Home›Guides›DRP and BCP

DRP and BCP

Outsourced BCP: pros and cons

With an outsourced BCP, a provider hosts a standby that is already running, while production stays on your premises. Users keep working if the failover is transparent. The cost is ongoing, and several limitations stem from the fact that the standby is not in the next room.

Updated in October 20264 min read5 sources cited

Key points

  • Pros: very short recovery time if the server fails, no second server room, failover can be transparent for workstations.
  • Cons: dependence on the on-site agent and the Internet link, data lag (hidden RPO), failback to be prepared, licences.
  • A server BCP is not a site BCP: a destroyed building requires separately tested remote access.
  • A standby that replicates everything also replicates ransomware: keep a historical backup alongside.
  • The contract follows the same rules as an outsourced DRP: hosting locations, reversibility, Article 28 GDPR clauses.

Pros

  • Short recovery time for a server failure, because the instance exists before the incident.
  • No second server room to cool, monitor and renew.
  • Possible transparency for workstations, when an on-site agent redirects traffic without changing the IP address. Users do not need to pull out a user manual.
  • Adjustable sizing. The instance can be scaled up without buying a server. In return, you pay for it.
  • Physical separation from production: a fire in the server rack does not take down the standby, provided users can still reach it.

Cons

  • The on-site agent must survive. If the BCP relies on an agent on your premises to redirect traffic, that agent disappears with the switch, a fire in the building or a general power cut. A server BCP is not a site BCP. For a destroyed site, remote access and public addresses are needed, tested separately.
  • The Internet link becomes vital. Data, and sometimes sessions, go through the VPN to the provider. A single connection, saturated or cut, stops the standby just when you need it. A second connection is often the real forgotten expense.
  • Data consistency. A permanent standby is only useful if it has received the transactions. An unmeasured lag is a hidden RPO. The ANSSI, France’s national cybersecurity agency, suggests replication where data loss must be under 24 hours, while considering an offline backup essential: if the standby received the ransomware as quickly as the users did, it is not a backup.
  • Failback. Data entered on the standby during the outage must be brought back to the repaired server. Without a procedure, that period is lost or you end up with two diverging databases.
  • Licences. The business software vendor must authorise this permanent instance. Some contracts prohibit it or charge for it.
  • Ongoing cost. You pay for months without any outage. That is normal. It is too expensive if the application could in fact tolerate half a day of downtime.
  • A false sense of testing. A running instance is not a tested failover. The redirection must have been triggered at least once.

Outsourced BCP or outsourced DRP

Outsourced BCPOutsourced DRP
Standby statusRunning permanentlyPrepared, started on the day of the disaster
Recovery timeThe shortestThe time it takes to start the instances
Cost when there is no disasterInstances paid every monthMainly storage and preparation
Return to an earlier versionNo, unless there is a historical backup alongsideYes, version chosen from the history
Site destroyedRemote access to be planned separatelyReserved public addresses

Details are in What is the difference between a DRP and a BCP?.

The contract

The contract points are the same as for an outsourced DRP. The ANSSI recommends obtaining the list of all storage locations, including standby sites, and providing for a security assurance plan and a reversibility clause. If personal data is processed, the provider is a processor within the meaning of the GDPR: the processor’s guide published by the CNIL, France’s data protection authority, points out that it acts on written instructions, only uses another processor with written authorisation, alerts the customer in the event of a breach, and at the end of the contract returns or destroys all data, including copies.

When it is the right choice

One or two servers for which an hour of downtime costs more than the annual subscription, a local network able to host the agent, a decent link, and nevertheless a historical backup alongside for the day when the standby itself is compromised. The ANSSI points out that a cyber-related crisis can last several weeks: the BCP must be able to hold for that long, not just a few hours.

At WeDoBack

The BCP offer follows this model: cloud instances running permanently from 50.22 € excl. VAT per month, storage from 8.75 € excl. VAT per month for 50 GB (175 € excl. VAT per TB), an agent on the customer’s network, an IPsec VPN, takeover with no change of IP address, and traffic returned to the repaired server. Replication or synchronisation of data between the BCP instance and the original server is not supported natively: it requires a specific process, defined according to the need (database, files, business application), including to carry over to the repaired server the data entered on the instance during the incident. WeDoBack can set it up on quotation. The limitations above apply as they stand, in particular the dependence on the on-site agent and the link. The DRP remains available for the “the site is gone” or “we need a version from before the attack” scenario. Taking a BCP without backup history leaves ransomware uncovered: WeDoBack covers it with its backup offers and the IMMUTABLE offer, which are separate lines. Data is encrypted on the machine before sending, with the key held by the customer, in ISO 27001 and HDS (French health data hosting) certified data centres. Human support is available from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time).

Frequently asked questions

Does an outsourced BCP protect against ransomware?

Not on its own. If the standby receives changes continuously, it also receives the encrypted files. You need a historical backup, ideally immutable, to go back to a version predating the attack. The BCP covers failures; the history covers corruption and encryption.

What happens if the site’s Internet connection is cut?

If the BCP relies on a VPN between the site and the provider, a link outage isolates the standby just when you need it. A second Internet connection, from another operator and over a different route if possible, is often the expense that makes the BCP genuinely useful.

How do you recover data entered on the standby?

It must be brought back to the repaired server before users return to it. Without a written and tested procedure, that period is lost or you end up with two diverging databases. This failback is part of the test, just like the failover.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.