Recovery Point Objective (RPO) and Recovery Time Objective (RTO) define how much data loss and downtime an organization can tolerate when a disaster occurs. These two metrics drive the design and cost of any effective backup and recovery strategy.
RPO and RTO Objectives
There may be many objectives that we're trying to achieve with our backup systems. However, one of the critical ones is, what is our RPO or RTO? Our recovery point objective and our recovery time objective.
Here's a timeline, and on this timeline we have some sort of incident. Maybe there was a fire in our data center and we lost equipment. We lost data, and now we have to do a restore on our cold site, and so we're going to bring things up.
What are we willing to lose out of this? There's two aspects to this. One is going back: how much information are we willing to lose? Can we lose 24 hours of information? That means that maybe our customers and clients have lost 24 hours worth of data. That sounds pretty scary, and I would say it is on many systems, maybe even most systems. But maybe what we can say is, can we agree on maybe an hour, or 15 minutes, of recovery point objective?
So the recovery point objective is how far back we can go, and it's measured in time. Let's say our recovery point objective is 15 minutes. The only acceptable amount is 15 minutes or less. We can't go over 15 minutes of loss.
And then we've got the recovery time objective, and that's how long it takes to recover. Generally there's a little bit more leeway with this. It's going to be hard to hit that 15 minutes of recovery time unless we just go to everything being live on two different sites and we can fail over at a click of a button, and then it can be pretty much instantaneous. So we could do it instantaneously.
But what is more realistic? A lot of that has to deal with our budget. So maybe we say our recovery time objective is going to be 6 hours, or maybe it's going to be 24 hours, or maybe it's going to be 48 hours. 48 hours starts getting a little scary. Most clients are not going to want 48 hours, but a lot of them can probably handle 6 hours of downtime. But even then, that's going to be determined by the industry and who your clients are. If we're talking about an e-commerce site that's making millions every single minute or hour, then we better make this much smaller. The time frame in which we recover should be pretty much instantaneous.
So it really has to deal with risk, how much risk we're willing to take on, and how much the cost is to achieve those numbers. Because the farther out from this incident line, the less expensive it is going to be, and the closer we get to this incident line, the more expensive it's going to get. So if we have 1 minute of recovery point objective and 5 minutes of recovery time objective, that's going to be much more costly than 24 hours of recovery point objective and 72 hours of recovery time objective.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →