TechKnowSurge
ISC2 CISSP 1.7 CompTIA Security+ 3.4 NIST 800-53 CP-2 NIST CSF RC.RP-04 ISC2 CISSP 7.10 NIST 800-53 CP-9 NIST CSF PR.DS-11 CompTIA SecurityX 4.4
VideoSecurityFree

RPO and RTO

Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are two critical metrics that define how much data an organization can afford to lose and how quickly systems must be restored after an incident. Understanding both helps organizations design backup strategies and allocate the resources needed to meet their recovery commitments.

Complete this video to capture a CTF flag worth 1 point.

About this video

Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are two key metrics used in disaster recovery planning to define acceptable boundaries for data loss and system downtime. When an incident such as a ransomware attack encrypts organizational data, these objectives guide how quickly and how completely the environment must be restored. RPO establishes the furthest point in time to which data must be recoverable, effectively setting the maximum tolerable data loss. If an organization sets an RPO of 15 minutes, backups must run at least that frequently, since any data created between the last backup and the moment of failure will be unrecoverable. RTO, by contrast, defines the maximum time allowed to restore systems and resume normal operations after an incident is detected and contained. An RTO of two hours means all affected data and services must be back online within that window, regardless of incident complexity. The relationship between these two metrics has direct cost implications. A shorter RPO demands more frequent backups, consuming greater storage capacity, processing power, and network bandwidth. A shorter RTO requires well-practiced recovery procedures, dedicated personnel, and infrastructure capable of rapid restoration. Organizations must weigh the operational expense of tighter objectives against the potential business impact of extended downtime or significant data loss, balancing risk tolerance with available resources.

What you'll learn

What's covered

RPO and RTO Objectives

Aligned to

ISC2 CISSP
1.7 Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
7.10 Implement recovery strategies
CompTIA Security+
3.4 Explain the importance of resilience and recovery in security architecture.
NIST 800-53
CP-2 Contingency Plan
CP-9 System Backup
NIST CSF
RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.
PR.DS-11 Backups of data are created, protected, maintained, and tested.
CompTIA SecurityX
4.4 Explain incident response and recovery procedures.

Key terms

Recovery Point Objective
RPO
The maximum acceptable amount of data loss measured in time, defining how far back data must be recoverable.
Recovery Time Objective
RTO
The maximum acceptable time to restore a system or service after a disruption.
Disaster Recovery
DR
The process and procedures for recovering IT systems and data following a disruptive event.
Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.
Backup Frequency
How often backup jobs are scheduled to run, determined by the criticality of the data, the organization's Recovery Point Objective (RPO), and available storage resources. Higher-frequency backups reduce the amount of data that can be lost in an incident.

Topics

Rpo Rto Disaster Recovery Backup Strategy Business Continuity Incident Response

Transcript

One thing that we need to define for our different resources is: what is the recovery point objective, and what is the recovery time objective?

Let's go over a little scenario here. Let's say there's an incident on our system. We had some ransomware. Ransomware encrypts some of our information within our system, so somebody was infected with ransomware and it encrypted our data. Now we fixed the issue in the sense that we've removed the ransomware, but now we need to do a full recovery on the data — we have to restore the data. So what does that look like? When we have objectives, we have a recovery point objective and a recovery time objective.

Recovery time objective

Let's look at recovery time objective first. Let's say we've lost that data, it's been encrypted at this point in time, and there is a certain amount of time we have to get back up and running. So there's this time right here. What is the time it takes for us to restore that data? That's the recovery time objective.

This is usually a little bit longer than the recovery point objective. Maybe this is data that's important to us but it isn't necessarily really critical for us to restore ASAP. So maybe our recovery time objective is 2 hours — we want two hours, and then that data needs to be back up and running.

Recovery point objective

We also have a recovery point objective. The recovery point objective is how much data are we willing to lose. The thing is, unless we're doing some sort of continuous backup, we're probably going to end up losing some data. So, how much data are we willing to lose? Maybe that is just going to be 15 minutes. The recovery point objective is what point do we go back, how far back.

What happens with this is we're going to be determining that we need to take a backup of this data every 15 minutes. So we have this going on like this, and now if we have an incident we could maybe lose just a couple of minutes, but the maximum that we would lose is up to 15 minutes, because we're taking a backup every 15 minutes. So this number right here essentially equates to how often we're going to be taking backups, and the recovery time objective is then how long it takes to restore those backups.

The cost of each

There is a cost associated with this. How far back — if we're doing backups really often, we're going to have to throw a lot more resources at it. Not just storage resources to store all of that data, but it also takes some processing power, and there's bandwidth that's getting needed up. So it will take up more resources in that, versus if we just do it a few times. The problem with that is that we have to go back further before we have some of that data, but we don't have as much data with processing and with storing that information.

Same thing with the recovery time objective. If we go further out with the recovery time, then we don't need to maybe practice as much with the recovery and what the recovery has. But if you're looking at two minutes of recovery time right here, that means that we need to be on top of things and we need to have extra people on staff to make sure that they're available to do the recovery, and they're looking at things and studying it to make sure that if something happens they could recover right away.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →