Business continuity plan vs disaster recovery plan: what North East organisations need

Business Continuity vs Disaster Recovery.

Last updated: 25 September 2026 by Damien Harrison, Director of Client Success. Change log: first published; regulatory and statistical references checked against primary sources on 25 September 2026.

A disaster recovery plan gets your systems and data back. A business continuity plan keeps the organisation serving clients while that happens, covering people, decisions, suppliers and communications. Many organisations have the first and assume it covers the second.

Tuesday, 7.40am. A legal practice in Stockton-on-Tees opens up to find its files encrypted. By Thursday afternoon the IT provider has restored everything from backup. The restore is clean and nothing is lost.

The practice still loses most of a week.

Fee earners spend two days working from personal phones because nobody set up an alternative way in. No one has clear authority to tell clients what has happened, so three different people give three different versions. The practice manager rings the insurer’s incident line and cannot answer basic questions about what data was affected. A completion slips, and one client hears about the incident from someone else before the firm tells them.

This is a composite of a pattern we see, rather than one client’s story. If you are a finance or operations director, the uncomfortable part will be familiar. The technology had an owner. Everything else defaulted to whoever happened to be nearest, and on a bad week that tends to be you.

It is also common. The government’s Cyber Security Breaches Survey 2025/2026 found that only 44% of small businesses had a business continuity plan covering cyber security, down from 53% the year before.

This article separates the two plans, sets out what a continuity plan needs to contain, and ends with three things you can put in place this week before a full plan exists.

What is the difference between a business continuity plan and a disaster recovery plan?

A business continuity plan (BCP) sets out how the organisation keeps delivering its critical services during any disruption. A disaster recovery plan (DRP) sets out how IT systems and data are restored after a failure. The DRP is one workstream inside the BCP.

The two get used interchangeably, which is where the trouble starts. Here is how they compare side by side.

Business continuity plan

  • Question it answers: how do we keep serving clients and meeting obligations while something is broken?
  • Covers: people, premises, suppliers, client and staff communications, decision-making, spending authority.
  • Owned by: leadership, usually the MD, FD or operations director.
  • Triggered by: any serious disruption, including cyber incidents, loss of premises, supplier failure, severe weather or key staff absence.
  • Measured by: whether critical services continued within the limits the business agreed.

Disaster recovery plan

  • Question it answers: how do we get systems and data back, in what order, and how fast?
  • Covers: backups, restore sequences, infrastructure, Microsoft 365, identity, line-of-business applications.
  • Owned by: IT, whether internal or your managed service provider.
  • Triggered by: technical failure, data loss or compromise.
  • Measured by: recovery time and data loss against the targets the business set.
Diagram showing the disaster recovery plan as one part of a wider business continuity plan
The disaster recovery plan is one part of continuity. The parts around it decide whether clients notice.

Why do so many organisations treat their backups as their plan?

Because most IT support contracts are written around systems, so the person asked “are we covered?” is the person who owns the backups, and their answer is honest as far as it goes.

A reactive support model is accountable for getting the server, the mailboxes and the applications running again. That is a fair scope for a support contract, and nobody at the provider is doing anything wrong by staying inside it. The flaw is structural. The parts of an incident that decide whether clients stay, whether the insurer pays out and whether the regulator is satisfied sit outside that scope, and the contract never says whose they are.

Backup products add to the confusion because they are often sold using continuity language. So organisations buy good backup, test it, and reasonably believe the question is closed. In our experience three failure patterns follow.

The decision vacuum

Nobody has written authority to declare an incident, approve emergency spending or speak to clients. People wait for permission while the clock runs.

The single point of memory

The plan lives in one person’s head, or in a document on the server that has just been encrypted. When that person is on holiday, so is the plan.

The assumed target

IT has decided how long each system can be down. The board has never agreed those numbers, and finds out during the incident that it disagrees.

Who will ask to see your business continuity plan?

Insurers, larger customers, auditors and regulators, and, as the example later in this article shows, investors and lenders. The request usually arrives with a deadline attached and lands on a finance or operations desk.

