Concept and mechanism
A Disaster Recovery plan starts with the impact of interruption and data loss. RTO defines maximum acceptable time between interruption and service recovery; RPO defines the maximum acceptable window relative to the recoverable data point. They are not interchangeable. In a fictional example, service stops at 10:00 and resumes completing operations at 10:42. With a 30-minute RTO, observed duration is 42 and the gap is 12. If failure at 14:00 only permits recovery of 13:40 state, the potential window is 20 minutes even if restoration takes only five. Distinguish agreed objective, observed measurement, and deviation.
Guided application
Analyze the complete service. An application starting within half an hour can remain unavailable if indispensable identity or database services need two hours. Align objectives, dependencies, and alternatives with business and technical teams. Consequences also vary over time: missing a cut-off can have much greater impact than the same delay in the morning. The manager should make this difference explicit in priorities and activation criteria. Requesting zero loss and zero time for everything does not establish feasibility; compare cost, complexity, and actual need. During an incident, do not rewrite objectives to match results. Communicate gaps, evidence alternatives, and obtain traceable decisions on degraded modes and reconciliation.
A 42-minute recovery exceeds a 30-minute RTO by 12 minutes without changing the original objective.
Common pitfalls
RTO as backup age; frequency as recoverable point; component as service; zero as guarantee.
Related topics: Strategies and data protection · Backups and recoverable points · Recovery-site readiness and configuration
Measure time and data separately and include dependencies in the commitment.
Reference: Define recovery time and recovery point objectives · DR recovery 2026-09; PostgreSQL 18, etcd 3.6 and selected AWS/Azure behavior