ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Setting RTO and RPO Recovery Targets for Your Law Firm

Recovery time and recovery point objectives turn a vague wish to be back quickly into numbers. Here is how partners can set them for each firm system.

3 min readBy Counsel Cyber Team

When a partner asks how fast the firm could recover from a serious outage, the honest answer is often "we are not sure." Two terms make the question answerable: recovery time objective and recovery point objective. They are simple ideas that drive real decisions about backup frequency, cloud design and budget.

The two terms in plain English

  • Recovery time objective (RTO): how long a system can be down before the impact becomes unacceptable. If your RTO for email is four hours, you plan to have email working again within four hours.
  • Recovery point objective (RPO): how much recent data you can afford to lose, measured in time. If your RPO for the document system is one hour, backups must capture changes at least that often so you lose no more than an hour of work.

RTO is about downtime. RPO is about data loss. A system can have a short RPO and a long RTO, or the reverse.

Why a law firm should set them deliberately

Courts do not extend deadlines because of a server failure, and clients expect responsiveness. A firm without defined objectives tends to either overspend on protecting trivial systems or underprotect critical ones. Setting targets puts the conversation in business terms partners understand.

ABA Model Rule 1.1 Comment 8 and Rule 1.6(c) touch on understanding technology risks and protecting client information, and availability of client files is part of serving clients. The ABA has not set specific recovery targets, so choose what fits your practice.

How to set targets: five steps

1. List your systems

Include email, document management, practice management, billing and trust accounting, phone system, file shares, e-filing access and any line-of-business applications.

2. Rank by impact

Ask partners and administrators: if this system were unavailable for a day, what would stop? Mark systems as critical, important or routine.

3. Ask the two questions

For each system:

  1. How long could we work without it, using a workaround?
  2. How much recent work could we afford to recreate?

4. Write the targets down

Record them in a simple list in your plan. For example, a hypothetical firm might decide that email needs a four-hour RTO and 15-minute RPO, document management needs a four-hour RTO and one-hour RPO, and archived closed-matter files can tolerate several days. These figures are illustrations, not recommendations.

5. Test them

Targets that are never tested are guesses. Run recovery exercises and measure the actual time. If testing shows eight hours for a system with a four-hour target, you have a gap to fix or a target to revise.

What drives the cost

Tighter targets generally cost more. Short RPOs need frequent backups or replication. Short RTOs may require standby systems, cloud-hosted recovery environments or simplified architecture. Moving to cloud services can change the picture, because the vendor handles some availability, but you still need an independent plan for data protection and for account compromise.

Common mistakes

  • Setting a universal target for every system
  • Choosing numbers that the current backup design cannot meet
  • Forgetting dependencies, such as needing identity services, internet access and licenses before applications work
  • Ignoring the people side, including who makes decisions and who contacts clients
  • Assuming the vendor's availability promise equals your recovery

Workarounds count

Part of meeting an RTO may be a manual fallback. Printed contact lists, a mobile hotspot, a shared mailbox in a second service, or access to court calendars by phone can keep the firm functioning while systems recover. Document these in your plan.

Put the numbers to work

Once targets exist, use them to:

  • Choose backup frequency and retention
  • Select cloud recovery options
  • Compare vendor service levels
  • Brief your cyber insurance carrier
  • Answer client questionnaires accurately

Next step

Gather partners for an hour, list your top ten systems and assign a draft RTO and RPO to each. Counsel Cyber can then compare those targets against your actual backup design and run a timed recovery test to show where reality falls short.