DRP and BCP
How do you ensure continuity for a critical server?
Continuity for a critical server is ensured by treating it separately, with a standby proportionate to its acceptable downtime, while ordinary servers make do with a backup. “Critical” means: if this one stops, the business stops, even if the other machines are still responding.
Updated in October 20263 min read5 sources cited
Key points
- One or two critical servers for an SME: if there are five, there are none.
- It needs a tested backup, an image capable of restarting elsewhere, a DRP or a BCP, and two people able to launch the procedure.
- Protect the chain of dependencies (directory, database, application), not the machine alone.
- A BCP without historical backup covers hardware failure, not ransomware.
- A written degraded mode is part of continuity: the ANSSI, France’s national cybersecurity agency, expects organisations to be able to maintain critical activities even without digital services.
Designating it properly
A server is critical if any of these statements is true:
- people are blocked immediately (till, production, open case file, switchboard);
- there is no paper workaround, or it only lasts an hour;
- replacing it requires hardware or a licence you do not have in stock.
If five are “critical”, in practice none is: budget and testing are spread too thin. Force a ranking. One or two are enough for an SME. This is the spirit of the business impact analysis described by NIST, the US National Institute of Standards and Technology: determine the criticality of each process, identify the resources it depends on, then set an order of recovery priority.
What this server must have, and the others need not
- A backup whose frequency meets its RPO, tested.
- An image capable of restarting elsewhere, not just its files.
- Either a DRP (it is started on an instance when needed) or a BCP (an instance is already running) if the RTO is too short for a restore.
- A well-designed failover network: workstations find it without a ten-page user manual.
- Its dependencies in the same plan. A business server that starts without the directory or the database does not provide continuity. Protect the chain, not the box alone. The ANSSI asks for the restore order to take into account infrastructure services (DNS, NTP, directory) and the criticality of applications.
- Two people able to launch the procedure.
Critical server checklist
| Item | Question to ask | Expected evidence |
|---|---|---|
| Backup | Is the last successful copy more recent than the RPO? | Morning report |
| System image | Has it already been started elsewhere? | Dated test report |
| Standby | DRP or BCP, sized for the actual number of users? | Instance sheet |
| Network | Can workstations reach the standby without reconfiguration? | Failover test |
| Dependencies | Are the directory, database and licences in the same plan? | Start-up order list |
| People | Do two people know how to trigger it? | Names and numbers, kept offline |
| Encryption key | Is it accessible if the site is lost? | Documented location |
What you can decline to do
- Duplicate every server “for symmetry”.
- Aim for zero data loss on a server whose entries can be re-keyed.
- A BCP on a critical server and no historical backup: hardware failure is covered, encryption is not.
Degraded mode is part of continuity
Writing down how to work for two hours without the server (order taking, forms, queue) reduces the perceived RTO even if the technical recovery takes four hours. Many plans leave this out and promise a technical timeframe that the first outage disproves. In its cyber crisis management guide, the ANSSI expects an organisation to be able to maintain its most critical activities, possibly in degraded mode, or even without digital services. It also recommends keeping the crisis directory of people to contact offline.
At WeDoBack
The critical server goes into the DRP or the BCP. The others stay on SMART or INTEGRAL. The DRP restarts it on a standby instance from the chosen version, with a monthly start-up test that does not affect production; a real-conditions test, of up to 10 hours, is available on quotation. The BCP has it taken over by a cloud instance that runs permanently, via an agent on the customer’s network and an IPsec VPN, with no IP address change for workstations. Replication or synchronisation of data between the BCP instance and the original server is not built in: it relies on a specific process, tailored to the need, which WeDoBack can set up on quotation. In both cases, an agent runs on the server (6 € excl. VAT per month for a virtual server, 20 € excl. VAT for a physical one, public prices as of October 2026), and recovery storage (from 175 € excl. VAT per TB per month) is a separate line from plain backup storage. The chain of dependencies (which servers start together) must be specified when requesting the quote: it cannot be deduced from the volume in terabytes alone.
Frequently asked questions
How do you know whether a server is really critical?
Ask three questions: are people blocked immediately when it stops? Is there a paper workaround that lasts more than an hour? Can it be replaced with hardware and licences already available? If the answer to the first is yes and to the other two is no, it is critical.
DRP or BCP for a critical server?
It all depends on its RTO. If the business can tolerate a few hours of downtime, a DRP (a prepared standby, switched on when needed) is sufficient and costs less day to day. If each hour of downtime costs more than the annual subscription for a permanent standby, a BCP is justified. In both cases, keep a historical backup alongside.
Should the directory and the database also be duplicated?
Yes, if they are needed for the critical server to start. A business server that restarts without its directory or its database does not provide continuity. NIST, the US National Institute of Standards and Technology, recommends setting recovery priorities by linking each resource to the processes it supports.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (French agency)
- Cyber crisis: keys to operational and strategic management (December 2021) — ANSSI (French agency)
- BCP offer: immediate business continuity — WeDoBack
- DRP offer: recovery after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
