ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Recovery Time and Recovery Point Goals in Plain English for Firms

RTO and RPO explained for law firm leaders, with an exercise for setting realistic recovery goals system by system and budgeting for what they require.

3 min readBy Counsel Cyber Team

Two acronyms drive almost every conversation about disaster recovery: RTO and RPO. They sound technical, but they express two questions that any managing partner can answer: how long can we be down, and how much recent work can we afford to lose?

Those answers determine what you need to buy and how you need to configure it. Without them, backup design becomes guesswork, and firms either overspend on protection they do not need or discover during a crisis that their setup cannot meet their expectations.

The two terms

Recovery time objective (RTO)

RTO is the target amount of time between a failure and the point at which a system is working again. If your RTO for email is four hours, the plan should make it possible to restore email within four hours of an outage.

Recovery point objective (RPO)

RPO is the maximum amount of data, measured in time, that you are willing to lose. If backups run once each night, a failure late in the day could lose almost an entire day of work, so your effective RPO is about twenty-four hours. If you want an RPO of one hour, data must be protected at least hourly.

A simple way to remember: RTO is about time to recover, RPO is about data you lose.

Why firms need different goals for different systems

Not every system carries the same urgency. A trial attorney with a hearing in the morning needs documents and email immediately. An archive of closed matters from a decade ago can wait. Setting a single goal for everything is expensive and usually unnecessary.

Group your systems by importance:

  1. Critical: email, calendars, practice management, document management, phone system, internet access.
  2. Important: accounting and billing, shared file storage, e-filing credentials.
  3. Lower priority: archives, internal wikis, old project folders.

An exercise you can do in one meeting

Gather the managing partner, administrator, a senior paralegal and your IT contact. For each system, ask:

  • If this were unavailable, how long until the firm suffers real harm? Consider court deadlines, client commitments and billing.
  • How much recent data could we re-create by hand? An hour of email is different from a day of billing entries.
  • Are there workarounds? Webmail on personal phones, paper notes, or temporary hotspots can bridge short outages.

Record the answers in a simple table of your own with system, RTO and RPO columns. Expect disagreement. Litigators and transactional attorneys, for example, may rank systems differently.

Translating goals into design

Once you have goals, ask your IT provider to explain what the current setup delivers and where it falls short.

  • Short RPO typically requires more frequent backups or continuous replication, which uses more storage and bandwidth.
  • Short RTO typically requires faster restore methods, such as local backups, standby systems, or replicated cloud environments, all of which add cost.
  • Ransomware complicates both, because restoring must start from a clean copy and may require rebuilding systems before data can be restored.

Ask for an honest estimate of actual recovery time, not the theoretical best case. A restore test, as covered in other posts, provides real evidence.

Budgeting for the answer

Tighter objectives cost more. Rather than asking "what should we spend," ask "what does each level of protection cost, and what is our exposure without it?" Present the options to the partners:

  1. Basic: nightly backups with offsite copies. Longer recovery, higher potential data loss.
  2. Enhanced: more frequent backups for critical systems and local copies for rapid restore.
  3. Advanced: replication or standby systems for the most critical applications.

Partners can then make a deliberate decision. Even a conscious decision to accept a longer recovery for some systems is better than an unexamined assumption.

Common mistakes

  • Assuming cloud services mean zero downtime. Vendors have outages, and accidental deletion is not the same as an outage.
  • Setting goals that nobody tests.
  • Forgetting dependencies, such as identity systems, DNS or internet service, that must be working before applications can start.
  • Ignoring staff. A recovery plan needs someone to run it, with clear contact lists and instructions kept offline.

Keeping goals current

Review RTO and RPO annually or after significant changes, such as adding an office, adopting a new platform, or changing the practice mix. Document them in your incident response and continuity plans, and share the summary with insurers and clients who ask.

Counsel Cyber helps law firms run this exercise and design recovery around the answers. If you would like a facilitated session with your partners, we can bring a template and handle the technical translation.