RTO and RPO: the numbers that decide how fast you’re back
Recovery Time Objective and Recovery Point Objective get treated as IT jargon, but they’re really business decisions wearing technical clothing.
RTO is how long a system can be down before the disruption becomes serious. RPO is how much data, measured in time, the business can afford to lose.
Neither number belongs solely to IT, and neither should be set by default configuration.
Checklist
Key Action Areas
One target doesn’t fit everything
The trap most organisations fall into is applying one RTO and one RPO across the entire environment. A four-hour recovery target sounds reasonable until it’s applied uniformly to both the customer-facing order system and the internal HR portal, which have wildly different real-world impact if they’re down for the same length of time. Tiering matters more than the headline number.
Tiering by business impact
A practical approach splits systems into tiers based on business impact rather than technical convenience. Tier one covers whatever generates revenue or carries regulatory exposure directly, order processing, client portals, core financial systems, and gets the tightest RTOs and RPOs the budget can support. Lower tiers, internal wikis, archived project files, non-critical reporting tools, can tolerate a day or more without materially damaging the business.
What a nightly backup really gives you
A nightly backup gives you an RPO of up to 24 hours by definition, no matter what the document says. If the business genuinely can’t tolerate losing a day of transaction data, that requires continuous replication or more frequent snapshotting, and that has a direct cost and infrastructure implication that needs to be owned by whoever holds the budget, not assumed by whoever configured the backup schedule.
DR and business continuity are parallel tracks
Disaster recovery and business continuity get used interchangeably in casual conversation, and the distinction matters more at the tier-one level. DR restores the technology: systems, data, infrastructure, back to a working state.
Business continuity is about keeping the business functioning while that restoration is underway, sometimes through manual workarounds, alternate suppliers, or a temporary process that doesn’t depend on the affected system at all. A mature plan treats these as parallel tracks rather than sequential steps.
Why this can’t be an IT-only decision
Restoring a database is only useful if the application server it feeds is also back, and that server might depend on an identity provider, a licensing service, or a third-party API nobody thought to include in the runbook. A plan that only covers systems IT directly controls will stall the moment it hits something outside that boundary.
Who needs to be in the room?
Setting these targets properly means pulling finance, sales, and operations into the room, not just IT. Each function will value speed of recovery and tolerance for data loss differently, and a plan built without that input tends to default to whatever the existing infrastructure happens to support, rather than what the business actually needs.
What’s in a Number?
The scale of the threat in Ireland gives this more urgency than it might have carried a few years ago. Cyber Ireland’s Annual Threat Report 2026 recorded 1,243 cyber attacks targeting Irish businesses over the year. That figure includes organisations well outside the obvious high-risk sectors, which is worth sitting with if your own risk assessment still treats a significant incident as unlikely.
Compliance Obligations
NIS2 has pushed this from good practice into a documented obligation for organisations within its scope, requiring business continuity and crisis management measures as part of the broader risk management framework. Even outside that specific regulatory driver, being able to show a board or an auditor a tiered RTO and RPO framework, with evidence it’s been tested, is rapidly becoming the standard against which IT maturity gets judged.
Read our guide on NIS2 for even more information on how this affects your organisation.
