The recovery time objective (RTO) is how long a system can be unavailable. The recovery point objective (RPO) is how much recent data the business can afford to lose. Together they shape backup frequency and recovery design.
Key takeaways
What to know before you act
- RTO is how quickly a system must be restored; RPO is how much data loss, measured in time, is acceptable.
- Targets should be set by business impact for each system, not one number for everything.
- Testing is the only way to confirm the targets are achievable.
Why it matters
What business leaders should understand
Without agreed objectives, backup systems are designed by guesswork. Clear RTO and RPO targets help leadership weigh cost against downtime and data loss.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with backup and disaster recovery, business continuity planning, and incident response services.
Related reading: What is the 3-2-1 backup rule? and How to run a cybersecurity tabletop exercise.
Definitions with examples
If the accounting system has an RTO of four hours, the business expects it to be working again within four hours of an outage. If its RPO is one hour, backups or replication must capture changes at least hourly, so no more than an hour of work would need to be re-entered.
A file archive might tolerate an RTO of several days and an RPO of 24 hours, while a scheduling or point-of-sale system may need much shorter targets. Tighter targets generally require more frequent backups, faster storage, replication, or standby systems—and more cost.
Setting and testing objectives
Start with a simple business impact analysis: which processes matter most, what each depends on, and what an outage would cost per hour or day. Use the results to set RTO and RPO for each system, then compare them with what the current backup design can deliver.
- Document targets for each critical system and the reasons for them.
- Identify dependencies such as internet access, identity, and line-of-business vendors.
- Measure actual restore times during tests and adjust design or targets.
- Review objectives when systems or business priorities change.
Practical action plan
Steps your business can take
List critical systems and the business processes that depend on them.
Agree on acceptable downtime and data loss for each system.
Match backup frequency and recovery methods to those targets.
Test recovery to confirm targets can actually be met.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is the 3-2-1 backup rule?
Build backup copies that support your recovery targets.
Explore nextRelated guide
How to run a cybersecurity tabletop exercise
Test recovery priorities with leadership.
Explore nextRelated guide
Cloud backup for small businesses
Estimate realistic restore times from the cloud.
Explore nextPlanning tool
IT budget calculator
Weigh the cost of tighter recovery targets.
Explore nextWarning signs
Do not ignore these indicators
- Backups run nightly but the business cannot lose a day of data
- Nobody knows how long a full restore would take
- Recovery priorities have never been discussed with leadership
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
National Institute of Standards and Technology
NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems
Contingency planning guidance, including business impact analysis and recovery objectives.
National Institute of Standards and Technology
Protecting Data from Ransomware and Other Data Loss Events
A practical guide for small organizations on backup, recovery, and protecting data from loss events.
National Institute of Standards and Technology
The NIST Cybersecurity Framework (CSF) 2.0
A flexible framework for governing, identifying, protecting, detecting, responding to, and recovering from cybersecurity risk.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
