DRP and BCP
What is the difference between a DRP and a BCP?
A BCP aims to keep the service from stopping at all, or almost; a DRP accepts that the service stops, then restarts it. You pay for a BCP every day; you pay for most of a DRP on the day you activate it, after paying for the preparation.
Updated October 20263 min read5 sources cited
Key points
- BCP: the standby is already running; the interruption is limited to the time needed to detect the failure and fail over.
- DRP: the standby is started when the decision is taken, from a chosen backup; downtime lasts as long as the recovery.
- Against ransomware, what counts is the ability to choose a clean version: a BCP that has replicated the encryption is no way out.
- Many SMEs combine the two: a BCP for one or two vital applications, a DRP and backup history for the rest.
Two official definitions
NIST, the US standards body, distinguishes the business continuity plan, which sustains business processes during and after a disruption, from the disaster recovery plan, which focuses on the information system and aims to restore its operation at an alternate site. The SGDSN, the French body responsible for national security, for its part defines the BCP as keeping essential activities running, possibly in degraded mode, followed by planned recovery. In other words: the BCP covers the ‘during’, the DRP the ‘after’, and a complete plan deals with both. The CNIL, the French data protection authority, uses both terms together when it recommends drawing up an IT business continuity and disaster recovery plan.
Side by side
Servers restart from a chosen backup.
A copy is already running and takes over immediately.
| DRP | BCP | |
|---|---|---|
| Objective | Recover after the disaster | Keep going during the disaster |
| Standby | Built or switched on when the decision is taken | Already running |
| Interruption | Minutes to hours, sometimes more: this is the plan’s RTO | As short as possible, often just the detection time |
| Data | That of the chosen backup, so slightly behind (RPO) | That of the standby, which must be kept continuously up to date |
| Main cost | Preparation storage, then activation | Instances paid for permanently |
| Good scenario | Destroyed server, ransomware, need to choose a clean version | Clear-cut failure of a machine whose immediate downtime is too costly |
| Misuse | Promising ‘zero interruption’ | Believing the standby protects against encryption that has already been replicated |
NIST sums up the trade-off with standby sites: a ‘cold’ site costs the least and takes the longest to bring online; a ‘hot’ site, ready immediately, costs the most. A DRP is akin to the former, a BCP to the latter.
An example
The file server goes down at 10 am because of a power supply failure.
- DRP. The decision to fail over is taken. An instance is switched on, the 6 am backup or the previous evening’s is restored, and users are reconnected. Downtime lasts as long as this operation. Work entered since the backup has to be redone.
- BCP. The agent redirects traffic to the cloud instance that is already running. Workstations keep using the same address. Downtime is limited to detection and failover. Recent entries are only on the standby if a replication process had already copied them there.
The same server, encrypted by ransomware at 10 am, changes the conclusion. A BCP that has replicated the encryption is no way out. A DRP that lets you choose the previous evening’s copy, especially if it is immutable, is. Europol and the No More Ransom project advise against paying the ransom: after an attack, the way out runs through a backup made before the attack. Hence the rule: a BCP for clear-cut failures, backup with history for attacks, and both if both scenarios are real.
You can have both
Many SMEs only need a DRP for one or two servers. A few applications (point of sale, production, continuously open patient records) justify a BCP, with a DRP still behind it in case the standby itself turns out to be bad. Having a BCP without any backup history is an incomplete architecture. To decide server by server, see DRP or BCP: which should you choose? and How do you set your RTO?.
At WeDoBack
The DRP restarts servers on standby instances, from the chosen version, and bills activation per day. The included monthly test checks that the servers boot, not that users can work. The BCP keeps instances running and takes over without any change of IP address, through an agent on the customer’s network and an IPsec VPN. Both rely on encrypted copies kept outside production. The public starting prices differ: DRP storage is advertised from €175 excl. VAT per TB per month; BCP storage can start at €8.75 excl. VAT per month for 50 GB, but the permanent instance (from €50.22 excl. VAT per month) is added even when there is no disaster. Replication or synchronisation of data between the BCP instance and the original server is not native: it relies on a specific process, tailored to the need, which WeDoBack can set up on quotation.
Frequently asked questions
Can you have a BCP without a DRP?
Technically yes, but it is an incomplete architecture. If the standby is itself corrupted, or if the attack has been replicated, you need to be able to start again from an earlier backup. The SGDSN, the French government’s general secretariat for defence and national security, describes continuity as keeping essential activities running, then resuming them in a planned way.
Is the DRP part of the BCP?
In the SGDSN’s approach, yes: the continuity plan covers both operating in degraded mode and the subsequent recovery. In everyday IT vocabulary, BCP refers to the standby that is already active and DRP to restarting after the event. Both readings converge: one without the other leaves a gap.
Which is better suited to a hardware failure?
For a clear-cut failure of a machine whose immediate downtime is costly, the BCP provides the fastest takeover. If a few hours of downtime are acceptable, a DRP to standby instances avoids waiting for the hardware to be replaced.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Guide to drawing up a business continuity plan (2013 edition, in French) — SGDSN (France)
- No More Ransom: advice and decryption tools against ransomware — Europol and partners
- GDPR practical guide – Personal data security (2024 version, in French) — CNIL (French authority)
- Offsite backup offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
