Skip to content

Strategic Business Leader · IT systems security and control

Business Continuity, Disaster Recovery and Backup for ACCA SBL

Updated 11 October 2026 · Fact-checked

Business continuity planning keeps critical business activities running during a disruption. Disaster recovery is the part that restores IT systems and data after failure. Backups and recovery sites support both. To answer SBL questions, identify critical processes, set recovery targets, choose backup and site options, and test the plans.

Understand Business Continuity, Disaster Recovery and Backup

Every organisation depends on systems, data, people and premises. If one fails, the business may stop. Planning for this is a risk response. It reduces the impact of an event even when you cannot prevent it.

Business continuity planning (BCP) is the wider plan. It covers how the whole organisation keeps critical activities going during a disruption. This includes staff, premises, suppliers, communications and customers, not just IT. It starts with a business impact analysis, which identifies critical processes and the cost of losing them.

Disaster recovery planning (DRP) is narrower. It covers how IT systems, applications and data are restored after an incident such as fire, flood, cyber attack, power failure or hardware failure. A DRP is usually one component of a BCP.

Backup means keeping copies of data and software so you can restore them. Backups can be full (everything), incremental (changes since the last backup of any type) or differential (changes since the last full backup). Copies should be stored offsite or in the cloud, and restores should be tested. A backup that has never been restored is an assumption, not a control.

Recovery sites are alternative locations to run systems. A hot site is fully equipped and mirrors live data, so it can take over in minutes or hours, at high cost. A warm site has hardware and connectivity but needs data loaded and some configuration, so recovery takes longer and costs less. A cold site is just space with power and basic facilities, so recovery is slowest and cheapest. Cloud services can offer similar options on a pay-as-you-use basis.

The right choice is a trade-off. Two targets drive it. Recovery time objective (RTO) is how long the business can tolerate being down. Recovery point objective (RPO) is how much data loss it can tolerate, measured as time. Tight targets need more expensive solutions.

Key rules to remember

BCP vs DRP
BCP = whole-business continuity of critical activities; DRP = restoring IT and data
DRP sits inside BCP. Say this clearly when asked for the difference.
Recovery time objective (RTO)
RTO = maximum acceptable downtime
Shorter RTO means a hotter, costlier recovery site.
Recovery point objective (RPO)
RPO = maximum acceptable data loss, measured in time
Shorter RPO needs more frequent backup or real-time replication.
Recovery site ranking
Hot: fastest and costliest; Warm: middle; Cold: slowest and cheapest
Match the site type to how critical the system is.
Backup types
Full = all data; Incremental = changes since last backup; Differential = changes since last full backup
Incremental is quick to take but slower to restore. Differential is the reverse.
Plan cycle
Analyse impact → design plan → document → train → test → review
Use this as a structure for any plan-related requirement.

How to solve Business Continuity, Disaster Recovery and Backup questions

Use this method for any SBL question on continuity, recovery or backup. Always tie your answer to the scenario.

  1. 1Read the requirement and note its verb: explain, assess, recommend, or advise. Note who you are writing for.
  2. 2Identify the disruption in the scenario and which business activities and systems it affects.
  3. 3Separate the issue into continuity (people, premises, suppliers, customers) and recovery (IT, data, applications).
  4. 4Rank the critical processes and set sensible RTO and RPO for each, using scenario facts such as volumes, deadlines and customer impact.
  5. 5Match solutions to targets: backup method, offsite storage, and hot, warm, cold or cloud recovery. Weigh cost against risk.
  6. 6Add governance: named responsibilities, documented plans, staff training, regular testing and review.
  7. 7Give a clear recommendation with a reason, and note limits such as cost, third-party reliance and residual risk.
  8. 8Check you used scenario facts and a professional tone, as professional skills marks depend on this.

Quickest way: Impact, target, solution, test

When to use it: Use when time is short and the requirement asks for a brief explanation or recommendation.

  1. Impact: name the critical process and what its loss costs.
  2. Target: state how long it can be down and how much data it can lose.
  3. Solution: pick backup type and site (hot, warm, cold or cloud) that fits that target and budget.
  4. Test: add testing, training and review, and link back to the scenario.

Common mistakes in Business Continuity, Disaster Recovery and Backup

  • Treating business continuity and disaster recovery as the same thing

    Both deal with disruption, and the terms are used loosely at work.

    Fix: State that BCP covers the whole business and DRP restores IT and data within it. Then give an example of each.

  • Listing hot, warm and cold sites from memory with no link to the scenario

    The definitions are easy to learn, so students write them out without applying them.

