DRP and BCP
How do you build a DRP for an SME?
An SME builds its DRP by starting from the services that block invoicing or production, writing down how long they can stay down, then preparing a concrete place to switch them back on. A forty-page binder that nobody has opened in three years is not a DRP.
Updated October 20263 min read5 sources cited
Key points
- Six steps: scope, thresholds (RPO, RTO), verified backup, recovery site, short procedure, dated test.
- Only services that must be restored the same day, sometimes within 72 hours, belong in the DRP; the rest is a matter for backup.
- The ANSSI, France’s national cybersecurity agency, requires a restoration order defined in advance, taking dependencies into account (directory, DNS, time).
- The encryption key and emergency accounts must be accessible outside the system to be restored, by at least two people.
- A procedure that does not fit on two to five pages will not be followed at 10 pm.
The frameworks’ approach, scaled to an SME
NIST, the US standards body, describes seven steps for an IT contingency plan: a policy, a business impact analysis, preventive controls, recovery strategies, writing the plan, testing and exercises, then maintenance. The SGDSN, the French government’s general secretariat for defence and national security, proposes five, from identifying essential activities to taking ownership of and maintaining the plan. For an SME, these approaches come down to six concrete steps.
Step 1. Define the scope
Bring management and the person who runs IT together for an hour. List the tools without which tomorrow’s work stops: business software, files, email, telephony, point of sale. Classify them:
- restore the same day;
- restore within 24 to 72 hours;
- rebuild when there is time.
Only the first column, sometimes the second, goes into the DRP. The rest is a matter for backup. This is the short version of the impact analysis that NIST and the SGDSN place at the start of any such approach.
Step 2. Set the RPO and RTO in one sentence per service
Example: ‘The quoting software can lose four hours of data entry and must be back by 9 am the next day.’ These two figures determine the backup frequency and the size of the standby. The ANSSI calls them maximum tolerable data loss (PDMA) and maximum tolerable downtime (DMIA), and requires the backup strategy to take them into account. The method is in How do you set your RPO? and How do you set your RTO?.
Step 3. Check that the backup feeds the plan
The DRP restores a copy. That copy must exist off site, be recent enough to meet the RPO, and have already been read back. The CNIL, France’s data protection authority, recommends storing at least one backup at a geographically separate site and keeping at least one offline. If there has never been a successful restoration, the next step is a backup test, not buying instances: see How do you test that a backup works?.
Step 4. Prepare the recovery site
- Standby machines: cloud instances, a second site, or hardware stored elsewhere.
- Start-up order. The ANSSI requires a restoration strategy and order to be defined, taking into account dependencies on infrastructure services (directory, DNS, time synchronisation).
- Addresses: workstations and external customers must know where to connect (IP retained, DNS, or instructions to users).
- Emergency administrator accounts, outside the domain in case the domain is compromised.
- The backup encryption key, accessible to two people. The ANSSI points out that the restoration procedure must include importing the encryption keys.
- Licences that allow this move.
Step 5. Write the procedure on two pages
NIST structures the plan in three phases: activation and notification, recovery, reconstitution. On two pages, that gives:
| Phase | Minimum content |
|---|---|
| Activation | Who has the authority to say ‘we are failing over’, numbers to call, list of people involved (the CNIL explicitly requires it) |
| Recovery | Numbered steps, in start-up order, with where to find the key and the accounts |
| Verification | A real business action: ‘the office assistant issues a test invoice’ |
| Return | How to move back to the original environment without losing the data entered on the standby |
| Communication | Who informs the teams, customers and the insurer |
If the procedure does not fit on two to five pages, it will not be followed at 10 pm.
Step 6. Test it
At least once a year, and after every server change. NIST calls for an annual test of recovery capabilities and teams; the CNIL asks organisations to test the application of the plan regularly. The test report dates the DRP. Without a date, the plan is out of date. See How do you test a DRP?.
Typical SME mistakes
- A DRP written by a provider and never reviewed internally.
- Forgetting the return path: you know how to move to the standby, but not how to come back.
- Email hosted in Microsoft 365 left out of the plan, even though nobody writes to the file server any more.
- A single password, stored in a password manager that itself sits on the server to be restored.
At WeDoBack
The outsourced DRP provides the recovery site: servers restart on standby instances, from the chosen backup version, with public IP addresses (€0.54 excl. VAT per month) if services are exposed. Building the plan (steps 1, 2 and 5) remains the customer’s responsibility. Support can help with the technical implementation: €45 excl. VAT per hour for a deployment, two hours per month included with INTEGRAL. The included monthly test checks that the instances boot. It does not replace step 6 carried out with a business user; a real-world test, of up to ten hours, is available on quotation. The encryption key stays with the customer: it must be covered in the procedure.
Frequently asked questions
How long does it take to build a DRP for an SME?
For two or three servers, allow a few half-days spread over a few weeks: an hour of scoping with management, writing the procedure, technical preparation, then a first test. The longest part is often fixing what the first test reveals.
Can you entrust writing the DRP to a service provider?
The provider can write the technical part, but management must set the priorities and acceptable timeframes, and the internal team must review the document and take ownership of it. The SGDSN, the French government’s general secretariat for defence and national security, recommends having the documents reviewed, ideally by a third party, then putting them to the test through drills and exercises.
Should Microsoft 365 or Google Workspace be included in the DRP?
Yes, if your email and shared files live there. The vendor’s service remains available if your servers fail, but a deletion or an account compromise requires a separate backup and a restoration procedure.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Guide to drawing up a business continuity plan (2013 edition, in French) — SGDSN
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI
- GDPR practical guide – Personal data security (2024 version, in French) — CNIL
- DRP offer: recovering operations after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
