Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are two critical metrics that define how much data an organization can afford to lose and how quickly systems must be restored after an incident. Understanding both helps organizations design backup strategies and allocate the resources needed to meet their recovery commitments.
RPO and RTO Objectives
One thing that we need to define for our different resources is: what is the recovery point objective, and what is the recovery time objective?
Let's go over a little scenario here. Let's say there's an incident on our system. We had some ransomware. Ransomware encrypts some of our information within our system, so somebody was infected with ransomware and it encrypted our data. Now we fixed the issue in the sense that we've removed the ransomware, but now we need to do a full recovery on the data — we have to restore the data. So what does that look like? When we have objectives, we have a recovery point objective and a recovery time objective.
Let's look at recovery time objective first. Let's say we've lost that data, it's been encrypted at this point in time, and there is a certain amount of time we have to get back up and running. So there's this time right here. What is the time it takes for us to restore that data? That's the recovery time objective.
This is usually a little bit longer than the recovery point objective. Maybe this is data that's important to us but it isn't necessarily really critical for us to restore ASAP. So maybe our recovery time objective is 2 hours — we want two hours, and then that data needs to be back up and running.
We also have a recovery point objective. The recovery point objective is how much data are we willing to lose. The thing is, unless we're doing some sort of continuous backup, we're probably going to end up losing some data. So, how much data are we willing to lose? Maybe that is just going to be 15 minutes. The recovery point objective is what point do we go back, how far back.
What happens with this is we're going to be determining that we need to take a backup of this data every 15 minutes. So we have this going on like this, and now if we have an incident we could maybe lose just a couple of minutes, but the maximum that we would lose is up to 15 minutes, because we're taking a backup every 15 minutes. So this number right here essentially equates to how often we're going to be taking backups, and the recovery time objective is then how long it takes to restore those backups.
There is a cost associated with this. How far back — if we're doing backups really often, we're going to have to throw a lot more resources at it. Not just storage resources to store all of that data, but it also takes some processing power, and there's bandwidth that's getting needed up. So it will take up more resources in that, versus if we just do it a few times. The problem with that is that we have to go back further before we have some of that data, but we don't have as much data with processing and with storing that information.
Same thing with the recovery time objective. If we go further out with the recovery time, then we don't need to maybe practice as much with the recovery and what the recovery has. But if you're looking at two minutes of recovery time right here, that means that we need to be on top of things and we need to have extra people on staff to make sure that they're available to do the recovery, and they're looking at things and studying it to make sure that if something happens they could recover right away.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →