DefinitionRTO (Recovery Time Objective) is the maximum acceptable time to restore a system or process after a disruption. RPO (Recovery Point Objective) is the maximum amount of data, measured in time, that can be lost. Together, they guide backup and continuity.
RTO vs RPO
- RTO looks forward from the disruption: how long the service can be down before the business impact becomes unacceptable.
- RPO looks backward: to what point in time data must be recovered. An RPO of four hours requires copies or replication at least every four hours.
The two are independent. A payment system may tolerate a few hours of downtime but cannot lose transactions (moderate RTO, near-zero RPO). A corporate website can stay down longer and lose a day of changes without major impact.
How to set them
RTO and RPO are business decisions, not IT decisions. They come from the business impact analysis (BIA), which starts from critical processes, measures the cost of downtime and data loss and maps the systems, suppliers and dependencies that support them. References such as NIST SP 800-34 and ISO 22301 cover this process. The lower the objectives, the more expensive the solution: continuous replication and a redundant environment cost more than a daily backup.
In practice
During a ransomware attack, RTO and RPO defined in advance change the team's question from "which server do we restore first?" to "which service must come back first to avoid unacceptable impact?". But they only hold if tested: periodic restores measure the real recovery time and reveal whether the backup is intact and protected from the attacker. Isolated or immutable backups, with credentials separate from the corporate environment, are what make the RPO achievable when the incident is deliberate.
Network Secure provides incident response to support containment and recovery within the objectives set by the business.
Frequently asked questions
What is the difference between RTO and RPO?
RTO measures how long a system can be down; RPO measures how much data loss, in time, is tolerable. One concerns availability, the other concerns data.
Who sets RTO and RPO?
Business units, supported by IT and security, based on a business impact analysis (BIA). IT then chooses the technical solution capable of meeting them.