Crisis and continuity · 3 September 2026
Business continuity and disaster recovery: executive differences
Restoring a server is not restoring a company. Continuity is measured in clients served, payroll paid and trust intact.
By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.
Original text in Spanish. Read the original Spanish version

Confusing business continuity with disaster recovery is an error of governance, not of vocabulary. The first answers the question “how do we keep serving?”. The second, “how do we switch this back on?”. An organisation can recover disks and lose the company.
BCP, DRP and the clocks that matter
- DRP (disaster recovery): a plan to restore systems, data and infrastructure.
- BCP (business continuity): a plan to sustain critical processes even if the main system does not come back.
- RTO: target time to restore a system. It measures technology.
- RPO: how much information one accepts losing. It measures data.
- MTPD: maximum tolerable period of disruption of the business process. It measures the company.
RTO and RPO are useful. They are not enough. The time to rebuild trust does not appear in the DR plan and, even so, it defines whether clients return.
Dependencies and critical suppliers
Continuity breaks at the dependency no one drew: the identity provider, the payments gateway, email, the contact centre, the bucket where the copies live. An internal RTO of four hours is of no use if the supplier takes three days and there is no plan B.
- List the processes that cannot stop for 72 hours.
- For each process, identify systems, people, sites and suppliers without which it does not operate.
- Ask each critical supplier for its declared RTO and whether it ever demonstrated it.
- Define what you do if that supplier does not come back: manual, alternate, orderly halt.
Tabletop exercises, not workshops of assent
ISO 22301 helps to put names and owners in place. It does not replace rehearsal. A certificate that no one has put to the test in a drill with the board is an emotional insurance policy. I insist on an annual exercise in which the chair has to decide with a cut in information, not on a workshop in which everyone assents.
- A plausible scenario, not a cinematic one.
- Incomplete information, with a time.
- Real roles, not observers.
- A continuity decision: what is sustained and what is stopped.
- A note of lessons that changes the plan, not minutes that archive it.
The crisis of trust
The backup does not rebuild a client who stopped paying. The alternate site does not rebuild a regulator who stopped believing. Continuity includes spokespersonship, digital identity and a defensible explanation. If tomorrow at 07:00 there is no central system, who collects, who serves, who informs the regulator and who tells the truth to the board at 09:00? If that answer depends on a single person, there is no continuity. There is hope.
References
- NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems. NIST. Accessed: 2026-09-04. La distinción entre recuperación de sistemas y continuidad de la operación se alinea con la planificación de contingencia de NIST. El texto no convierte esa guía en una certificación ISO 22301 de la empresa.