Business Continuity Plan

Last updated

Definition

A business continuity plan (BCP) is the client's documented answer to how the business keeps operating through a disruption – a cyberattack, a fire, a flood. It covers people, premises, communications, suppliers, and manual workarounds, not just systems. A disaster recovery (DR) plan is the technical subset: how the IT environment is restored, in what order, within the agreed RTO and RPO.

Why it matters to an MSP

The distinction matters because it defines what you deliver versus what the client owns. You own the DR plan: the recovery runbook, restore order and dependencies, where credentials live, vendor and ISP numbers, and the decision tree between restoring in place, virtualizing on the appliance, or failing over to DRaaS. The client owns the BCP: who decides to invoke it, how staff are contacted when email is down, whether the practice can see patients on paper for two days, where people work if the office is unusable, and what customers and regulators are told. You contribute the technology sections and the recovery objectives, but refuse to be sole author of the rest – whoever writes the whole BCP owns every decision in it when it fails.

Commercially, the BCP is where RTO and RPO get their business meaning. A four-hour recovery objective is a technical target until it is written next to "we lose roughly $8,000 per hour the ERP is down," at which point Tier 1 BCDR pricing sells itself. It is also a common ask: cyber-insurance applications, HIPAA risk analyses, and SOC 2 and CMMC assessments all look for a documented and tested plan. Running an annual BCP review and tabletop exercise is a natural vCIO deliverable, because it turns backup from a line item into a business conversation.

Related terms: RTO, RPO, DRaaS, vCIO