Cybersecurity

Business continuity and disaster recovery in practice

Turn BCP and DRP documents into tested capabilities. Understand BIA, RTO and RPO, and their relationship with ISO 22301 and NIS2.

Many organisations have a continuity plan stored in a folder or shared drive, sometimes prepared mainly for certification. Its value lies in whether it works. Ransomware, a data centre failure or a prolonged provider outage tests the ability to restore critical processes. This guide explains BCP, DRP, BIA, RTO and RPO, and how regular exercises turn documentation into capability.

What is the difference between BCP and DRP?

A Business Continuity Plan (BCP) explains how the organisation maintains critical activities during disruption: who decides, where people work, how customers are informed and which manual or alternative processes bridge the outage.

A Disaster Recovery Plan (DRP) focuses on restoring IT systems, data and infrastructure after a failure or attack. It is a component of continuity planning, not a synonym for it.

FactorBusiness continuityDisaster recovery
FocusOrganisation and business processesIT systems, data and infrastructure
ObjectiveMaintain operations during disruptionRestore systems following disruption
ScopePeople, processes, locations and communicationServers, networks, backups and applications
OwnerBusiness management and continuity leadIT and infrastructure teams
Typical contentRoles, alternatives and escalationRecovery sequence, backups and runbooks

Neither replaces the other. Restoring a server is insufficient if no one knows who informs customers; a staff contingency plan cannot recover missing data. Effective arrangements coordinate both.

What is a BIA, and why does it come first?

A Business Impact Analysis (BIA) identifies critical processes and their tolerance for disruption. It assesses financial, legal, operational and reputational effects, including how they worsen over time. The aim is to distinguish truly critical activities from functions that can tolerate a longer interruption.

Typical outputs include:

  • ranked critical processes and acceptable disruption periods;
  • dependencies on systems, suppliers and key people;
  • the maximum tolerable period of disruption (MTPD) for each process;
  • recovery priorities that determine the DRP sequence.

Without a BIA, a continuity plan may spend heavily on the wrong protection while leaving the most important process exposed.

What do RTO and RPO mean?

RTO concerns how quickly to recover. RPO concerns how much recent data can be lost, expressed as a period of time. They translate business needs into measurable targets for backup and recovery design.

MeasureMeaningThe question it answers
RTO — Recovery Time ObjectiveTarget recovery timeHow soon should the service be restored?
RPO — Recovery Point ObjectiveTolerable data loss periodHow much recent work can we afford to lose?

For example, an RTO of four hours means aiming to restore the service within four hours of disruption. An RPO of one hour permits loss of no more than one hour’s data. Backup or replication must be designed and tested accordingly.

Choose RTO within the MTPD; they are different measures. Tighter targets usually cost more, making their selection a business and budget decision as well as a technical one.

How do we build an effective plan?

Continuity is the outcome of a structured process:

  1. Scope and sponsorship: define covered activities and the accountable management sponsor.
  2. Business impact analysis: identify critical processes, dependencies and tolerances.
  3. Risk assessment: examine threats such as cyberattacks, outages, human error and supplier failure.
  4. Continuity strategy: choose measures suited to RTO and RPO targets.
  5. BCP and DRP development: document roles, escalation, communications and recovery runbooks.
  6. Exercises and review: test and maintain the arrangements.

Which continuity strategies are available?

Select the strategy to meet BIA-derived needs:

  • Redundancy and high availability: parallel systems and automated failover for tight recovery targets.
  • Backup and restore: recurring, tested backups, with frequency aligned to RPO.
  • Alternative sites or cloud recovery: arrangements for loss of a primary location or data centre.
  • Manual workarounds: temporary paper-based or manual processes while systems recover.
  • Supplier alternatives: replacement providers and service levels for critical dependencies.

Why must the plan be tested?

An untested plan rests on assumptions. Outdated contacts, missing permissions, unusable backups and overlooked dependencies may prevent execution. Exercises expose these problems before a real incident.

Use complementary levels of testing:

  • Tabletop exercises: key participants walk through decisions, sequence and communications. These are relatively quick and reveal ownership gaps.
  • Technical recovery tests: actually restore backups, test failover and measure RTO/RPO performance.
  • Full simulations: rehearse a larger scenario, preferably isolated from production, to assess the complete process under realistic conditions.

Record lessons after each exercise and update the plans. Testing should recur, typically at least annually and after significant changes.

How does this relate to ISO 22301 and NIS2?

ISO 22301 provides the framework for a Business Continuity Management System (BCMS), connecting BIA, strategy, plans, exercises and continual improvement through a Plan–Do–Check–Act cycle. It turns the elements above into a management system that can be certified. A BCMS also fits alongside an ISO/IEC 27001 ISMS.

NIS2 makes continuity measures a legal obligation for organisations within scope. Failures can lead to regulatory action and fines depending on classification, the infringement and applicable Hungarian rules. Management oversight and evidence of implementation are essential.

How zemITis helps

Our CISA, CISM and ISO 27001 Lead Auditor specialists support BIA, recovery targets, BCP/DRP development and exercises, with independent peer review. Whether you need standalone ISO 22301 preparation or continuity capabilities within NIS2 preparation, a free consultation can establish the next steps. Our security officer service can also maintain plans and coordinate recurring tests.

Next steps

Let’s plan your next step.

Risk assessment, compliance preparation or ongoing expert support: we help you choose the right approach for your organisation.