All insights

What are RTO and RPO, and what should ours be?

5 min readBy Brendon Whiting, Founder · 13 April 2026

RTO, the recovery time objective, is how long a system can be down before the damage is unacceptable. RPO, the recovery point objective, is how much recent work you can afford to lose. Decide both per system, in hours, before buying anything, because together they determine what your backup and recovery setup actually has to be.

The reason these two acronyms are worth learning, when most are not, is that they convert an unanswerable question into two answerable ones. Ask an owner how good their backups should be and you get a shrug or the word bulletproof. Ask how many hours the practice can run without the clinical system, and how much of today's work you could bear to re-enter, and you get real numbers, because those are questions about the business rather than about technology.

Take them one at a time. Recovery time is about downtime: from the moment something fails to the moment people are working again. It includes everything, diagnosis, the decision, the restore itself, verification, and people getting back in, which is why the honest number is always larger than the one on the vendor's datasheet. Recovery point is about data loss, and it is set by how often backups run: nightly backups mean a failure at four in the afternoon costs you the day's work, and whether that is a shrug or a catastrophe depends entirely on what your day's work is.

Setting them is a business conversation, not a technical one, and the useful method is to price the pain. For each critical system, ask what the first hour of downtime costs, then the first day, then three days, in revenue, in wages paid for people who cannot work, in appointments cancelled, in customer trust. The curve is rarely linear: many businesses can absorb a morning and are in real trouble by day three. Where the curve turns sharply upward is where your recovery time objective belongs, and the same logic sets the data-loss number, since re-entering four hours of transactions is an annoyance and re-entering four weeks is an existential problem.

Then tier the systems, because uniform targets are how backup budgets get wasted. Most small businesses land on three tiers: critical systems the business stops without, where hours matter; important systems that can wait a day; and everything else, where a week is survivable. Tiering costs nothing to do and saves real money, because it stops you buying the fastest recovery for the archive nobody has opened since 2019.

What the numbers then buy is straightforward. Loose targets, a day of downtime and a day of data loss, are met by conventional nightly backups and a competent restore process, which is what most small businesses actually have. Tighter targets, a few hours, need more frequent snapshots and faster restore paths, usually cloud-based. Very tight targets, minutes, mean replication and standby infrastructure, and the cost steps up accordingly. This is the whole point of setting the numbers first: you are choosing a tier rather than being sold one, and you can tell whether a proposal is over- or under-specified for your actual tolerance.

There is an external reason to write these numbers down as well as an internal one. The Essential Eight expects backups to be retained, protected and restored to a tested standard, and an assessor or an insurer asking how quickly you could recover is asking for your recovery time objective whether or not they use the phrase. A business that can answer with two numbers and a timed test result is having a different conversation from one that says we have backups, and the difference shows up in renewal questionnaires and tender responses long before it shows up in an incident.

Two things routinely blow real recovery times past the planned ones, and neither is the backup software. The first is dependency order, since restoring the application before the database it needs simply means doing it twice. The second is decision latency: hours disappear while people work out whether this is a real incident and who can authorise the response, which is why the recovery plan names who declares an incident. Both are free to fix and neither shows up on a datasheet.

The honest caveat is that a target is an intention until it is measured. Any provider, ours included, can write four hours into a document; only a timed test restore turns that into a fact, and the gap between the two is the most common unpleasant surprise in this field. Set your numbers, then insist on a test that proves them, at least annually. If you want help setting targets you can defend and building to them, call 1800 456 567.

Put numbers on your tolerance

We help businesses set recovery targets they can defend, then build backup and recovery to match rather than to a brochure.

Frequently asked questions

You can ask for it, and you will not like the quote. Near-zero targets mean continuous replication and standby infrastructure, which is real engineering with real ongoing cost, and it is the right answer for a hospital or a trading floor. For most small businesses the honest targets are hours, and pretending otherwise either wastes money or produces a plan nobody funds.

No, and setting them uniformly is the most common mistake. Your clinical system, ledger or job-management platform might justify a four-hour target, while the archive of old marketing files can be down a week without anyone noticing. Tiering the systems is what keeps the cost sane, because you are only paying for speed where speed earns it.

Test a restore and time it, which is the only answer that means anything. Ask your provider what your current recovery time actually is, and if the reply is an estimate rather than a measurement, that is the finding. Backup software reports whether jobs ran; only a real restore tells you how long being down would last.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.