Business Continuity Plan (BCP)
Definition
Business Continuity Plan (BCP)
A business continuity plan (BCP) is a documented playbook that keeps critical operations running through cyberattacks, outages, and other disasters. The plan maps threats, quantifies impact per process, assigns recovery owners, and sets recovery-time targets that carry a company through the incident.
The plan sits inside a broader risk-management program. Where a disaster recovery plan focuses on IT restoration alone, a BCP also covers people, facilities, suppliers, and communications — the full stack needed to keep serving customers.
Most large enterprises now treat the BCP as a board-level document. Regulators such as the US Federal Reserve, the UK FCA, and Singapore’s MAS expect regulated firms to test plans on a fixed cadence.
Firms also need one to pass SOC 2 reviews and sign enterprise contracts. A well-written BCP names three artifacts: a business impact analysis that ranks each process by revenue and safety exposure, a threat register that pairs each disruption with its likelihood, and a set of runbooks that translate strategy into steps a duty manager can execute without pause.
Skip any of the three and the plan drifts into shelfware.
Key takeaways
- A BCP keeps core operations alive during a disruption, not just IT systems.
- Most plans move through five stages: risk analysis, strategy design, implementation, testing, and maintenance.
- The plan names owners, contact trees, workarounds, and recovery-time objectives (RTOs) per function.
- A disaster recovery plan is a narrower, IT-focused component inside the BCP.
- Boards, insurers, auditors, and enterprise buyers now expect an annually tested plan.
How it works
A BCP works by identifying the processes that must keep running, quantifying the loss if they stop, then pre-building the people, technology, and workarounds that keep those processes alive under stress. The plan is written once, tested repeatedly, and updated on a fixed cadence.
Most programs run a five-stage lifecycle drawn from ISO 22301 and NIST’s SP 800-34 contingency planning guide.
| Stage | Focus | Typical output |
|---|---|---|
| Risk analysis | Threat mapping and business-impact analysis | Prioritized process list with RTO/RPO targets |
| Strategy design | Choose the recovery approach per process | Playbook: workaround, backup site, third-party fallback |
| Implementation | Stand up sites, tools, and contact trees | Runbooks, standby contracts, backup infrastructure |
| Validation | Tabletop and live-fire testing | Test report with gaps and fixes |
| Maintenance | Cadence review and post-change updates | Version log, refreshed owner list |
Two backup layers usually sit under the plan. On-site backups give teams fast access to recent data, while off-site or cloud backups protect against fire, flood, or ransomware that reaches the primary site.
The business impact analysis (BIA) done during risk analysis pins a dollar-per-hour cost on each process. That number is what drives spending on backup capacity and hot-site design.
Recovery time objective (RTO) and recovery point objective (RPO) round out the architecture. Ready-made frameworks such as Smartsheet’s business continuity plan templates can shortcut the drafting stage for small teams that lack in-house risk staff.
Examples
BCPs look different by industry, but the muscle memory is the same: name a threat, name the process it hits, name the workaround. The four cases below are drawn from real incidents that reshaped how modern plans are written.
Maersk, 2017 NotPetya attack. The Danish shipping giant lost 4,000 servers and 45,000 PCs within hours. Its BCP had not segmented domain controllers, so restoration took ten days and roughly USD 300 million in losses.
Maersk then rewrote the plan around network segmentation, offline backups, and a documented clean-room rebuild sequence.
AWS US-East-1 outage, December 2021. When a single Amazon region went down for seven hours, companies without multi-region BCPs saw checkout, streaming, and IoT services stall.
Firms with pre-configured failover to US-West-2 kept customers online. The event pushed fintech CTOs to bake regional failover directly into their runbooks.
Philippines BPO sector, Typhoon Rai (Odette), December 2021. Major providers including Concentrix, TDCX, and TaskUs invoked BCPs that shifted seats to Bacolod, Cebu, or Manila hubs and moved agents to secure work-from-home setups within 24 hours.
Client SLAs held because the plan had named backup sites in advance.
CrowdStrike Falcon update, July 2024. A faulty sensor update grounded flights and knocked out hospital systems worldwide.
Companies whose BCP covered vendor-side software failures — offline reboot procedures, manual dispatch fallbacks — recovered inside hours. Those without spent days on rebuilds.
Related terms
A BCP borrows structure from several adjacent operations disciplines — vendor management, IT operations, HR, compliance, and communications all sit nearby and share templates, playbooks, and metrics with the continuity function. The list below flags the closest neighbors, so a reader can build a full risk-and-continuity vocabulary. Each links to a fuller Outsource Accelerator glossary entry for deeper reading.
- Business Process Outsourcing (BPO): third-party delivery model that a BCP must factor into its supplier-failure scenarios.
- Service Level Agreement (SLA): contractual uptime and response commitments a BCP is expected to protect.
- Key Performance Indicator (KPI): the metrics used to prove a BCP kept operations running to target.
- Standard Operating Procedure (SOP): the day-to-day process document a BCP replaces with a shortened crisis version.
- Business Process Automation (BPA): the automation layer whose failure modes need to be mapped inside the BCP.
- Knowledge Process Outsourcing (KPO): judgement-heavy offshored work that needs its own continuity clauses.
- Call Center: a common function requiring named backup sites and remote-agent playbooks inside a BCP.
FAQ
How is a BCP different from a disaster recovery plan?
A BCP covers the whole business: people, processes, suppliers, communications, and IT. A disaster recovery plan is narrower and focuses on restoring IT systems and data. The disaster recovery plan usually sits inside the BCP as one workstream, so continuity is the wider container.
Who owns the BCP inside a company?
Most firms name a business continuity manager or risk officer as the plan owner. That person coordinates department leaders, IT, security, HR, communications, and legal. In regulated industries the board or a risk committee signs off on the plan and test results.
How often should a BCP be tested?
Most standards call for annual full-scale tests plus quarterly tabletop exercises. Regulated banks, healthcare providers, and airlines test more often. Any material change to sites, vendors, or critical systems should trigger an out-of-cycle review.
What are RTO and RPO?
Recovery time objective (RTO) is the maximum time a process can stay down before it damages the business. Recovery point objective (RPO) is the oldest data loss the business can accept. Together they drive backup frequency, hot-site design, and vendor selection.
Do small businesses really need a BCP?
Yes. Insurers, enterprise buyers, and SOC 2 auditors now ask for one. A one-page plan that names a backup site, cloud backups, and a phone tree is often the deciding factor when a small vendor bids for an enterprise contract.
Explore the Outsource Accelerator hubs for tools that help you find continuity-tested BPO partners and vet their crisis playbooks before you sign.







Independent




