TechKnowSurge
VideoSecurityFree

Backup Objectives

Effective backup planning starts with defining clear objectives — understanding which systems are critical, how quickly they must be restored, and how much data loss is acceptable. These decisions shape the entire backup strategy and determine the level of investment required.

Complete this video to capture a CTF flag worth 1 point.

About this video

A well-designed backup strategy begins not with technology, but with a clear understanding of what the organization is trying to protect and why. The first step is identifying which systems are truly critical — those whose failure would result in significant financial loss, operational disruption, or unacceptable downtime. An e-commerce platform generating substantial revenue per minute sits at one end of the spectrum, while a low-traffic corporate website may require far less aggressive protection. These distinctions directly influence how much investment is justified and how frequently backups should occur. Two key metrics guide backup planning: recovery time objective (RTO), which defines how quickly a system must be restored after failure, and recovery point objective (RPO), which defines how much data loss is acceptable. An organization running highly automated deployments may only need partial backups, since infrastructure can be rebuilt programmatically. Conversely, systems that required extensive manual configuration may warrant full, frequent backups to avoid repeating that effort. Most organizations manage multiple systems simultaneously, each with different levels of criticality. External customer-facing services may be the obvious priority, but internal platforms supporting sales, development, or core business operations can generate equal or greater losses when they go down. Assigning backup objectives to each system — rather than applying a one-size-fits-all approach — ensures that resources are allocated where they matter most and that recovery plans are realistic and actionable.

What you'll learn

What's covered

Backup Planning Fundamentals

Key terms

Recovery Time Objective
RTO
The maximum acceptable time to restore a system or service after a disruption.
Recovery Point Objective
RPO
The maximum acceptable amount of data loss measured in time, defining how far back data must be recoverable.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Disaster Recovery
DR
The process and procedures for recovering IT systems and data following a disruptive event.
Critical System
Any system whose failure or prolonged downtime would cause significant operational or financial harm to an organization.
Backup Objectives
The defined goals for a backup strategy, including acceptable downtime and data loss thresholds based on organizational requirements.

Topics

Backup And Recovery Disaster Recovery Rto Rpo Business Continuity Data Protection Critical Systems

Transcript

Knowing What We Are Trying to Achieve

One of the key aspects to creating a good backup system is knowing what we are trying to achieve. What could happen, and what are we going to do about that?

Let's create a scenario that we'll use throughout this module. Here we have a machine. This is a client machine, and it's accessing our web services that we're in charge of. We have these web services, and then we also have this bank of database servers that are supporting these web services. So this is our setup, and we have to maintain high availability, to include if something disastrous were to happen and we would lose these servers, to get them back up and running again, and perhaps even get them back up and running within a certain time period.

Forming the Objectives

So we start forming what our backup objectives are. That is, how fast do these servers need to come online? If these were an e-commerce site and we were making millions every single minute, then downtime could be very costly for us — you better believe I'm going to be investing a lot more into this setup. If this is just hosting a simple little corporate site that not many people visit, then perhaps we don't invest as much time into backing up these servers and making them as secure.

Maybe it also depends on how we go about doing business. If I deploy things using automation, then I might not need to back up the full server, but just part of the server. Or if I have spent hours and hours and hours setting these up, I probably want to get a full backup of this more often.

So it's going to be critical, depending on what we have, that we are able to figure out what exactly we are trying to achieve with these backups. How much information are we going to lose, or willing to lose? How much time and money are we willing to invest into this?

More Than One Critical System

Usually we're managing more than one critical system. So in this example right here, we've got end users that are accessing maybe our e-commerce site — that's pretty critical. But maybe our internal services that are supporting our internal users are not as important and it's not as big of a deal. Or perhaps we've got inside developers or sales or something that relies on our business systems, and we do lose thousands, or tens of thousands, or hundreds of thousands, or a million dollars a day in lost productivity when our systems go down for our internal users. Well, at that point in time, those become our critical systems.

So one of the things that we'll have to do is identify what those critical systems are, and then what our backup objectives are for those systems.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →