Business continuity plan (BCP): method and example

Definition, how it differs from DRP and IT continuity, business impact analysis, steps, testing, ISO 22301 and the NIS 2 and DORA requirements, with a worked example.

· 10 min read
Illustration: an activity curve holding steady through a spike, under an orange disc

A business continuity plan (BCP) is the set of measures, resources and procedures that enable an organisation to keep its essential activities running during a major crisis (cyberattack, outage, disaster, pandemic), in degraded mode if needed, and then return to normal. It is based on a business impact analysis (BIA) that sets, for each activity, a maximum tolerable period of disruption and a maximum tolerable data loss. NIS 2, DORA and the ISO 22301 standard make it an explicit requirement.

01

What is a business continuity plan (BCP)?

The SGDSN guide (France's General Secretariat for Defence and National Security), still the French reference, describes the BCP as the document that sets out the organisation's continuity strategy and all the arrangements for continuing and then resuming its activities after an event that seriously disrupts normal operations. In other words, the BCP answers a simple question: if tomorrow our premises, our IT or a key supplier disappear, how do we keep serving our customers, patients or users?

The BCP is therefore not limited to IT. It covers people (mass absence, loss of key skills), premises, suppliers and service providers, energy, and of course the information system. But in recent years, the scenario that shapes most plans is the ransomware attack: within hours it takes down every application, email and sometimes telephony, and rebuilding takes weeks. This is why the French cybersecurity agency, ANSSI, stresses preparing business continuity alongside the technical response.

02

BCP, DRP, IT continuity and crisis management: what are the differences?

These terms are often confused, even in tender documents. Yet they refer to complementary arrangements that come into play at different times and are owned by different people. Select them below to place them on an incident timeline.

Who does what when the incident strikes
  • Crisis

    Crisis management

    Goal
    Decide, coordinate and communicate during the event.
    Owner
    Executive crisis team, senior management.
    Example
    Activating the crisis team, making trade-offs, communicating with customers and authorities.
  • BCP

    Business continuity plan

    Goal
    Keep essential activities running, in degraded mode if needed, then return to normal.
    Owner
    Senior management and business units, with the business continuity manager.
    Example
    Taking orders by phone and on paper while the ERP is unavailable.
  • ITCP

    IT continuity plan

    Goal
    Prevent the incident from interrupting the information system: redundancy, automatic failover.
    Owner
    IT department.
    Example
    Failing an application over to a second data centre with no noticeable outage.
  • DRP

    Disaster recovery plan

    Goal
    Restore the information system and data after an interruption.
    Owner
    IT department, with business units validating the data.
    Example
    Rebuilding servers and restoring offline backups after a ransomware attack.
BCP, DRP, IT continuity and crisis management compared
PlanQuestion it answersScopeOwner
BCP (business continuity plan)How do we keep operating during the crisis?The whole organisation: business units, people, premises, suppliers, ITSenior management and business units
ITCP (IT continuity plan)How do we stop the IT system from going down?Critical infrastructure and applicationsIT department
DRP (disaster recovery plan)How do we restart IT after the outage?Systems, backups, dataIT with business units
Crisis managementWho decides, and how do we communicate?Steering, trade-offs, communicationCrisis team

IT continuity in the broad sense covers both the ITCP and the DRP: the part of the plan that concerns the information system. On its own it is not enough, because an organisation whose servers restart in four hours can still be paralysed if nobody knows how to process orders in the meantime. Conversely, degraded-mode business procedures only make sense if IT comes back within the promised time.

03

The business impact analysis (BIA), the starting point of the BCP

The business impact analysis (BIA) is the step that sets a real BCP apart from a binder of procedures. It involves listing the organisation's activities, identifying the essential ones, then measuring how their impacts worsen with the length of the interruption: after four hours, a day, a week. The SGDSN recommends assessing these impacts from several angles: human, financial, contractual, legal, environmental, social and reputational.

Essential activities and dependencies

For each essential activity, the BIA identifies the resources it depends on: people and skills, premises, applications and data, service providers, raw materials. These dependencies often reveal unexpected weak points, such as a single managed-services provider or business software hosted by a vendor with no fallback plan. They extend the thinking on availability needs carried out in the DICP classification.

MTPD and maximum data loss, RTO and RPO

The BIA produces two quantified targets per activity:

  • the maximum tolerable period of disruption (MTPD): beyond it, the consequences become unacceptable. The recovery time objective (RTO) must stay below it;
  • the maximum tolerable data loss: the amount of data, expressed as time, that can be lost. It corresponds to the recovery point objective (RPO) and determines how often backups or replication must run.

ANSSI's draft ReCyF framework, published for the French transposition of NIS 2, asks essential entities to document these two values for each activity or service. The simulator below shows what happens when actual capabilities do not meet these targets.

Simulator · MTPD / MTDL vs RTO / RPO
Activity assessed
Data loss 24 h · target 4 h Off target
Downtime 2 days · target 24 h Off target
Illustrative values: each activity's maximum tolerable downtime (MTPD) and maximum tolerable data loss (MTDL) come from your own business impact analysis (BIA). Logarithmic time scale.
04

How to build a business continuity plan in 7 steps

The SGDSN approach and the ISO 22301 standard agree on the essentials. Here is a seven-step outline that works for an SME as well as a group.

  1. Frame the project. Get a mandate from management, appoint an owner, set the scope (sites, subsidiaries, activities) and the obligations to meet (contracts, NIS 2, DORA, sector requirements).
  2. Carry out the BIA. Identify essential activities, their dependencies, their MTPD and maximum data loss, through interviews with each business unit.
  3. Analyse the risks. Identify the scenarios that could interrupt these activities: ransomware, a provider outage, fire, staff unavailability. An existing risk analysis, for example carried out with EBIOS RM, provides a solid basis.
  4. Choose the continuity strategy. For each activity, decide how to meet the targets: fallback site, remote working, IT redundancy, safety stock, a second supplier, manual procedures. Make trade-offs based on cost.
  5. Write the plan and procedures. Crisis organisation, activation criteria, quick-reference sheets per business unit, ITCP, DRP, communication plan, contact lists.
  6. Put the resources in place. Backup contracts, isolated backups, fallback equipment, staff training.
  7. Test, then improve. Exercise the plan, learn the lessons and keep it up to date whenever the organisation or systems change.
05

What does a business continuity plan contain?

A usable BCP consists of a steering document and a set of operational sheets. It typically includes:

  • the context and objectives: scope, obligations, essential activities and their recovery targets;
  • the crisis scenarios selected and the working assumptions;
  • the crisis organisation: executive crisis team, operational teams, roles, deputies, activation and stand-down criteria;
  • the continuity strategies and procedures for each activity, including degraded modes;
  • the ITCP and DRP, with the order in which applications are restarted;
  • the internal and external communication plan, which ANSSI covers in its guide on cyber crisis communication;
  • the contact lists of people who can be mobilised and external contacts (insurer, providers, authorities), available on paper: a BCP stored only on the server encrypted by the ransomware is of no use;
  • the testing programme and the rules for updating the plan.
06

Testing the BCP: exercises and keeping it operational

An untested plan is a hypothesis. The SGDSN provides for several levels of verification: a critical review of the documents, ideally by a third party; technical tests, such as failing over to a backup site or restoring backups; and exercises that check the procedures are known and can be carried out in time.

Three exercise formats

  • The tabletop exercise: the crisis team walks through a scenario around a table. Inexpensive, it quickly exposes the organisation's blind spots.
  • The technical test: a full restore of an application from backups, or a site failover, measuring actual times against the RTO and RPO.
  • The full-scale crisis exercise: a realistic simulation over several hours, with injected events. ANSSI's guide on organising a cyber crisis exercise explains how to prepare one.

Each exercise leads to a lessons-learned review and an improvement plan. Keeping the BCP operational also means updating it when the organisation changes: a new application, a new provider, a move, a reorganisation.

07

ISO 22301, the business continuity standard

ISO 22301 specifies the requirements for a business continuity management system (BCMS). It follows the common structure of ISO management system standards, the same as ISO 27001: context, leadership, planning, support, operation, performance evaluation, improvement. The current version dates from 2019; an amendment published in 2024 adds consideration of climate change. In late 2025 ISO decided to revise the standard, and a new version is being drafted.

ISO 22301 does not say how to write a BCP, but how to manage it over time: objectives, responsibilities, BIA, testing, internal audits, management review. It comes with guidance such as ISO 22313 (guidelines) and ISO/TS 22317 (BIA). If you already run an ISMS certified to ISO 27001, whose Annex A also addresses continuity, you will reuse much of the machinery.

08

Is a business continuity plan mandatory? NIS 2, DORA and healthcare

NIS 2

Article 21 of the NIS 2 Directive lists among the minimum risk-management measures "business continuity, such as backup management and disaster recovery, and crisis management". In France, ANSSI's draft ReCyF framework, still a working version, details what this covers: backup and restore procedures tested at least once a year, backups protected against incidents that would make them unusable, and, for essential entities, a BCP and DRP suited to cyber-originated crises and consistent with the recovery targets. For the full picture, read our article on NIS 2 and see our compliance campaigns module.

DORA and digital operational resilience

For banks, insurers and other financial entities, the DORA regulation, which has applied since 17 January 2025, is the most detailed. Its Article 11 requires an ICT business continuity policy, response and recovery plans, a BIA, a crisis management function, and tests at least yearly and after any substantive change, including cyberattack and switchover scenarios. Article 12 covers backups, restoring onto separate systems, and setting recovery time and recovery point objectives for each function. See how our vendor risk management module covers ICT third-party providers.

Healthcare

In French healthcare institutions, the CaRE programme run by the national digital health agency (ANS) devotes an entire domain to business continuity and recovery, with a formal continuity and recovery plan for critical activities and regular exercises operating in degraded digital mode. The ANS explains how the BCP exercise carried out in this framework relates to the annual cyber crisis exercise expected of institutions.

Finally, continuity increasingly depends on your suppliers: an unavailable software vendor or hosting provider can stop your activities as surely as a direct attack. Supply chain attacks are the most recent illustration.

09

Business continuity plan example: an SME facing ransomware

Take a fictitious industrial SME with 180 employees that manufactures and ships parts for automotive customers. Its reference scenario: ransomware encrypts the ERP, email and file servers on a Monday morning. Here is a simplified version of its BIA and strategy.

Simplified BIA and continuity strategy example (illustrative values)
ActivityMTPDMax. data lossPlanned degraded mode
Order shipping24 h4 hPre-filled paper delivery notes, the day's order list printed every evening
Production48 h24 hThe week's production plans printed, manual control of the lines
Invoicing5 days24 hDeferred invoicing, batch catch-up after restoration
PayrollDepends on the calendar1 monthRepeat the previous month's payroll transfer, adjust afterwards

To meet these targets, the SME opts for a daily ERP backup plus an offline copy, out of reach of an attacker who has taken over the network; a contract with a provider able to rebuild the infrastructure within 48 hours; spare workstations not joined to the domain; a five-person crisis team with deputies; and printed quick-reference sheets for shipping and production. The first tabletop exercise reveals that nobody knows whom to call at the insurer: the paper contact list is completed the same day. The restore test shows an actual RTO of 30 hours for the ERP, beyond the shipping MTPD: the company decides to print the next day's orders every evening, which makes the target achievable without heavy investment.

10

How Phinasoft supports your continuity programme

Phinasoft is not a BCP-writing tool, but it supports the building blocks that feed the plan and make it demonstrable. The risk analysis module, with an EBIOS RM label from ANSSI and ISO 27005 compatibility, helps you identify the scenarios that threaten your essential activities. The NIS 2 and DORA frameworks, part of a catalogue of more than 20 frameworks, let you measure compliance with supporting evidence, including through campaigns across subsidiaries or sites. Third-party assessment covers your critical providers, and action plans are tracked over time with clear reports for management. To see for yourself, request a demo.

Summary

01

Keep going, not just repair

The BCP keeps essential activities running during a crisis, in degraded mode if needed. The DRP and IT continuity plan, which are more technical, restore or protect the information system.

02

It all starts with the BIA

The business impact analysis sets a maximum tolerable downtime and a maximum tolerable data loss for each activity. Technical solutions must meet these targets, otherwise the plan stays theoretical.

03

A regulatory requirement

NIS 2, DORA and healthcare programmes require documented, tested continuity plans. ISO 22301 provides the framework to manage them over time.

Frequently asked questions

What is the difference between a BCP and a DRP?

A business continuity plan (BCP) aims to keep essential activities running during a crisis, in degraded mode if needed, and covers the whole organisation: people, premises, suppliers and IT. A disaster recovery plan (DRP) is more technical: it describes how to restore the information system and data after an interruption. The DRP is one building block of the BCP.

Is a business continuity plan mandatory?

No law requires every company to have a BCP. It becomes mandatory for financial entities under DORA, for entities covered by NIS 2, which must address business continuity and crisis management, and in several regulated sectors such as healthcare. Customers, insurers and large clients also increasingly require one.

What do RTO and RPO mean?

The recovery time objective (RTO) is the target time to restore an activity after an interruption; it must stay below the maximum tolerable period of disruption. The recovery point objective (RPO) is the maximum amount of data, expressed as time, that can be lost, which determines how often backups must be taken.

How often should a business continuity plan be tested?

At least once a year is standard practice, and it is what DORA requires of financial entities, which must also test after any substantive change. It helps to alternate tabletop exercises, technical restore tests and fuller crisis exercises, then update the plan after each lessons-learned review.

Who is responsible for the BCP in a company?

Senior management is accountable and approves the continuity strategy. A business continuity manager, often reporting to the risk manager, the CISO or operations, runs the programme. Business units define their needs in the BIA, and IT implements the IT continuity and disaster recovery plans.

What is ISO 22301?

ISO 22301 is the international standard that specifies requirements for a business continuity management system. The current version dates from 2019, with a 2024 amendment on climate change, and a revision is under way. Organisations can be certified against it by an accredited body.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.