DRP and BCP
DRP or BCP: which should you choose?
Choose a BCP for services whose downtime, even for an hour, costs more than paying for a standby all year round; a DRP for those that can stay down for the time of a controlled restoration. In both cases, keep a backup with version history against ransomware, one that the failover cannot have overwritten.
Updated October 20263 min read5 sources cited
Key points
- The choice is made service by service, not for the whole company at once.
- Compare the cost of an hour of downtime multiplied by the real duration of a restoration with the annual cost of the standby: this is the trade-off described by NIST and the ISO 22301 standard.
- If you have never timed a restoration, run that test first: without it, you are not yet in a position to choose.
- Against ransomware, a BCP alone is not enough: you must be able to return to a clean version.
The money question, put simply
Estimate the cost of an hour of downtime: salaries paid to staff who cannot work, lost sales, penalties, patients or customers not served. Multiply by the number of hours a conventional restoration would take in your company (often half a day to two days for a physical server without a tested image).
Compare this with the annual cost of a BCP (instances running for twelve months) and the cost of a DRP (preparation, plus activation only on the days of a disaster).
- If a four-hour outage costs €8,000 and is plausible once a year, a BCP costing a few thousand euros a year is a rational choice.
- If the same outage costs €400 because the team can work on paper for an afternoon, a DRP is enough, and sometimes backup alone.
- If you have never timed a restoration, you are not yet in a position to choose. Run a restoration test before buying a BCP.
This is exactly the trade-off NIST describes: finding the balance point between the cost of unavailability, which rises with the length of the outage, and the cost of recovery resources, which rises the faster you want to restart. The ISO 22301 standard follows the same approach: choose the continuity strategy by weighing the cost of standby resources against the consequences of the business stopping.
Two thresholds to set before choosing
ANSSI, France’s national cybersecurity agency, asks that the backup strategy take two values into account, to be set for each service:
| Threshold | Question | What it determines |
|---|---|---|
| RTO (DMIA in French): maximum tolerable downtime | How long can this service stay down? | A DRP if we are talking hours, a BCP if we are talking minutes |
| RPO (PDMA in French): maximum tolerable data loss | How much data entry can be lost? | Frequency of backups or replication |
The method is in How do you set your RTO? and How do you set your RPO?.
Decision grid by situation
| Situation | Most consistent choice |
|---|---|
| File server, half a day of downtime acceptable | Backup + DRP |
| Production or point-of-sale application, immediate downtime very costly | BCP, plus a backup with version history |
| Main concern: ransomware | Immutable backup + a DRP able to return to a clean date. A BCP alone is not enough |
| Single physical server, no spare hardware | DRP to instances, so you do not have to wait for a new server to be purchased |
| Two servers, only one of which is vital | BCP or DRP on the vital one, simple backup on the other |
| Two-person team, no written procedure | A simple, tested DRP rather than a BCP that nobody will know how to fail back |
On ransomware, the guideline from CERT-MU, Mauritius’s national incident response team, points the same way: the way out is a restoration from a backup taken before the attack. A standby that follows production in real time is no substitute for it.
Signs that a BCP is premature
- Nobody can say which applications must stay available.
- Licences prohibit running elsewhere.
- The site has a single, weak Internet connection: local users will not reach the cloud standby in good conditions unless that path is planned for.
- Failback (from standby to production) has never been described.
Signs that a DRP is not enough
- Customer commitments or ongoing care rule out several hours of downtime.
- The last restoration test took longer than management is willing to accept.
- The server is physical and old, and the hardware replacement lead time exceeds the RTO.
At WeDoBack
The DRP and the BCP exist side by side, on the same principle of encrypted offsite copies, with the key held by the customer. You can protect one server with a BCP and the others with INTEGRAL or SMART backup, without putting the whole company on the most expensive level. The choice is made server by server. Public reference prices: DRP storage from €175 excl. VAT per TB per month, activation billed per day; BCP with storage from €8.75 excl. VAT per month for 50 GB and instances from €50.22 excl. VAT per month, plus one agent per server. Replication or synchronisation of data between the BCP instance and the original server is not native: it requires a specific process, tailored to the need, which WeDoBack can set up on quotation.
Frequently asked questions
How do you estimate the cost of an hour of downtime?
Add up the salaries of the people who cannot work, lost revenue, contractual penalties and the cost of catching up. Continuity frameworks (ISO 22301, NIST) recommend measuring the consequences of an interruption for each essential activity and setting the length of interruption beyond which they become unacceptable.
Is a BCP useful if my Internet connection is weak?
Less than it seems. If the standby is in the cloud, users on site must reach it through that connection. A single, slow connection can make the standby unusable; you then need a second connection or a degraded mode.
Can you start with a DRP and move to a BCP later?
Yes, and it is often the soundest approach. A DRP forces you to write the procedure, measure restoration and identify the truly critical services. That information is then used to size a BCP for only the services that justify it.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- ISO 22301 – Business continuity — ISO
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI, France’s national cybersecurity agency
- Guideline on Ransomware Removal — CERT-MU (Mauritius)
- Offers and prices for offsite backup — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
