ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

How Long Can We Be Down? Business Targets for Disaster Recovery

RTO and RPO sound technical but reduce to two partner-level questions: how long can the firm be down, and how much recent work can it afford to lose?

3 min readBy Counsel Cyber Team

When a firm's systems fail, partners tend to ask two questions in the first ten minutes: how long until we are back, and how much work did we lose? Those are the business versions of two terms from disaster recovery planning: recovery time objective and recovery point objective.

Many firms have never set these deliberately, which means their backup design reflects whatever was convenient or cheap rather than what the practice needs. Setting realistic targets is a partner-level conversation, and it shapes budget, technology and expectations.

Two definitions

Recovery time objective (RTO) is the maximum acceptable length of time a system can be unavailable. If your document management system has an RTO of four hours, you are saying that being down longer than that causes unacceptable harm.

Recovery point objective (RPO) is the maximum acceptable amount of data loss, measured in time. If email has an RPO of one hour, you are saying you can tolerate losing up to an hour of messages, and your backups need to run at least that often.

A simple way to remember: RTO is about the clock after the failure, and RPO is about the clock before it.

Why law firms are particular

Law practice has features that influence these targets.

  • Deadlines. A missed filing deadline is far more serious than a missed internal report. A litigation team with a motion due tomorrow cannot wait three days.
  • Billable time. Every hour of downtime carries a measurable cost in lost productivity.
  • Client files and confidentiality. Data loss can touch ethical duties of competence and communication.
  • Trust accounting. Records may have regulatory requirements, so losing recent entries can cause serious problems.
  • Court and client expectations. Clients may expect rapid responses regardless of IT problems.

Step 1: List your systems

Include email, document management, practice management, billing and trust accounting, phone system, file servers, remote access, the website, and any line-of-business applications such as e-filing integrations.

Step 2: Rank by importance

Group systems into tiers.

  1. Critical: the firm cannot function without it. Typically email, document management, practice management and phones.
  2. Important: work slows significantly without it.
  3. Deferrable: can wait several days.

Ask attorneys and staff, not just IT. The people who do the work know what hurts.

Step 3: Assign targets, honestly

For each tier, propose an RTO and RPO and discuss them in plain language.

  • "If email is down for one day, what happens?"
  • "If we lose this morning's documents, how hard is it to recreate them?"
  • "How many hours of billing entries could we re-enter from memory?"

Do not choose numbers because they sound good. Shorter targets cost more, because they require more frequent backups, replication and standby systems.

Step 4: Compare targets with reality

Now ask your IT provider how long a restore would actually take and how often backups run. Compare that to the targets.

  • If backups run nightly, your actual RPO is up to a day, no matter what the plan says.
  • If a full server restore requires pulling hundreds of gigabytes over an office internet connection, your RTO may be measured in days.
  • If the recovery process depends on one technician, your RTO includes the time to find that person.

Gaps are normal. The point is to make them visible.

Step 5: Decide what to do about the gaps

Options include:

  • Increasing backup frequency for critical systems.
  • Using cloud-based recovery or replication so you can run key systems from another location.
  • Moving systems to vendor-hosted platforms with their own resilience, while still backing up your data separately.
  • Preparing manual workarounds for short outages, such as a list of critical client contacts and calendar deadlines kept outside the main system.
  • Accepting some risk knowingly and documenting that decision.

Step 6: Test and revisit

Targets on paper mean little until a restore test shows what is achievable. Re-examine them annually or after any major change in systems, staffing or practice mix. Insurers and clients sometimes ask whether you have defined recovery objectives, so record them in a short document.

Don't forget communication

A recovery plan should say who informs clients, who contacts the carrier, how staff will be reached if email is down and where the plan itself is stored. A plan that lives only on the failed server is not much use.

Getting started

Counsel Cyber helps law firms define recovery objectives, compare them with their current backups and design improvements within budget. If you would like to run this exercise with your partners, we can facilitate a short working session.