Key takeaways
- RTO defines the target time to restore an agreed level of service.
- RPO defines the maximum acceptable age of restored data, not the backup frequency by itself.
- Targets should be approved by service owners and validated against complete dependencies and measured tests.
Use precise definitions
Also define the minimum business service level required at the RTO. A system being powered on does not necessarily mean the business service has recovered.
- Target elapsed time from disruption to an agreed service level
- Must include dependencies, validation and operational handover
- Should be measured during realistic recovery tests
- Maximum acceptable age of data available after recovery
- Must reflect business transactions, reconciliation and legal needs
- Should consider replication lag, backup timing and corruption risk
A practical target-setting method
Assess business impact
Understand financial, customer, legal, safety and operational consequences over time.
Define the minimum service
Specify the volume, locations, channels and functions needed during recovery.
Map dependencies
Include applications, identity, networks, data, people, suppliers and facilities.
Review solution capability
Compare business needs with architecture, contracts, staffing and recovery evidence.
Approve targets and gaps
Document accepted objectives, assumptions, investment decisions and residual risk.
Test and refine
Measure actual results and adjust the plan or capability where targets are not met.
Common target-setting mistakes
- Assigning the same target to every application.
- Treating backup frequency as the confirmed RPO.
- Ignoring the time required to restore identity, network and security services.
- Measuring infrastructure availability rather than end-to-end business service recovery.
- Setting targets without confirming staffing, supplier and communication requirements.
- Publishing ambitious objectives without funding or testing the required capability.
What good evidence looks like
A recovery test report should show the start point, scope, recovery point used, actual timings, dependencies, validation results, issues, assumptions and approved actions. Compare measured performance directly with the approved RTO and RPO.
Where targets are not currently achievable, report the gap transparently and agree an interim strategy such as manual workarounds, limited service, alternate channels or risk acceptance.
RTO and RPO workshop template
Use this editable worksheet to record business services, tolerable disruption, recovery targets, dependencies, assumptions and approvals.
Resilience is demonstrated through current plans, practiced decisions and measured recovery evidence—not assumptions.