Definitions

  • RPO, Recovery Point Objective. The maximum amount of data you can afford to lose, expressed as a period of time. An RPO of one hour means that, in the worst case, one hour of data is lost. RPO is driven by backup frequency.
  • RTO, Recovery Time Objective. The maximum acceptable time between an incident and a system returning to service. An RTO of two hours means the system must be restored within two hours. RTO is driven by recovery speed.

Comparing RPO and RTO

RPO looks backwards: how much data has been lost since the last healthy backup? RTO looks forwards: how long until operations resume? Both targets should be set for each critical system, based on the actual business cost of downtime and data loss.

The trap: targets that cannot be met in practice

RPO and RTO have little value if the backup design cannot meet them on the day of an attack. Two conditions are required:

  • A recoverable RPO: if the latest healthy point is corrupted or deleted, the stated RPO no longer reflects a real recovery capability. Disconnected restore points limit this risk.
  • An achievable RTO: rebuilding manually across heterogeneous hypervisors can take days. Instant recovery (R2V) brings systems back within minutes, so RTO can be measured in minutes rather than days.

With Oxibox, an individual system can restart within minutes. During the real-world Dharma incident, the entire information system was restored in under two hours.