Skip to content
Backup & continuity

Business continuity plan vs disaster recovery plan: the difference and where to start

BCP or DRP? A clear difference, business impact analysis, degraded modes, roles and a yearly exercise: how an SMB in Morocco keeps its business running.

By the ALLSAFE SOLUTIONS engineering team30 September 20268 min read
IT support

The DRP (disaster recovery plan) restarts IT after an outage; the BCP (business continuity plan) keeps you serving customers during that outage. The first is technical: backups, restores, the order in which systems come back. The second is about organisation: who decides, how orders are taken when the ERP is down, how calls get through when the switchboard is cut off, what customers are told. An SMB does not need a two-hundred-page binder to have a useful BCP. It needs to know which processes keep it alive, how long they can stop, and what everyone does in the meantime.

We have already covered the technical side in our guide to the disaster recovery plan for SMBs. This article deals with the earlier, broader step: organising business continuity, in Morocco or elsewhere, with proportionate means.

BCP and DRP: the difference in one sentence each

Business continuity plan (BCP) Disaster recovery plan (DRP)
Question it answers How do we keep working during the crisis? How do we bring systems back after the outage?
Scope The whole company: processes, people, suppliers, communication IT: servers, data, network, applications
Owner Management, with business managers The IT manager or managed service provider
Typical means Degraded modes, second internet link, call forwarding, crisis team Backups, replication, replacement hardware, restore procedures
How it is tested Tabletop exercise or simulation with the teams Timed restore in an isolated environment

The DRP is therefore a chapter of the BCP. A company with only a DRP will know how to restart its server, but not necessarily how to answer the phone while it is off. Conversely, a BCP without a tested DRP rests on a promise nobody has checked.

Step 1: business impact analysis, in plain language

Specialists call it a BIA (Business Impact Analysis). For an SMB, it means bringing management and two or three business managers together around three questions, process by process:

  1. What stops if this tool or service becomes unavailable? Collecting payments, invoicing, delivering, booking appointments, answering customers, paying salaries.
  2. After how long does the outage become serious? Not in theoretical figures: in concrete consequences, such as a truck that does not leave, a missed tax deadline or customers calling a competitor.
  3. What does the process depend on? An application, an internet connection, a single person who knows how to do it, an external supplier.

The result fits on one page: the list of vital processes, ranked from most to least urgent, with their dependencies. This is often when you discover that a process thought to be secondary, such as access to the bank portal or sending payslips, relies on a single computer or a single person.

Step 2: set RTO and RPO per application

For each application that supports a vital process, management sets two objectives:

  • the RTO, the acceptable downtime before returning to normal;
  • the RPO, the amount of work you accept to lose, which sets the backup frequency.
Application Process supported Target RTO Target RPO Planned degraded mode
ERP / invoicing Orders, invoicing, stock To be decided with management To be decided Numbered paper order forms, deferred entry
Email Customer and supplier exchanges To be decided To be decided Web access from any device, printed contact list
Telephony Reception, customer service To be decided Not applicable Forwarding to mobiles, crisis greeting message
Internet access Everything in the cloud To be decided Not applicable Second link, mobile tethering as a last resort
File shares Files, contracts, drawings To be decided To be decided Copy of essential documents accessible off site

The columns are deliberately left open here: these values depend on your business and your budget. What matters is that they are written down, approved by management and then compared with what the infrastructure can actually deliver.

Step 3: write the degraded modes

This is the heart of the BCP and the part most often missing. A degraded mode answers the question: “the tool is down, how do we carry on?” Four cases cover most SMBs.

Telephony: never let the phone ring out

A properly configured IP phone system can automatically forward calls to mobiles or another site if the main link fails, and play a suitable greeting. With a hosted solution or a mobile app, teams stay reachable from anywhere. Our article on the mistakes that degrade IP telephony shows how to prepare these overflow rules, and our 3CX IP telephony offer builds them in from installation.

Email: access that does not depend on the office

Cloud email remains reachable from a browser or a phone, even if the office has no network. Users still need to know their credentials, MFA must work on their mobile, and a list of key contacts must exist outside the mailbox itself.

ERP: the paper procedure nobody likes, but that saves the day

When the ERP is unavailable, orders must not get lost. A set of numbered forms, one person in charge of collecting them and a clear rule for re-entering them after recovery are often enough. The BCP also states what is not done in degraded mode, for example granting customer credit without checking the outstanding balance.

