Business continuity and resilience advisory
PlanRespondRecoverImprove
FRAMEWORK · 11 MIN READ

Setting realistic RTO and RPO targets

A business-focused method for defining recovery objectives that are meaningful, achievable and supported by evidence.

Key takeaways

  • RTO defines the target time to restore an agreed level of service.
  • RPO defines the maximum acceptable age of restored data, not the backup frequency by itself.
  • Targets should be approved by service owners and validated against complete dependencies and measured tests.

Use precise definitions

Also define the minimum business service level required at the RTO. A system being powered on does not necessarily mean the business service has recovered.

FOCUSRecovery Time Objective
  • Target elapsed time from disruption to an agreed service level
  • Must include dependencies, validation and operational handover
  • Should be measured during realistic recovery tests
FOCUSRecovery Point Objective
  • Maximum acceptable age of data available after recovery
  • Must reflect business transactions, reconciliation and legal needs
  • Should consider replication lag, backup timing and corruption risk

A practical target-setting method

01

Assess business impact

Understand financial, customer, legal, safety and operational consequences over time.

02

Define the minimum service

Specify the volume, locations, channels and functions needed during recovery.

03

Map dependencies

Include applications, identity, networks, data, people, suppliers and facilities.

04

Review solution capability

Compare business needs with architecture, contracts, staffing and recovery evidence.

05

Approve targets and gaps

Document accepted objectives, assumptions, investment decisions and residual risk.

06

Test and refine

Measure actual results and adjust the plan or capability where targets are not met.

Common target-setting mistakes

  • Assigning the same target to every application.
  • Treating backup frequency as the confirmed RPO.
  • Ignoring the time required to restore identity, network and security services.
  • Measuring infrastructure availability rather than end-to-end business service recovery.
  • Setting targets without confirming staffing, supplier and communication requirements.
  • Publishing ambitious objectives without funding or testing the required capability.

What good evidence looks like

A recovery test report should show the start point, scope, recovery point used, actual timings, dependencies, validation results, issues, assumptions and approved actions. Compare measured performance directly with the approved RTO and RPO.

Where targets are not currently achievable, report the gap transparently and agree an interim strategy such as manual workarounds, limited service, alternate channels or risk acceptance.

RTO and RPO workshop template

Use this editable worksheet to record business services, tolerable disruption, recovery targets, dependencies, assumptions and approvals.

Download CSV
Resilience is demonstrated through current plans, practiced decisions and measured recovery evidence—not assumptions.

Continue building your resilience capability

APPLY THIS TO YOUR ORGANIZATION

Turn guidance into a practical resilience improvement plan.

Discuss your priorities