Security teams must be prepared to minimise the impact that security incidents can have on their normal business operations. When an incident occurs, *organisations might experience significant disruptions to the functionality* of their systems and services. Prolonged disruption to systems and services can have serious effects, causing legal, financial, and reputational damages. Organisations can use business continuity planning so that they can *remain operational during any major disruptions*. Similar to an incident response plan, a *business continuity plan* (BCP) is a document that **outlines the procedures to sustain business operations during and after a significant disruption**. A BCP helps organisations ensure that critical business functions can resume or can be quickly restored when an incident occurs. [[Business Continuity Plan|Business continuity plans]] are *not the same as disaster recovery plans*. [[Disaster Recovery Plan|Disaster recovery plans]] are used to recover information systems in response to a major disaster. These disasters can range from hardware failure to the destruction of facilities from a natural disaster, like a flood. ### Recovery strategies When an outage occurs due to a security incident, organisations must have some sort of a functional recovery plan set to resolve the issue and get systems fully operational. BCPs can include strategies for recovery that focus on returning to normal operations. Site resilience is one example of a recovery strategy. ### [[Site Resilience]]