Resilience and Recovery: BCP and DR Essentials
If your core systems went down this morning, how long would it be before you’re serving customers again? A Business Continuity Plan (BCP) and a Disaster Recovery (DR) plan exist to answer that question. The cause varies: a storm, a regional outage, a pandemic, or ransomware. What doesn’t vary is that your community still expects the branch to open and the payments to clear.
BCP and DR both sit inside Business Continuity Management (BCM), alongside resilience, emergency response, crisis management, and third-party oversight. FFIEC guidance asks for an enterprise-wide, process-oriented approach, not a binder on a shelf. That framing points to the difference between resilience and disaster recovery: recovery brings you back after a disruption, while resilience keeps you standing through it. You need both.
BCP vs DR: Where the Two Plans Differ
The two plans are written to work together, but they answer different questions. A BCP covers how the institution keeps operating during and immediately after a disruption. It names who does what, which functions come back first, and how you serve customers when the usual path is closed. A DR plan covers the technology underneath that work: restoring the data, applications, and infrastructure the BCP assumes will be there.
BCP:
- Covers people, processes, and facilities, not just systems.
- Is built on a business impact analysis, a risk assessment, and a continuity strategy.
- Includes pandemic planning and other long-duration disruptions.
DR:
- Restores the data, applications, and infrastructure you need after a disaster.
- Covers backup validation and confirms redundant equipment is current and working.
Neither plan is finished the day it’s written. A BCP test is usually a tabletop exercise that tells you whether your people know their roles while the phones are ringing. A DR test is hands-on: it proves your backups actually restore inside your Recovery Time Objective (RTO). Untested, both plans are assumptions.
7 Ways to Get Ready for a Disaster or Business Interruption
Documented BCP and DR plans are the starting point. These seven steps close the distance between the plan and the day you need it.
- Confirm every day that backup and replication jobs actually completed.
- Use Uninterruptible Power Supplies (UPS) to ride out short outages.
- Shut critical equipment down preemptively when an extended outage is coming.
- Lock down the server room: physical access, power, and cooling.
- Keep ATMs stocked and running for customers who need cash.
- Name a backup for every key role, so no single absence stops the work.
- Validate and test both plans at least annually, and after any material change.
Managing BCM In-House or With a Partner
Most community institutions run BCM with a small IT team and no spare capacity. That’s the real constraint. Handling it in-house means the testing, documentation, and exam evidence land on people whose days are already full. Local providers are convenient, but most have never sat through an FFIEC exam. A national provider built around banking knows the exam, what it asks for, and how to carry the routine work in the background. Every path trades one thing for another: time, cost, or expertise. The right choice depends on which one you’re shortest on.
No matter how you choose to manage it, the work is the same: develop the plans, implement them, test them, and keep them current as guidance changes. Automation and outside support can carry the maintenance load so your team keeps its attention on the decisions that need judgment. You stay focused on the community. We’ll stay focused on keeping the systems ready.
Know your recovery time. Don't estimate it.
A plan you haven't tested is a guess. Walk through what's documented, what's actually been restored in a test, and what an examiner will ask to see. Then close the gaps before a disruption finds them for you.
Sources:
- FFIEC IT Examination Handbook, Business Continuity Management booklet