Home›Guides›DRP and BCP

DRP and BCP

How do you ensure continuity for a critical server?

You ensure continuity for a critical server by treating it separately, with a standby solution proportionate to its acceptable downtime, while ordinary servers make do with a backup. “Critical” means: if this one stops, the business stops, even if the other machines are still responding.

Updated October 20263 min read5 sources cited

Key points

  • One or two critical servers for an SME: if there are five, there are none.
  • It needs a tested backup, an image that can restart elsewhere, a DRP or a BCP, and two people able to launch the procedure.
  • You protect the chain of dependencies (directory, database, application), not the machine alone.
  • A BCP without historical backups covers hardware failure, not ransomware.
  • A written degraded mode is part of continuity: the ANSSI, France’s national cybersecurity agency, expects organisations to be able to keep critical activities running even without digital services.

Designating it properly

A server is critical if one of these statements is true:

  • people are blocked immediately (till, production, open case file, switchboard);
  • there is no paper workaround, or it only holds for an hour;
  • replacing it requires hardware or a licence you do not have in stock.

If five servers are “critical”, in practice none are: budget and testing get spread too thin. Force a ranking. One or two are enough for an SME. This is the spirit of the business impact analysis described by NIST: determine how critical each process is, identify the resources it depends on, then set an order of priority for recovery.

What this server needs, and the others do not

  1. A backup whose frequency meets its RPO, and that has been tested.
  2. An image that can restart elsewhere, not just its files.
  3. Either a DRP (it is started on an instance when the day comes) or a BCP (an instance is already running) if the RTO is too short for a restore.
  4. A well-designed failover network: workstations find it without a ten-page manual.
  5. Its dependencies in the same plan. A business server that starts without the directory or the database is not in continuity. You protect the chain, not the box alone. The ANSSI asks for the restore order to take account of infrastructure services (DNS, NTP, directory) and how critical the applications are.
  6. Two people able to launch the procedure.

Critical server checklist

ItemQuestion to askExpected evidence
BackupIs the last successful copy more recent than the RPO?Morning report
System imageHas it already been started elsewhere?Dated test report
StandbyDRP or BCP, sized for the actual number of users?Instance sheet
NetworkCan workstations reach the standby without reconfiguration?Failover test
DependenciesAre the directory, database and licences in the same plan?Start-up order list
PeopleDo two people know how to trigger it?Names and numbers, kept offline
Encryption keyIs it accessible if the site is lost?Documented location

What you can decline to do

  • Duplicate every server “for symmetry”.
  • Aim for zero data loss on a server whose entries can be re-keyed.
  • A BCP on a critical server and no historical backup: hardware failure is covered, encryption is not.

Degraded mode is part of continuity

Writing down how to work for two hours without the server (order taking, forms, queue) reduces the perceived RTO even if the technical work takes four hours. Many plans leave this out and promise a technical recovery time that the first outage proves wrong. In its cyber crisis management guide, the ANSSI expects an organisation to be able to maintain its most critical activities, possibly in degraded mode, or even without digital services. It also recommends keeping the crisis contact directory offline.

At WeDoBack

The critical server goes into the DRP or the BCP. The others stay on SMART or INTEGRAL. The DRP restarts it on a standby instance from the chosen version, with a monthly start-up test that does not touch production; a live test of up to 10 hours is available on quotation. The BCP has it taken over by a cloud instance that runs permanently, via an agent on the customer’s network and an IPsec VPN, with no IP address change for workstations. Data replication or synchronisation between the BCP instance and the original server is not built in: it relies on a specific process, tailored to the need, which WeDoBack can set up on quotation. In both cases, an agent runs on the server (€6 excl. VAT per month for a virtual machine, €20 excl. VAT for a physical one, public prices as of October 2026), and recovery storage (from €175 excl. VAT per TB per month) is a separate line from plain backup storage. The chain of dependencies (which servers start together) should be specified when requesting the quote: it cannot be inferred from the volume in terabytes alone.

Frequently asked questions

How can you tell whether a server is really critical?

Ask three questions: are people blocked immediately when it stops? Is there a paper workaround that holds for more than an hour? Can it be replaced with hardware and licences already available? If the answer to the first is yes and to the other two no, it is critical.

DRP or BCP for a critical server?

It all depends on its RTO. If the business can tolerate a few hours of downtime, a DRP (a prepared standby, started when needed) is enough and costs less day to day. If each hour of downtime costs more than a year’s subscription to a permanent standby, a BCP is justified. In both cases, keep a historical backup alongside.

Should the directory and the database be duplicated too?

Yes, if they are needed for the critical server to start. A business server that restarts without its directory or its database is not in continuity. NIST recommends setting recovery priorities by linking each resource to the processes it supports.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.