Home›Guides›DRP and BCP

DRP and BCP

What is the difference between a DRP and a BCP?

A BCP aims to keep the service from stopping at all, or almost; a DRP accepts that the service stops, then restarts it. You pay for a BCP every day; you pay for most of a DRP on the day you activate it, after paying for the preparation.

Updated October 20263 min read5 sources cited

Key points

  • BCP: the standby is already running; the interruption is limited to the time needed to detect the failure and fail over.
  • DRP: the standby is started when the decision is made, from a chosen backup; downtime lasts as long as the recovery.
  • Against ransomware, what counts is the ability to choose a clean version: a BCP that has replicated the encryption is no way out.
  • Many SMEs combine both: a BCP on one or two vital applications, a DRP and backup with version history for the rest.

Two reference definitions

NIST distinguishes the continuity plan, which sustains business processes during and after a disruption, from the disaster recovery plan, which focuses on the information system and is designed to restore its operation at an alternate site. The ISO 22301 standard, for its part, views continuity as keeping essential activities running at a predefined level, possibly in degraded mode, then resuming them in a planned way. In other words: the BCP covers the ‘during’, the DRP the ‘after’, and a complete plan deals with both. In Mauritius, section 31 of the Data Protection Act 2017 requires appropriate security measures against the loss or destruction of data: a plan that addresses both continuity and recovery is the natural response.

Side by side

DRPBCP
ObjectiveRecover after the disasterKeep going during the disaster
StandbyBuilt or switched on when the decision is madeAlready running
InterruptionMinutes to hours, sometimes more: this is the plan’s RTOAs short as possible, often just the detection time
DataThat of the chosen backup, so slightly behind (RPO)That of the standby, which must be kept continuously up to date
Main costPreparation storage, then activationInstances paid for permanently
Good scenarioDestroyed server, ransomware, need to choose a clean versionClear failure of a machine whose immediate downtime is too costly
MisusePromising ‘zero downtime’Believing the standby protects against encryption that has already been replicated

NIST sums up the trade-off with standby sites: a ‘cold’ site is the cheapest and takes the longest to bring online; a ‘hot’ site, ready immediately, is the most expensive. A DRP resembles the former, a BCP the latter.

An example

The file server goes down at 10 am because of a power supply failure.

  • DRP. The decision is made to fail over. An instance is started, the 6 am backup or the previous evening’s backup is restored, and users are reconnected. Downtime lasts as long as this operation. Work entered since the backup has to be redone.
  • BCP. The agent redirects traffic to the cloud instance that is already running. Workstations keep using the same address. Downtime is limited to detection and failover. Recent entries are only on the standby if a replication process had already copied them there.

The same server, encrypted by ransomware at 10 am, changes the conclusion. A BCP that has replicated the encryption is no way out. A DRP that lets you choose the previous day’s copy, especially if it is immutable, is. After an attack, you restore from a backup taken before the attack: this is the common thread of the ransomware guideline from CERT-MU, Mauritius’s national incident response team. Hence the rule: a BCP for clear failures, backup with version history for attacks, and both if both scenarios are real.

You can have both

Many SMEs only need a DRP on one or two servers. A few applications (point of sale, production, patient records open around the clock) justify a BCP, with a DRP behind it in case the standby itself turns out to be bad. Having a BCP without any backup history is an incomplete architecture. To decide server by server, see DRP or BCP: which should you choose? and How do you set your RTO?.

At WeDoBack

The DRP restarts servers on standby instances, from the chosen version, and bills activation per day. The included monthly test checks that the servers boot, not that users can work. The BCP keeps the instances running and takes over with no change of IP address, via an agent on the customer’s network and an IPsec VPN. Both rely on encrypted copies kept outside production. The public starting prices differ: DRP storage is advertised from €175 excl. VAT per TB per month; BCP storage can start at €8.75 excl. VAT per month for 50 GB, but the permanent instance (from €50.22 excl. VAT per month) is added even when there is no disaster. Replication or synchronisation of data between the BCP instance and the original server is not native: it requires a specific process, tailored to the need, which WeDoBack can set up on quotation.

Frequently asked questions

Can you have a BCP without a DRP?

Technically yes, but it is an incomplete architecture. If the standby is itself corrupted, or if the attack has been replicated, you must be able to start again from an earlier backup. Continuity frameworks (ISO 22301, NIST) describe continuity as keeping essential activities running, then resuming them in a planned way.

Is the DRP part of the BCP?

In the approach of continuity frameworks such as ISO 22301, yes: the continuity plan covers operating in degraded mode and then recovery. In everyday IT vocabulary, BCP refers to a standby that is already active and DRP to restarting after the event. Both readings converge: one without the other leaves a gap.

Which is better suited to a hardware failure?

For a clear failure of a machine whose immediate downtime is costly, a BCP provides the fastest takeover. If a few hours of downtime are acceptable, a DRP to standby instances means you do not have to wait for the hardware to be replaced.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.