As soon as the ERP, email or telephony are in the cloud, the internet link becomes a single point of failure. A second connection from another operator, ideally over a different technology, with automatic failover on the firewall, changes the picture entirely. Our guides on choosing a business fibre link in Morocco and on multi-site FortiGate SD-WAN detail the options, which we deploy in particular with Fortinet.

Step 4: roles and crisis communication

A poorly coordinated crisis often costs more than the outage itself. The BCP names, each with a deputy:

  • The decision-maker, who triggers the plan and arbitrates priorities.
  • The technical coordinator, in-house or managed service provider, who runs the DRP and reports to the decision-maker at set times.
  • Business managers, who activate the degraded modes in their department.
  • The communication lead, who informs staff, customers and suppliers with messages prepared in advance.

Template messages are written in calm times: one for staff, one for customers, one for suppliers and, in case of a personal data breach, the elements needed to assess your obligations under Moroccan law 09-08. The backup channel is defined too: mobile messaging group, call tree, SMS.

Step 5: document it and exercise it once a year

The BCP lives in a short document, available in print and outside the information system: vital processes, objectives, degraded modes, roles, contacts, template messages and a pointer to the technical DRP.

At least once a year, a tabletop exercise brings the players together around a realistic scenario: “Monday morning, the head office internet link is down and the ERP is unreachable.” Everyone explains what they do. Gaps show up quickly: an outdated number, a form nobody can find, a deputy who does not know their role. Each gap leads to a dated correction.

Cost and benefit: reasoning without magic numbers

There is no standard budget for a BCP. The right reasoning compares, process by process, what one day of downtime costs (lost revenue, penalties, hours paid without output, reputation) with what the continuity measure costs (second link, licence, hardware, preparation time). Many measures are inexpensive: call forwarding rules, paper forms, a contact list, a yearly exercise. Others, such as a full standby site, are only justified for activities that tolerate almost no interruption.

The most common mistakes

  • Confusing BCP with backup: a backup protects data, not the ability to serve customers during the restore.
  • Letting IT set priorities alone, when they belong to management.
  • Forgetting the internet link when everything has moved to the cloud.
  • Storing the plan on the server it is meant to help rebuild.
  • No deputies: the only person who knows how is on leave on the day.
  • Never exercising: the plan ages without anyone noticing.

Checklist: your business continuity today

  • Vital processes are listed and ranked with management.
  • Each critical application has a written RTO and RPO.
  • A degraded mode exists for telephony, email, ERP and internet.
  • A second internet link, with automatic failover, protects cloud services.
  • Crisis roles are assigned, each with a deputy.
  • Template messages for staff, customers and suppliers are ready.
  • The BCP exists in print, outside the information system.
  • The technical DRP is tested and the BCP exercised at least once a year.

How we do it

We start from the free initial audit, which identifies dependencies and single points of failure. We then run a short impact analysis with management and propose measures in order of best risk reduction for the effort: immutable backup and a tested DRP as part of our backup and business continuity offer, with Veeam; link and telephony redundancy; degraded modes written with your teams. Under our managed IT services, 24/7 monitoring detects failures and our engineers handle a critical incident in under 15 minutes. See concrete examples in our case studies.

To find out where your company is vulnerable and where to start, request your free audit: we reply within 24 business hours.

Frequently asked questions

What is the difference between a BCP and a DRP?

The disaster recovery plan (DRP) describes how to bring IT systems back after an outage. The business continuity plan (BCP) is broader: it describes how the company keeps operating during the crisis, with backup means, degraded procedures, roles and communication. The DRP is one part of the BCP.

Where should an SMB start: BCP or DRP?

With a simple impact analysis: which processes stop the business if they are interrupted, and after how long. It shows where a DRP is enough and where continuity measures are needed, such as a second internet link or call forwarding.

What is a degraded mode?

A way of working planned in advance for when a tool is unavailable: taking orders on numbered paper forms, forwarding the switchboard to mobiles, failing over to a second internet connection. It lets you keep serving customers until recovery.

How often should a business continuity plan be tested?

At least once a year through a tabletop exercise or a simulation with business managers, on top of the technical restore tests of the DRP. The plan is also reviewed after every major change: office move, new ERP, new provider.

About the editorial team

ALLSAFE SOLUTIONS

Network, security and cloud engineers

Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.

LinkedIn
← All articles
CallWhatsAppFree audit