RPO and RTO: the two numbers that decide your backup and DR design
KINNEX Team4 min read
Two short terms control most backup and disaster recovery decisions.
Recovery point objective (RPO)
How far back you are willing to go when you recover. If the RPO is 24 hours, a nightly backup is enough. If it is 15 minutes, you need frequent snapshots or continuous replication.
Recovery time objective (RTO)
How long the business can wait for the system to come back. An RTO of a week allows restoring from backup onto new hardware. An RTO of minutes needs a standby system ready to take over.
Set them per system
Not everything is equally critical. Email, billing and a plant control server may need strict targets; an archive share may not. Ranking systems by business impact keeps the budget on what matters.
What drives cost
Shorter RPO and RTO need more infrastructure: replication, a second site, automation and regular testing. Halving the target usually more than doubles the cost, so ask whether the stricter number is really needed.
Write them down
A one-page table listing each system, its owner, RPO, RTO, backup method and restore test date turns an abstract plan into something you can check.
And test
Meeting the objective on paper is not the same as meeting it on the day. Run a recovery exercise at least once a year and time it.