Cyber insurers Proposal forms commonly ask whether you have a documented and tested incident response plan. Answering yes without one can put a future claim at risk.
Larger customers Supplier security questionnaires often ask whether you have a continuity plan and when it was last tested.
ISO 27001 auditors Annex A 5.29 and 5.30 cover security during disruption and ICT readiness for continuity. Control 5.30 was new in the 2022 revision and expects recovery to be planned and tested.
The ICO UK GDPR Article 32 expects you to be able to restore access to personal data in a timely manner after an incident, and to test the measures you rely on.

Sector regulators add their own layer. In health and care, the NHS Data Security and Protection Toolkit has expected continuity plans to cover communications and data protection obligations since version 8, and the 2025-26 toolkit expected smaller providers to show a test or tabletop exercise within the last twelve months. Version 9 for 2026-27 is now live, so check the current requirements for your category. Our DSPT guide covers this in more detail.

For law firms, the SRA Code of Conduct for Firms does not name a continuity plan, but it requires firms to identify, monitor and manage all material risks to the business, and to be open with clients and explain promptly when things go wrong. Both are hard to meet during an incident without a plan. In financial services, the FCA’s formal operational resilience rules apply to banks, insurers, enhanced scope SM&CR firms and payment and e-money firms, while other regulated firms are still expected to manage operational risk.

None of these can be answered well in an afternoon. The organisations that handle them calmly are the ones that did the work before the form arrived.

How much downtime can your organisation actually tolerate?

You find out through a business impact analysis, which sets two targets for each critical system: a Recovery Time Objective (how long it can be down) and a Recovery Point Objective (how much data, measured in time, you can afford to lose).

The important word is “agreed”. These targets belong to the business, and they should be signed off by the people who carry the consequences. A finance director and an IT lead will often have different instincts about how long payroll can wait, and it is far better to find that out in a meeting room than during an incident.

Illustrative starting points for a 25 to 250 person organisation. Your own targets should come from your business impact analysis.
Service Example RTO Example RPO Who should agree it
Email and Teams 2 to 4 hours 1 hour Operations director
Case, practice or ERP system 4 to 8 hours 15 to 60 minutes MD or head of the relevant service
Finance and payroll 1 working day, less near pay dates 1 to 4 hours Finance director
Telephony 1 to 2 hours Not applicable Operations director
Shared files (SharePoint, OneDrive) 4 hours 1 to 4 hours Operations director

A quick way to put a number on a lost day

Published figures are not much help here. The government survey puts the median perceived cost of a business’s most disruptive breach at £0, because most reported incidents are low-impact phishing attempts that never stop the business. They tell you very little about what a week without your systems would cost.

So work it out for yourself. As an illustration, take 40 staff at an average employment cost of £30 an hour over a 7.5 hour day. If an outage halves their productivity, that is £4,500 a day in paid time that produces little, before you count unbilled work, delayed invoices, emergency IT costs or the client who quietly moves elsewhere. For a fee-earning firm the unbilled time is usually the larger figure.

What should a business continuity plan contain?

Six parts, built in this order. The structure follows ISO 22301, the international standard for business continuity, scaled for an organisation without a dedicated resilience team.

1

Scope and critical services

Decide what the plan covers and which services the business must keep delivering. Being clear about what is out of scope keeps the document usable.

2

Business impact analysis

For each critical service, record its dependencies and the RTO and RPO the business has agreed. This drives every later decision, including how often backups run.

3

Named roles, deputies and authority

Name people, and give every role a deputy. Write down who can declare an incident, who can invoke the plan and who can approve spending, and up to what limit.

4

Activation and communications

Define what triggers the plan and who is told first. Prepare holding messages for staff, clients, suppliers and your insurer. If personal data is involved, a reportable breach must go to the ICO within 72 hours of you becoming aware of it.

5

Recovery procedures

Short checklists for each critical service, including workarounds while systems are down. This is where your disaster recovery plan plugs in, with restore order and named owners.

