Two acronyms sit at the center of every disaster recovery plan: RPO and RTO. IT providers use them constantly, and law firm leaders often nod without being sure what they mean. They are not technical details. They are business decisions that only the firm can make, and they determine what you should spend on backup and recovery.
The Definitions
- Recovery Point Objective (RPO): how much data the firm can afford to lose, measured in time. If your RPO for email is one hour, you can tolerate losing up to one hour of messages. It determines how often you must back up.
- Recovery Time Objective (RTO): how long the firm can be without a system before the impact becomes unacceptable. If your RTO for the document system is four hours, it must be usable again within four hours of an outage. It determines how you design recovery.
Think of RPO as "how far back do we go" and RTO as "how long until we are back."
Why They Matter for a Law Firm
Law firms operate on deadlines. A filing due at 5 p.m. cannot wait for a three-day restore. Billing and time entries represent revenue. Trust accounting records have regulatory importance. Client communications cannot simply vanish. Setting RPO and RTO forces a conversation about which systems matter most, and it prevents two common failures: spending heavily on systems that do not need it, and discovering that a critical system takes days to restore.
ABA Model Rule 1.4 on communication and Rule 1.6(c) on safeguarding client information both come into play when data is unavailable, and ABA Formal Opinion 483 discusses obligations after a data breach. Planning recovery in advance helps a firm respond reasonably.
How to Set Them
Step 1: List your systems
Include email, document management, practice management, billing, accounting and trust software, the phone system, file servers, line-of-business applications, and anything staff would struggle to work without.
Step 2: Rank by impact
For each system, ask two questions:
- If this were unavailable for an hour, a day, a week, what would happen?
- If we lost the last hour, day or week of data, could we recreate it?
Rank each as critical, important or routine.
Step 3: Assign objectives
Here is a hypothetical example for a mid-size firm. These numbers are illustrations only, not recommendations:
- Email and calendar: very low RPO and an RTO of a few hours, because deadlines and client contact depend on it
- Document management: low RPO and a short RTO, since work product changes constantly
- Billing and time entry: an RPO of a day may be tolerable if staff can re-enter time, with an RTO of a day or so
- Trust accounting: low RPO because errors are costly, with a moderate RTO
- Archived closed files: a longer RPO and RTO, as they change rarely
Step 4: Check that your backups meet them
If a system has a one-hour RPO but only a nightly backup, the plan does not meet the goal. If RTO is four hours but restoring from offsite storage takes two days, the plan fails. Ask your IT provider to compare actual backup frequency and measured restore times against your targets.
Step 5: Test
Run restore tests and time them. Real numbers beat estimates. Include the steps that surround restoration, such as reconnecting users and verifying the data.
Cost Versus Speed
Tighter objectives cost more: more frequent backups, replication, standby systems, and more staff time. That is why ranking matters. Spend on speed where downtime is truly expensive and accept slower recovery for the rest.
Common Mistakes
- Setting one target for everything
- Choosing goals without talking to attorneys and billing staff
- Forgetting dependencies, such as the identity system needed to log in to everything else
- Writing goals that nobody tests
- Not revisiting goals when the firm grows or changes software
Document and Review
Put the objectives in a one-page table or list, approved by firm leadership, and include them in your incident response and continuity plans. Review annually or after significant changes. Cyber insurance applications and client questionnaires increasingly ask about recovery capability, and written goals make answers simple.
Counsel Cyber's Role
Counsel Cyber helps law firms translate recovery goals into backup design, run timed restore tests, and keep the documentation current. If you have never put numbers on how long you can be down, we can facilitate the conversation with your partners.