DRP and BCP
How do you test a DRP?
You test a DRP by trying to work on the standby system, not by rereading the document. The weakest test is a meeting; the strongest is a real failover with users, followed by a failback. In between, a series of levels lets you make progress without shutting the company down every time.
Updated October 20264 min read6 sources cited
Key points
- Level A, tabletop test: is the document still accurate? Two to three hours, without touching the technology.
- Level B, isolated restore: does the standby system start and does the application open, without cutting production?
- Level C, real failover: the only one that measures the RTO and tests the failback.
- An automatic boot check is useful, but it does not prove that the business can work.
- Every test produces a dated report: times, gaps, decisions.
What the frameworks say
Business continuity frameworks recommend three complementary approaches: having the documents reviewed, ideally by a trusted third party; testing how the arrangements are implemented, for example by failing over certain functions to a backup site; and finally checking, through exercises, that procedures are known, understood and can be applied within the planned time. In Mauritius, CERT-MU, in its guideline on devising a backup plan, recommends an off-site copy and regular restore tests. ANSSI, France’s national cybersecurity agency, requires in its guide on backup that a procedure for restoring the information system be written and regularly carried out.
NIST distinguishes two forms of exercise. A tabletop exercise is a discussion in which everyone describes their role in response to a scenario. A functional exercise has people perform the actual steps in a simulated environment. The three levels below follow this progression.
Level A. Tabletop test
The people named in the plan walk through the steps out loud, with their phones in front of them. You check that the numbers answer, that the key can be found, that the server order is still correct. Duration: for a tabletop cyber crisis exercise, ANSSI allows two to three hours, including briefing and debriefing, and about six weeks of preparation; NIST mentions two to eight hours depending on the objectives. Minimum frequency: after every departure of a key person. This level proves nothing about the technology. It proves that the document is still accurate.
Level B. Isolated technical restore
You restore or start the standby system without cutting production. You log in. You open the application. You record the time from the decision to the business screen. Real users are not switched over. This is the test that reveals a missing disk, a licence, a password, a closed network.
Limitation: since production was not cut, you have not proven the failover step itself (DNS, IP, agent) or the failback.
Level C. Real failover, in an announced time slot
One evening or on a Sunday, production is stopped or traffic is sent to the standby system. A few users carry out a genuine business task: edit a document, check off an order, read a file. Then you fail back and check that the data entered on the standby system has not been lost.
This is the only level that measures the RTO and tests the failback. It is planned, it is communicated, and it has a stop criterion (“if the standby system is not up by 11 pm, we cancel”).
| Level | What it proves | What it does not prove | Impact on production |
|---|---|---|---|
| A. Tabletop | The document, the contacts, the roles | That the technology works | None |
| B. Isolated restore | That the standby system starts and the application opens | The network failover and the failback | None |
| C. Real failover | The actual RTO, business work, the failback | — | Announced time slot |
Checklist before level C
- Date and time slot approved by management, users informed.
- Last successful backup verified, encryption key at hand.
- Stop criterion written down, with the deadline and the person who decides.
- One business user per application tested, with a specific task to perform.
- Failback procedure reviewed, and production backed up just before.
- One person in charge of recording times and gaps as they happen.
What the report must contain
Date, level, participants, start time, time at which the business task succeeded, gaps, decisions. A sentence such as “test OK” is useless six months later. NIST calls this document an after-action report: it records the observations and recommendations for improving the plan. ANSSI treats lessons learned as a stage in its own right in every exercise.
What an automatic boot test proves, and does not prove
Some services start the copies every month and check that they boot. This is useful: an image that no longer boots is detected without disturbing production. It is not a level C test. The application may be broken, the database inconsistent, the failover network untested, the failback unknown. Presenting this check as “the DRP is tested” is inaccurate. The correct statement is: “image boot is checked; the business failover is not yet”.
At WeDoBack
The monthly test included in the DRP belongs to this last category: an automatic procedure starts the stored instances and reads their boot screen, without touching production. Testing under real conditions, which corresponds to level C or an extended level B, is offered for up to ten hours and is subject to a quote. Both have a role. Neither replaces the other. Human support is available from 9 am to 1 pm and from 2 pm to 5:30 pm (Paris time, i.e. from 11 am to 3 pm and from 4 pm to 7:30 pm Mauritius time during European summer time, one hour later during European winter time), on +33 9 72 50 78 28: a real test is scheduled within these hours, or explicitly planned outside them.
Frequently asked questions
Can a DRP be tested without stopping production?
Yes, for levels A and B: the tabletop test and the restore into an isolated environment do not touch production. Only the real failover (level C) requires an announced time slot, an evening or a weekend, with a stop criterion defined in advance.
Who should take part in the test?
The people named in the plan: the person who decides to fail over, the administrator, the holder of the encryption key, and at least one business user able to check that they can actually work. Without a business user, you are testing IT, not business recovery.
What should you do if the test fails?
That is the point of a test: finding what does not work before a disaster. Record the gap, fix it, and schedule a new trial on that point. Both NIST and ANSSI, France’s national cybersecurity agency, stress lessons learned, which turn failure into an improvement of the plan.
Sources
Documents consulted in October 2026.
- SP 800-84, Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities (September 2006) — NIST
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Organising a cyber crisis management exercise (in French) — ANSSI
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI
- DRP offer: disaster recovery — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