6

Testing and review schedule

Put the first test date in the document before you sign it off, and set out what triggers a review, such as new systems, new suppliers or changes in key staff.

What you can stabilise this week

A full plan takes weeks. These three things take a few hours and remove most of the confusion from the first day of an incident:

  • Name an incident lead and a deputy, and give them written authority to declare an incident and spend up to an agreed limit.
  • Keep a contact list for staff, key clients, suppliers and your insurer somewhere that does not depend on your own systems, with personal mobile numbers included.
  • Draft one holding statement for clients that can go out within an hour, and get it approved now rather than during the incident.

Does Microsoft back up our Microsoft 365 data?

Microsoft keeps the service running, and protecting your data, accounts and configuration stays with you. Microsoft’s own services agreement advises users to back up content they store on its services regularly.

Recycle bins, retention policies and version history help with the odd deleted file. They help much less when ransomware syncs encrypted files into SharePoint and OneDrive across the whole organisation, or when a compromised administrator account deletes data deliberately.

Microsoft now sells its own Microsoft 365 Backup product, which is a real improvement on native retention. The trade-off is that the backup copies sit inside Microsoft’s cloud alongside the live data. For most organisations in regulated sectors we recommend an independent copy held outside the tenant as well, so a problem inside your Microsoft 365 account cannot reach it.

A disaster recovery plan for Microsoft 365 should cover three things. First, backup of mail, SharePoint, OneDrive and Teams at a frequency that matches the RPO you agreed. A four hour RPO means very little if backups only run overnight. Second, protection and monitoring of Entra ID, because whoever controls your identities controls everything else. Third, a backup of your tenant configuration, including Conditional Access policies, so you can rebuild your security settings as well as your data.

Across the wider estate, the 3-2-1 principle still holds: three copies of your data, on two different types of storage, with one copy offsite. The NCSC has seen ransomware encrypt connected USB drives, network storage and cloud backups as well as live data, so its guidance on ransomware-resistant backups is worth reading. It asks for backups that resist deletion or alteration, the ability to restore an earlier version when later ones are corrupted, and alerts when someone makes significant or privileged changes.

If you want help with this part, see our managed backup and disaster recovery service.

How do you test a continuity plan without disrupting the business?

Start with a tabletop exercise: a facilitated two hour discussion where your leadership team walks through a realistic incident and records every point where they hesitate or disagree.

Tabletops cost little and surface a lot. What happens if the incident lead is on a flight? Who approves paying for temporary office space? Which clients get a phone call rather than an email? The NCSC’s free Exercise in a Box gives you ready-made scenarios covering ransomware, phishing and supply chain attacks, and you do not need to be an expert to run it.

Alongside tabletops, run short practical drills: a contact list call-down, a timed restore of one critical system, or a day where a team works using only the workarounds in the plan. Test at least once a year and again after any significant change. ISO 27001 asks for testing at planned intervals, and the DSPT expects smaller providers to show a test within the last twelve months.

The output of a good test is a short list of gaps, each with an owner and a date. That list is also the evidence an auditor, insurer or major customer will ask for.

Why testing matters: the Gloucester City Council reprimand

After a ransomware attack on Gloucester City Council in December 2021, the ICO issued a reprimand under UK GDPR Article 32. The council had backups, but they were not used: it opted for a full rebuild of its systems, which significantly slowed the recovery of access to personal data. It also had a documented incident response process, which the ICO found was not sufficient for an incident of that scale. The council could not restore access to personal data in a timely manner, could not work out which people were at risk, and did not publish breach notifications until 17 months after its first report to the ICO.

Backups existed and a plan existed. Neither had been tested against a serious scenario, and the gaps only showed up when it mattered.

What does this look like in practice?

A continuity plan is usually filed under risk. For one Tees Valley software developer, it became part of a funding case.

