Disaster recovery vs business continuity vs data loss prevention

Issue 4 2023 Security Services & Risk Management


Jim Morrison.

In mid-May, the Western Cape Parliament's technology systems went offline after a cyberattack. While this event was undoubtedly bad for productivity, they could at least recover from the attack thanks to data backups, business continuity, and disaster recovery plans.

Every business must have such measures in place, says Jim Morrison, Account Manager at Sithabile Technology Services. "The simple fact is that it's easy to become a cybercrime victim, experience catastrophic equipment failure, or an employee accidentally loses important data. That's why we tend to say 'when, not if' about cyber risks, especially cyberattacks. Unfortunately, automated tools and the low risk of prosecution means cybercrime is as opportunistic as a street mugging. If you want to reduce risks from cyberattacks and employee mistakes, you need to have both prevention and cure in place. Business continuity and disaster recovery plans can cover both those bases."

Yet despite often being used interchangeably, Business Continuity (BC) and Disaster Recovery (DR) are different. So is Data Loss Prevention (DLP). How can you tell the difference between BC, DR and DLP?

Building a resilient business

The concept of resilience has become very popular since the pandemic. Books such as Antifragile and Grit inform discussions on how people and organisations can reduce harm from unexpected changes and challenges.

Yet while we can cover volumes on exploring resilience, it's a straightforward proposition for an organisation,” says Morrison. "Business resilience is about how well your operations can resist negative disruption or recover from such disruption. It's like losing the keys to your office front door; how quickly can you find a replacement key and open up so that people can get to work?"

The cornerstone of business resilience is business continuity planning, supported by disaster recovery and reinforced by data loss prevention.

Business continuity: BC is there to help an organisation continue operating through a disruptive event, and BC planning is to identify critical operational areas, then put policies and processes in place to help those through planned and unexpected disruptions.

Disaster recovery: As the name suggests, DR steps in when something goes wrong. Specifically, it focuses on recovering technology systems and data in the event of a disaster, bringing them back to operational status.

Data loss prevention: DLP is an ongoing effort to track and secure data through policies and processes, often automated, preventing accidental losses or intentional data theft.

The resilience pyramid

Business continuity is the strategic master plan. It determines what is important, what could threaten those critical areas, how to reduce those risks, and what to do when something goes wrong. Disaster recovery often guides the tangible parts of that strategy, particularly for assets: what data or applications are important, how they are being backed up, and the appropriate timelines and priorities to recover systems. Data loss prevention aims to prevent disaster recovery by determining measures such as encryption, access controls, and employee training.

"You can visualise resilience as a pyramid. Business continuity is at the top, while disaster recovery and data loss prevention form the foundations. You make BC plans, then use DLP to support prevention and DC to support recovery," says Morrison. "If you don't know where to start, always start with BC planning. That's your guiding light. Once you have a grasp on BC needs, you'll see where DR and DLP fit in."

The pyramid of business continuity, disaster recovery and data loss prevention form the most robust approach against cyber-related risks and help mitigate many other disruptions, such as fires, equipment failure and even loss of people. And if done correctly, it helps employees be more productive inside a highly secure business.

Hence, why it's important to distinguish these three disciplines. But while their definitions are straightforward, every business has unique needs. Poorly designed interventions can be worse than none since they create a false sense of security, and ample gaps for criminals to exploit.

"BC, DR and DLP are not just products you pull from a shelf or a cloud app store. They need alignment with your business. It's worth the effort to engage with professionals to put the right measures in place. When disaster strikes, you'll be glad you did, because if you don't have a plan, all you'll get is chaos."

For more information, contact Sithabile Technology Services, www.sithabile.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

ArxTech: Over 30 years of evolving security solutions for South Africa’s toughest challenges
Security Services & Risk Management Integrated Solutions
[Sponsored] For over 30 years, a Centurion-based company has helped shape how security technology is designed, deployed, and supported in South Africa. Originally known as CellSecure, it now operates as ArxTech.

Read more...
Don’t Miss the Exclusive Launch of the AirXpress 3 SCBA
Security Services & Risk Management
Be the first to experience the all-new AirXpress 3 Self-Contained Breathing Apparatus (SCBA), designed and manufactured by MSA, and brought to you by PSA Africa.

Read more...
Transform WhatsApp chaos into real-time security intelligence
Security Services & Risk Management
The HYDRA AI security intelligence software plugs into existing guard chat groups to automatically convert voice notes, photos, and texts into structured, real-time security data and insights.

Read more...
SABRIC Annual Crime Statistics 2024
News & Events Security Services & Risk Management Residential Estate (Industry)
SABRIC has released its Annual Crime Statistics for 2024, reflecting a significant decline in financial crime losses, but also warning of the growing threat posed by artificial intelligence (AI) in fraud schemes.

Read more...
Health, safety, and environmental eLearning
Training & Education Security Services & Risk Management
SHEilds is a global leader in health, safety, and environmental eLearning, delivering internationally recognised qualifications such as NEBOSH, IOSH, IEMA, and ProQual NVQs.

Read more...
See crime stopped in seconds
Products & Solutions Security Services & Risk Management
Fog Bandit, a leader in security fog, is bringing its instant crime-stopping technology to Securex Cape Town 2025. Experience the innovation trusted worldwide to protect retailers, warehouses, and high-value sites.

Read more...
SA’s private security industry receives multi-million USD investment
News & Events Security Services & Risk Management
South Africa's private security sector has attracted significant international attention, with the world’s largest tactical flashlight manufacturer, Nextorch, announcing a major investment in its local operations, Nextorch Africa.

Read more...
Vetting people in security estates
iFacts Security Services & Risk Management Residential Estate (Industry)
In today’s security-conscious South Africa, estate management’s responsibility extends beyond gates and patrols; it involves ensuring that every resident, staff member, and service provider upholds the community’s safety standards.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
IVA AI Pro Visual Gun Detection
Products & Solutions Surveillance Security Services & Risk Management Residential Estate (Industry)
Bosch has announced the launch of the IVA AI Pro Visual Gun Detection analytics based on deep learning. It is designed for automatic detection and classification of people and brandished firearms.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.