DRP and BCP
What is a DRP?
A disaster recovery plan (DRP) brings together the resources and steps planned to restart IT after a disaster, on a replacement environment, within a timeframe the company has deemed acceptable. It begins when production has already stopped and ends once you are back on the usual environment.
Updated October 20264 min read5 sources cited
Key points
- A DRP is not software: it is a file that states what to restart, where, in what order, who decides and how to return.
- It sets two thresholds per service: the acceptable downtime (RTO, known in France as DMIA) and the acceptable data loss (RPO, known in France as PDMA).
- Its RPO is that of the backup feeding it: a DRP never restores a state more recent than the last clean copy.
- Without a dated test, it is a document, not a plan. The CNIL (the French data protection authority) recommends testing the application of the plan regularly.
A reference definition
NIST, the US standards body, defines the disaster recovery plan as an information-system-focused plan designed to restore operability of a system, application or infrastructure at an alternate site after an emergency. The business continuity plan, by contrast, aims to sustain business processes during and after a disruption.
The SGDSN, the French body responsible for national security, treats recovery as part of the business continuity plan: keep essential activities running, in degraded mode if necessary, then resume in a planned way. The two plans complement each other; the difference is explained in What is the difference between a DRP and a BCP?.
What it contains
A DRP is not software. It is a living file:
- the list of services to restart, in order (directory, databases, applications, then workstations);
- the maximum acceptable downtime (RTO) and the amount of data you accept having to re-enter (RPO);
- where the copies are, and how they are turned into servers that boot;
- who decides to fail over, who holds the encryption key, who informs users;
- how to switch back once the original site has been repaired;
- the date of the last test, and what it showed.
Without that last line, you have a document. You do not have a plan.
NIST divides the plan into three phases, a useful way to structure the few pages an SME needs:
| Phase | Question it answers |
|---|---|
| Activation and notification | Who spots the incident, who decides to trigger the plan, who informs whom? |
| Recovery | What steps restart the services, in what order, on which environment? |
| Reconstitution | How do you validate operation, move back to the original environment and close the incident? |
The ANSSI, France’s national cybersecurity agency, stresses the order: a restoration strategy and sequence must be defined, taking particular account of dependencies on infrastructure services (DNS, directory, time synchronisation).
DRP and backup
The backup provides the data and, if it is an image, the system. The DRP provides the place where that system restarts and the procedure that lets people use it: network, addresses, DNS or IP, licences, accounts. Having backups in a cloud with no standby server planned means being able to restore ‘somewhere’, some day. The DRP names that somewhere and that day.
The DRP’s RPO is that of the backup feeding it. If the last clean copy dates from 10 pm the previous evening, the fastest DRP in the world will restore the 10 pm state, not the state at 10 am the next day. The ANSSI also requires the backup strategy to take into account the maximum tolerable data loss (PDMA) and the maximum tolerable downtime (DMIA): these are the French names for RPO and RTO, detailed in What is an RPO? and What is an RTO?.
What a DRP is not
- A BCP. A BCP aims to keep the service running with almost no interruption. A DRP accepts an interruption, followed by recovery.
- Replication alone. A replica follows the original, attack included. A DRP must be able to choose an earlier version.
- A verbal promise from your provider. ‘We’ll sort you out’ with no measured RTO and no annual test is not a plan.
For an SME
A useful DRP fits in a few pages and covers two or three servers, not the fifty applications on a corporate group’s diagram. It addresses: a fire in the server room, a physical server that cannot be repaired within 48 hours, ransomware that has made production unusable. If it covers everyone in the same way, it will never be tested.
Article 32 of the GDPR requires organisations to be able to restore access to personal data in a timely manner after an incident. In its guide to personal data security, the CNIL recommends drawing up an IT business continuity and disaster recovery plan that includes the list of people involved, making sure users and providers know whom to alert, and regularly testing both backup restoration and the application of the plan. The step-by-step method is in How do you build a DRP for an SME?.
At WeDoBack
The WeDoBack DRP restarts the customer’s servers on standby instances, from the backup version the customer chooses. Compute resources are allocated at the time of recovery, not permanently. An automatic monthly test checks that these instances boot, without touching production. A real-world test, of up to ten hours, is available on quotation. Activation on the day of the disaster is billed per day. DRP storage starts at €175 excl. VAT per TB per month, plus one agent per server, the instances and, for services reachable from the Internet, public IP addresses at €0.54 excl. VAT per month. Copies are encrypted on the machine before they are sent, with a key held by the customer: recovery requires that key to be available. Returning to the original server, once repaired, is part of the plan: the data is restored there and backups resume.
Frequently asked questions
Is a DRP mandatory for an SME?
No regulation requires every SME to have a DRP. However, Article 32 of the GDPR requires organisations to be able to restore access to personal data in a timely manner after an incident, and the CNIL, the French data protection authority, recommends drawing up an IT business continuity and disaster recovery plan, even a basic one, and testing it regularly. Customer contracts, your insurer or sector-specific regulations may also require one.
What is the difference between a DRP and a simple backup?
A backup preserves the data, and sometimes the system image. A DRP also specifies where those systems will restart, the start-up order, the network, the accounts and who decides to fail over. With a backup alone, you know you can restore ‘somewhere’, some day; the DRP names that place and that timeframe.
Who should write the DRP?
Management sets the priorities and acceptable timeframes; the person who runs IT, or the service provider, describes the technical steps. The SGDSN, the French government’s general secretariat for defence and national security, recommends having the documents reviewed, ideally by a third party, then putting them to the test through drills and exercises.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Guide to drawing up a business continuity plan (2013 edition, in French) — SGDSN (France)
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI (French agency)
- GDPR practical guide – Personal data security (2024 version, in French) — CNIL (French authority)
- DRP offer: recovering operations after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
