address: users do not reconfigure their workstations. When the original server has been repaired, the agent can hand traffic back to it. Replication or synchronisation of data between the BCP instance and the original server is not supported natively: it requires a specific process, defined according to need (database, files, business application), including carrying over to the repaired server the data entered on the instance during the incident. WeDoBack can set this up on quotation. Storage starts at €8.75 excl. VAT per month for 50 GB (i.e. €175 excl. VAT per TB), and instances at €50.22 excl. VAT per month, plus one agent per server. These amounts run permanently, even when there is no incident. Copies are encrypted on the machine before they are sent and stored on dedicated servers, separate from production. Endpoint control and anti-ransomware tools are included, as with the DRP; automated vulnerability remediation remains a paid option.
Frequently asked questions
Is a BCP more expensive than a DRP?
Generally yes, on a monthly basis: the standby instances run permanently, whether or not there is an incident. That is the price of a takeover in minutes rather than hours. NIST also ranks ‘hot’ standby sites, ready immediately, as the most expensive.
Does a BCP protect against ransomware?
Not on its own. If replication to the standby is fast and faithful, it may copy files that are already encrypted. You need to keep a backup with version history, ideally immutable, to return to a version from before the attack.
Should every server be covered by a BCP?
Rarely. A BCP is reserved for services whose downtime, even brief, costs more than a permanent standby. The other servers are covered by a DRP or a well-tested backup.
Sources
Documents consulted in October 2026.
- Guideline on Incident Handling — CERT-MU (Mauritius)
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- ISO 22301 – Business continuity — ISO
- Introductory Guide to the Data Protection Act 2017 — Data Protection Office (Mauritius)
- Guideline on Ransomware Removal — CERT-MU (Mauritius)
- BCP offer: immediate business continuity — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
