Home›Guides›DRP and BCP

DRP and BCP

How do you build a DRP for an SME?

An SME’s DRP is built by starting from the services that block invoicing or production, writing down how long they can stay down, then preparing a concrete place to bring them back up. A forty-page binder that nobody has opened in three years is not a DRP.

Updated October 20263 min read5 sources cited

Key points

  • Six steps: scope, thresholds (RPO, RTO), verified backup, recovery site, short procedure, dated test.
  • Only services that must be back the same day, sometimes within 72 hours, go into the DRP; the rest is covered by backup.
  • ANSSI, France’s national cybersecurity agency, calls for a restoration order defined in advance, taking dependencies into account (directory, DNS, time).
  • The encryption key and emergency accounts must be accessible outside the system being restored, by at least two people.
  • A procedure that does not fit on two to five pages will not be followed at 10 pm.

The frameworks’ approach, scaled to an SME

NIST describes seven steps for an IT contingency plan: a policy, a business impact analysis, preventive controls, recovery strategies, writing the plan, testing and exercises, then maintenance. CERT-MU, Mauritius’s national incident response team, describes a similar cycle in its incident handling guideline: preparation, detection, containment, recovery, then lessons learned. For an SME, these approaches come down to six concrete steps.

Step 1. Define the scope

Bring management and the person who runs IT together for an hour. List the tools without which tomorrow’s work stops: business software, files, email, telephony, point of sale. Sort them:

  • back the same day;
  • back within 24 to 72 hours;
  • rebuilt when time allows.

Only the first column, sometimes the second, goes into the DRP. The rest is covered by backup. This is the short version of the impact analysis that NIST and the ISO 22301 standard place at the start of any approach.

Step 2. Set RPO and RTO in one sentence per service

Example: ‘The quoting software can lose four hours of data entry and must be available again before 9 am the next day.’ These two figures determine the backup frequency and the size of the standby. ANSSI calls them maximum tolerable data loss (PDMA) and maximum tolerable downtime (DMIA), and asks that the backup strategy take them into account. The method is in How do you set your RPO? and How do you set your RTO?.

Step 3. Check that the backup feeds the plan

A DRP restores a copy. That copy must exist off site, be recent enough to meet the RPO, and have already been read back. In its backup plan guideline, CERT-MU recommends keeping an offsite copy and testing restoration regularly. If there has never been a successful restoration, the next step is a backup test, not buying instances: see How do you test that a backup works?.

Step 4. Prepare the recovery site

  • Standby machines: cloud instances, a second site, or hardware stored elsewhere.
  • Start-up order. ANSSI asks that a restoration strategy and order be defined, taking into account dependencies on infrastructure services (directory, DNS, time synchronisation).
  • Addresses: workstations and external customers must know where to connect (IP retained, DNS, or instructions to users).
  • Emergency administrator accounts, outside the domain in case the domain is compromised.
  • The backup encryption key, accessible to two people. ANSSI points out that the restoration procedure must include importing the encryption keys.
  • Licences that allow this move.

Step 5. Write the procedure on two pages

NIST structures the plan in three phases: activation and notification, recovery, reconstitution. On two pages, that gives:

PhaseMinimum content
ActivationWho has the authority to say ‘we fail over’, numbers to call, list of responders (CERT-MU’s incident handling guideline places this in preparation)
RecoveryNumbered steps, in start-up order, with where to find the key and the accounts
VerificationA real business action: ‘the administrative assistant issues a test invoice’
ReturnHow to switch back to the original environment without losing the data entered on the standby
CommunicationWho informs the teams, the customers, the insurer

If the procedure does not fit on two to five pages, it will not be followed at 10 pm.

Step 6. Test it

At least once a year, and again after every server change. NIST provides for an annual test of recovery capabilities and teams; CERT-MU also recommends regular restoration tests. The test report dates the DRP. Without a date, the plan is out of date. See How do you test a DRP?.

Typical SME mistakes

  • A DRP written by a provider and never reviewed internally.
  • Forgetting failback: you know how to move to the standby, not how to come back.
  • Email hosted in Microsoft 365 left out of the plan, even though nobody writes to the file server any more.
  • A single password, kept in a password manager that itself sits on the server to be restored.

At WeDoBack

The outsourced DRP provides the recovery site: servers restart on standby instances, from the chosen backup version, with public IP addresses (€0.54 excl. VAT per month) if services are exposed. Building the plan (steps 1, 2 and 5) remains the customer’s responsibility. Support can help with the technical implementation: €45 excl. VAT per hour for a deployment, two hours per month included with INTEGRAL. The included monthly test checks that the instances boot. It does not replace step 6 carried out with a business user; a real-world test, lasting up to ten hours, is available on quotation. The encryption key stays with the customer: it must be included in the procedure.

Frequently asked questions

How long does it take to build a DRP for an SME?

For two or three servers, allow a few half-days spread over a few weeks: an hour of scoping with management, writing the procedure, technical preparation, then a first test. The longest part is often fixing what the first test reveals.

Can the writing of the DRP be outsourced to a provider?

The provider can write the technical part, but management must set the priorities and acceptable timeframes, and the internal team must review the document and make it their own. Continuity frameworks recommend having the documents reviewed, ideally by a third party, and then putting them to the test through tests and exercises.

Should Microsoft 365 or Google Workspace be included in the DRP?

Yes, if your email and shared files live there. The vendor’s service remains available if your servers go down, but a deletion or an account compromise requires a separate backup and a restoration procedure.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.