RTO vs RPO Explained for Small Business Websites
RPO is the most data you can afford to lose, measured as time since the last recovery point. RTO is the longest your site can stay down before it is back. Set both from business need first, then choose backups and hosting that can meet them.
This guide is for owners and managers who need to decide how much downtime and data loss their website can tolerate, and for anyone who has to ask a host about it.
What do RPO and RTO mean?
AWS defines both as objectives that the organization sets for itself. Recovery Point Objective (RPO) is the maximum acceptable amount of time since the last data recovery point. Recovery Time Objective (RTO) is the maximum acceptable delay between the interruption of service and restoration of service.
| RPO | RTO | |
|---|---|---|
| Question it answers | How much data can we lose? | How long can we be offline? |
| Measured in | Time since last recovery point | Time until service is restored |
| Driven mostly by | Backup or replication frequency | Restore process and tooling |
A simple example
An online shop takes orders all day. If it backs up once every 24 hours, its RPO is up to a day, so a failure just before the next backup could lose a day of orders. If the owner decides that is too much, they shorten the backup interval or add replication.
How to choose your targets
- List what the site does for the business, such as sales, bookings, lead forms or information.
- Estimate the cost of one hour offline and of losing one hour, one day or one week of data.
- Choose an RPO and an RTO you could defend to a customer.
- Check the cost of meeting them. Tighter targets cost more.
- Write the targets down and review them once a year.
Match targets to backups and hosting
| If your RPO is about | You usually need |
|---|---|
| A week | Weekly full backups stored off the server |
| A day | Daily backups stored off the server |
| A few hours | Frequent database backups or replication |
For RTO, the questions are practical: who restores the site, from which copy, in which location, and how long did the last test restore take?
Test it
Targets only matter if a restore meets them. Restore a backup to a test location at least once a year and time it. Compare the result with your RTO and the age of the backup with your RPO.
What to ask your host
- How often are backups taken and where are they stored?
- Who can restore, and how long does a restore usually take?
- Which RPO and RTO, if any, are written into the service agreement?
- In which country are the backups stored?
Treat any figure that is not in a signed service agreement as a target, not a promise.
Frequently asked questions
What is the difference between RTO and RPO?
RPO limits how much data you can lose, measured as time since the last recovery point. RTO limits how long service can be down.
What is the difference between RTO and MTTR?
Both measure the time from the start of an outage to recovery. AWS notes that MTTR is a mean over several events, while RTO is a target or maximum for a single event.
What RPO should a small business choose?
The one that matches how much recent data you could not rebuild. A brochure site can accept a week. A shop usually needs far less.
Related
Sources
Need this built or fixed?
Start a proposal and our EU-sovereign team will scope it with you.
Start a proposal →