    Fix: Choose one option for the scenario's system and justify it using downtime cost, data volume and budget.

  • Recommending the most advanced solution for everything

    Students assume more protection is always better.

    Fix: Match the solution to how critical the process is. Low-priority systems may only need a cold site or simple backup.

  • Ignoring people, premises and suppliers

    Students think of the topic as an IT issue only.

    Fix: Cover alternative work locations, staff communication, key supplier dependence and customer messaging for continuity questions.

  • Forgetting testing and maintenance of the plan

    Students stop once the solution is chosen.

    Fix: Always add regular tests, restore checks, updates when the business changes, and staff training. Untested plans often fail.

  • Keeping backups on the same site as the live system

    It is convenient and seems adequate.

    Fix: Recommend offsite or cloud storage so one fire, flood or ransomware event cannot destroy both copies.

Worked examples

Example 1

A company runs an online retail platform. Orders are taken 24 hours a day. A server failure last month stopped trading for two days and the last backup was a week old. The board asks you to explain what went wrong in its planning and to recommend improvements. (10 marks)

Show the solution
  1. Diagnose: two days of downtime shows no workable recovery target or alternative site. A week-old backup shows an RPO that was far too loose for a 24-hour trading business.
  2. Impact: lost sales, damaged customer confidence, and possible loss of order data, which may cause fulfilment and payment errors.
  3. Recommend a tighter RPO by moving to frequent backups, ideally near real-time replication of the order database.
  4. Recommend a tighter RTO with a hot or cloud-based standby environment, since trading is continuous and downtime is costly. Accept the higher cost because the revenue at risk is high.
  5. Store backups offsite or in the cloud, and test restores regularly.
  6. Broaden to continuity: a documented plan, named responsible staff, customer communication during outages, and checks on key suppliers such as the payment provider.
  7. Governance: regular testing, review after the incident, and board oversight of the plan.

Answer: The failure came from loose recovery targets and no standby capacity. Recommend near real-time replication, a hot or cloud standby, offsite backup with tested restores, and a wider continuity plan with clear responsibilities, communication and regular testing.

Example 2

A small accounting practice has 15 staff. Its client files are on a single office server and are backed up weekly to a drive kept in the same office. A partner asks whether a hot site is needed. Advise the partner. (8 marks)

Show the solution
  1. Assess criticality: the practice has deadlines but can usually tolerate some hours or a few days of downtime, so a very short RTO is not essential.
  2. Identify weaknesses: the backup is weekly, so up to a week of work could be lost, and it sits in the same office, so a fire or theft could destroy both copies.
  3. Conclude a hot site is unlikely to be justified. It is expensive relative to the size of the firm and the tolerable downtime.
  4. Recommend daily or more frequent backups to a cloud service or offsite location, with periodic restore tests.
  5. Suggest a low-cost recovery option such as cloud-hosted files or a cold or warm arrangement, plus remote working so staff can continue from home.
  6. Add basic continuity steps: a written plan, contact lists, and a note of client deadlines that need priority.

Answer: A hot site is not justified. Fix the real weaknesses first: move to frequent offsite or cloud backups, test restores, and arrange a low-cost recovery and remote working option, supported by a short written continuity plan.

Exam tips

  • Define BCP and DRP in one line each, then apply them. Marks come from application to the scenario.
  • Always link the choice of hot, warm or cold site to cost, criticality and tolerable downtime in the case.
  • Include non-IT continuity points such as people, premises, suppliers and communication.
  • Mention testing, training and review of plans. Examiners often credit this as the point that makes a plan reliable.
  • Use a clear recommendation, stating the trade-off, to earn professional skills marks for judgement and commercial awareness.

Practice questions from IT systems security and control

Business Continuity, Disaster Recovery and Backup in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Business Continuity, Disaster Recovery and Backup: frequently asked questions

What is the difference between business continuity and disaster recovery?

Business continuity keeps critical activities of the whole organisation running during a disruption. Disaster recovery restores IT systems and data after a failure. Disaster recovery is normally one part of business continuity.

What is the difference between hot, warm and cold sites?

A hot site is fully equipped with current data and can take over very quickly, but costs the most. A warm site has equipment but needs data and setup, so it is slower and cheaper. A cold site is basic space and is the slowest and cheapest.

What are RTO and RPO?

Recovery time objective is the longest downtime the business can accept. Recovery point objective is the most data loss it can accept, measured in time. Together they guide which backup and recovery solutions to choose.

Is a backup enough for disaster recovery?

No. A backup only preserves data. You also need a place and equipment to run systems, staff who know the steps, and tested procedures to restore. Without these, recovery may take much longer than the business can accept.