Business Continuity Plan (BCP)
Definition
Business Continuity Plan (BCP)
A business continuity plan (BCP) is a written playbook that keeps core operations running through a cyberattack, an outage, or a disaster. It ranks each process by risk, names who owns recovery, and sets how fast the service must be back online.
The plan sits inside a wider risk management program. Where a disaster recovery plan restores IT alone, a BCP also covers people, facilities, suppliers, and communications — the full stack you need to keep serving customers.
Most large enterprises treat the BCP as a board level document. Regulators including the US Federal Reserve, the UK Financial Conduct Authority (FCA), and the Monetary Authority of Singapore (MAS) expect regulated firms to test plans on a fixed cadence.
A working BCP names three artifacts. A business impact analysis ranks each process by revenue and safety exposure. A threat register pairs each disruption with a likelihood. Runbooks turn strategy into steps a duty manager can run without pausing.
Key takeaways
- A BCP keeps core operations alive during a disruption, not just IT systems.
- Most plans move through five stages: risk analysis, strategy design, implementation, testing, and maintenance.
- The plan names owners, contact trees, workarounds, and a recovery time objective (RTO) for every function.
- A disaster recovery plan is a narrower, IT focused component sitting inside the BCP.
- Boards, insurers, auditors, and enterprise buyers expect a plan tested at least once a year.
How it works
A BCP works by naming the processes that must keep running, pricing the loss if they stop, then building the people, technology, and workarounds that hold those processes up under stress. Test it repeatedly and update it on a fixed cadence.
Most programs run a five stage lifecycle drawn from ISO 22301, first published in 2012 and revised in 2019, and from NIST’s SP 800-34 contingency planning guide, whose Revision 1 dates to 2010.
| Stage | Focus | Typical output | Example target |
|---|---|---|---|
| Risk analysis | Threat mapping and business impact analysis | Ranked process list | Top 10 processes priced per hour |
| Strategy design | Recovery approach per process | Workaround, backup site, or third party fallback | RTO of 15 minutes to 72 hours |
| Implementation | Sites, tools, and contact trees | Runbooks, standby contracts | 3 data copies, 2 media, 1 offsite |
| Validation | Tabletop and live fire testing | Test report with gaps and fixes | 1 full test and 4 tabletops a year |
| Maintenance | Cadence review and change updates | Version log, refreshed owner list | Review every 6 to 12 months |
Two backup layers usually sit under the plan. On site copies give teams fast access to recent data, while off site or cloud copies protect against fire, flood, or ransomware that reaches the primary site.
The business impact analysis run during stage one pins a cost per hour on each process. That number drives every spending decision after it, from backup capacity to hot site contracts.
A trading desk losing USD 50,000 an hour earns a very different budget from a reporting job losing USD 200 — same plan, different spend.
Recovery time objective (RTO) and recovery point objective (RPO) finish the architecture. RTO is the clock; RPO is the data.
A payments queue might carry a 15 minute RTO and a near zero RPO, while a monthly reporting job sits at 72 hours and a full day of lost records.
Ready made frameworks such as Smartsheet’s business continuity plan templates can shortcut the drafting stage for small teams with no in house risk staff.
Examples
BCPs look different by industry, but the muscle memory is the same: name a threat, name the process it hits, name the workaround. The four cases below come from real incidents that reshaped how modern plans get written.
- Maersk, 2017 NotPetya attack. The Danish shipping giant lost 4,000 servers and 45,000 PCs in hours. Its plan had not segmented domain controllers, so restoration ran ten days and cost roughly USD 300 million, after which Maersk rebuilt around offline backups.
- Amazon Web Services US-East-1 outage, December 2021. The Amazon Web Services (AWS) region went dark for about seven hours, stalling checkout, streaming, and connected device traffic. Firms with tested failover to US-West-2 stayed open.
- Philippine outsourcing sector, Typhoon Rai, December 2021. Providers including Concentrix, TDCX, and TaskUs moved seats to Bacolod, Cebu, or Manila hubs and shifted agents to secure home setups inside 24 hours. Backup sites had been named in advance.
- CrowdStrike Falcon update, July 2024. A faulty sensor update grounded flights and hospital systems worldwide on 19 July. Plans covering vendor side failure, with offline reboot steps and manual dispatch, recovered inside hours — others spent days rebuilding.
The pattern repeats. Every firm above owned the same technology the survivors did. What separated them was a written answer to three questions — who decides, who calls whom, and what runs manually while systems are down.
Related terms
A BCP borrows structure from nearby disciplines. Vendor management, IT operations, HR, compliance, and communications all share templates and metrics with it. The terms below are its closest neighbors, each with a fuller Outsource Accelerator entry behind it.
- Business Process Outsourcing (BPO): third party delivery model a BCP must cover in its supplier failure scenarios.
- Service Level Agreement (SLA): contractual uptime and response commitments the plan is built to protect.
- Key Performance Indicator (KPI): the metrics that prove a plan kept operations running to target.
- Standard Operating Procedure (SOP): the everyday process document a crisis runbook temporarily replaces.
- Business Process Automation (BPA): the automation layer whose failure modes belong inside the threat register.
- Knowledge Process Outsourcing (KPO): judgement heavy offshored work that needs its own continuity clauses.
- Call Center: a function that needs named backup sites and remote agent playbooks.
FAQ
How is a BCP different from a disaster recovery plan?
A BCP covers the whole business: people, processes, suppliers, communications, and IT. A disaster recovery plan is narrower and restores IT systems and data. The disaster recovery plan usually sits inside the BCP as one workstream.
Who owns the BCP inside a company?
Most firms name a business continuity manager or risk officer as the plan owner. That person coordinates department heads, IT, security, HR, communications, and legal. In regulated industries a board risk committee signs off on the plan and the test results.
How often should a BCP be tested?
Most standards call for one full scale test a year plus quarterly tabletop exercises. Regulated banks, hospitals, and airlines test more often. Any material change to a site, a vendor, or a critical system should trigger a review outside the normal cycle.
What are RTO and RPO?
Recovery time objective (RTO) is the longest a process can stay down before it damages the business. Recovery point objective (RPO) is the oldest data loss you can accept. Together they set backup frequency, hot site design, and vendor choice.
Do small businesses really need a BCP?
Yes: insurers, enterprise buyers, and SOC 2 auditors all ask for one, and a single page plan naming a backup site, cloud backups, and a phone tree often decides whether a small vendor wins an enterprise contract.
Explore the Outsource Accelerator hubs to find continuity tested BPO partners and vet their crisis playbooks before you sign.







Independent




