DRP and BCP
DRP or BCP: which should you choose?
Choose a BCP for services whose downtime, even for an hour, costs more than paying for a standby all year round; a DRP for those that can stay down for the time of a controlled restoration. In both cases, keep a backup history against ransomware that the failover cannot have overwritten.
Updated October 20263 min read5 sources cited
Key points
- The choice is made service by service, not for the whole company at once.
- Compare the cost of an hour of downtime multiplied by the actual duration of a restoration with the annual cost of the standby: this is the trade-off described by NIST and the SGDSN.
- If you have never measured a restoration, run that test first: without it, you are not yet in a position to choose.
- Against ransomware, a BCP alone is not enough: you must be able to return to a clean version.
The money question, put simply
Estimate the cost of an hour of downtime: salaries of staff present but unable to work, lost sales, penalties, patients or customers not served. Multiply by the number of hours a conventional restoration would take in your company (often half a day to two days for a physical server without a tested image).
Compare that with the annual cost of a BCP (instances running twelve months a year) and the cost of a DRP (preparation, plus activation only on the days of a disaster).
- If a four-hour outage costs €8,000 and is plausible once a year, a BCP costing a few thousand euros a year is a rational choice.
- If the same outage costs €400 because the team can work on paper for an afternoon, a DRP is enough, and sometimes backup alone.
- If you have never measured restoration, you are not yet in a position to choose. Run a restoration test before buying a BCP.
This is exactly the trade-off NIST, the US standards body, describes: finding the balance point between the cost of unavailability, which grows with the length of the outage, and the cost of recovery resources, which grows the faster you want to restart. The SGDSN, the French government’s general secretariat for defence and national security, proposes the same approach: compare the cost of maintaining standby resources with the cost of business disruption to define the continuity strategy.
Two thresholds to set before choosing
The ANSSI, France’s national cybersecurity agency, requires the backup strategy to take two values into account, to be set for each service:
| Threshold | Question | What it determines |
|---|---|---|
| DMIA (or RTO): maximum tolerable downtime | How long can this service stay down? | DRP if we are talking hours, BCP if we are talking minutes |
| PDMA (or RPO): maximum tolerable data loss | How much data entry can be lost? | Frequency of backups or replication |
The method is in How do you set your RTO? and How do you set your RPO?.
Decision grid by situation
| Situation | Most consistent choice |
|---|---|
| File server, half a day of downtime acceptable | Backup + DRP |
| Production or point-of-sale application, immediate downtime very costly | BCP, plus a backup history |
| Main concern: ransomware | Immutable backup + DRP able to return to a clean date. A BCP alone is not enough |
| Single physical server, no spare hardware | DRP to instances, so you do not have to wait for a new server to be purchased |
| Two servers, only one of which is vital | BCP or DRP for the vital one, simple backup for the other |
| Team of two people, no written procedure | A simple, tested DRP, rather than a BCP nobody will know how to fail back |
On ransomware, Cybermalveillance.gouv.fr, the French government’s cyber-assistance platform, is clear: the way out is to restore from a backup made before the attack. A standby that follows production in real time is no substitute.
Signs that a BCP is premature
- Nobody can say which applications must stay available.
- The licences forbid running elsewhere.
- The site has a single, weak Internet connection: local users will not reach the cloud standby in good conditions unless that path is planned for.
- Failing back (standby to production) has never been described.
Signs that a DRP is not enough
- Customer commitments or ongoing patient care rule out several hours of downtime.
- The last restoration test took longer than management is willing to accept.
- The server is physical and old, and the hardware replacement lead time exceeds the RTO.
At WeDoBack
The DRP and the BCP exist side by side, on the same principle of encrypted offsite copies with the key held by the customer. You can protect one server with the BCP and the others with INTEGRAL or SMART backup, without bringing the whole company up to the most expensive level. The choice is made server by server. Public reference prices: DRP storage from €175 excl. VAT per TB per month, activation billed per day; BCP with storage from €8.75 excl. VAT per month for 50 GB and instances from €50.22 excl. VAT per month, plus one agent per server. Replication or synchronisation of data between the BCP instance and the original server is not native: it relies on a specific process, tailored to the need, which WeDoBack can set up on quotation.
Frequently asked questions
How do you estimate the cost of an hour of downtime?
Add up the salaries of the people who cannot work, the lost revenue, contractual penalties and the cost of catching up. The SGDSN, the French government’s general secretariat for defence and national security, recommends measuring the consequences of an interruption for each essential activity and setting the length of interruption beyond which they become unacceptable.
Is a BCP useful if my Internet connection is weak?
Less than it seems. If the standby is in the cloud, on-site users have to reach it through that connection. A single, slow line can make the standby unusable; you then need to plan a second connection or a degraded mode.
Can you start with a DRP and move to a BCP later?
Yes, and it is often the soundest approach. A DRP forces you to write the procedure, measure restoration and identify the truly critical services. That information is then used to size a BCP for only the services that justify it.
Sources
Documents consulted in October 2026.
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Guide to drawing up a business continuity plan (2013 edition, in French) — SGDSN
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI
- Ransomware: what to do if your organisation falls victim to an attack? (in French) — Cybermalveillance.gouv.fr
- Offsite backup offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