Organisation Software developer, Tees Valley
Trigger Seeking financial support. The funder required a business-wide continuity plan before making an offer.
What we did Consultancy to build the plan, covering key customers, critical systems and the response if anything went wrong, then test it.
Result A tested plan approved as a working document, presented to the board and the funder.

The funder wanted to see more than a backup policy. They asked who the key customers were, which systems the business depended on, and what would happen to both if something failed. We worked with the leadership team to answer those questions in writing, tested the plan, and made sure it held up as a document people could act on.

The plan went to the board and then to the funder. The result was a higher valuation than the business expected and a significantly better financial offer. Evidence that the business could keep operating through disruption reduced the risk the funder was pricing in.

Not sure where you stand?

Our business continuity readiness check takes around five minutes and shows which parts of continuity and recovery you already have covered.

Frequently asked questions

Is a disaster recovery plan part of a business continuity plan?

Yes. The disaster recovery plan covers restoring IT systems and data. It sits inside the business continuity plan, which also covers people, premises, suppliers, communications and decision-making.

Do we need a business continuity plan for Cyber Essentials?

No. Cyber Essentials covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Backups sit outside those controls, although the current requirements recommend them. Cyber Essentials reduces the chance of an incident but does not cover how you respond to one.

Does ISO 27001 require business continuity planning?

ISO 27001:2022 Annex A 5.29 and 5.30 cover information security during disruption and ICT readiness for business continuity, and control 8.13 covers backup. Control 5.30 was new in 2022, and auditors expect to see recovery planned, tested and the results recorded.

Do cyber insurers require a business continuity plan?

Requirements vary by insurer, but proposal forms commonly ask whether you have a documented and tested incident response plan, alongside controls such as MFA and backups. Answer accurately: saying yes without a real, tested document can cause problems if you ever claim.

Does Microsoft back up our Microsoft 365 data?

Microsoft keeps the service available, but protecting your data, accounts and configuration is your responsibility, and Microsoft’s own services agreement advises users to back up their content. Most regulated organisations benefit from an independent backup held outside the Microsoft 365 tenant.

How often should we test our continuity plan?

At least once a year, and again after significant changes such as a new core system, a new key supplier or changes in senior staff. ISO 27001 expects testing at planned intervals, and the NHS DSPT expects smaller providers to show a test within the last twelve months.

Where should you start?

Most organisations are at one of these points. Find yours, and the next step becomes clear.

1

Backups, but no plan

Put the three stabilising actions above in place this week, then agree RTOs and RPOs with your leadership team. That meeting is the foundation for everything else.

2

A plan that has not been tested

Run a two hour tabletop exercise. You will leave with a list of gaps, owners and dates, which is the evidence insurers and auditors ask for.

3

A tested plan with an audit or renewal coming

Check that your disaster recovery arrangements, including Microsoft 365, actually meet the targets in the plan, and that the evidence is somewhere you can find it quickly.

4

Not sure which applies

A short conversation will tell you. We will look at what you have now and tell you plainly where the gaps are.

Bondgate IT is certified to ISO 27001, ISO 9001 and Cyber Essentials, so our own continuity arrangements are part of what external auditors examine every year. We have seen what a major incident does to an organisation in this region at close quarters: we featured in the BBC documentary Cyber Siege: From Russia to Redcar, which followed the 2020 ransomware attack on Redcar and Cleveland Council. When we build a plan with you, we act as part of your team through the process rather than handing over a template. We have supported organisations from our base in Darlington since 1998, with engineers on site across the Tees Valley every week, including IT support in Stockton-on-Tees and IT support in Middlesbrough.

Start with a free conversation

Thirty minutes with our team, looking at what you already have and what your next insurer, auditor or customer is likely to ask for. You will leave knowing which of the steps above applies to you.

Book your free conversation

About the author

Damien Harrison is Director of Client Success at Bondgate IT. He holds ISO 27001 and ISO 27701 Lead Auditor qualifications and an MBA, and works with finance, operations and leadership teams across the North East on cyber security, compliance and resilience.

Facebook
LinkedIn
WhatsApp
Email
Print