When a partner asks how fast the firm could recover from a serious outage, the honest answer is often "we are not sure." Two terms make the question answerable: recovery time objective and recovery point objective. They are simple ideas that drive real decisions about backup frequency, cloud design and budget.
The two terms in plain English
- Recovery time objective (RTO): how long a system can be down before the impact becomes unacceptable. If your RTO for email is four hours, you plan to have email working again within four hours.
- Recovery point objective (RPO): how much recent data you can afford to lose, measured in time. If your RPO for the document system is one hour, backups must capture changes at least that often so you lose no more than an hour of work.
RTO is about downtime. RPO is about data loss. A system can have a short RPO and a long RTO, or the reverse.
Why a law firm should set them deliberately
Courts do not extend deadlines because of a server failure, and clients expect responsiveness. A firm without defined objectives tends to either overspend on protecting trivial systems or underprotect critical ones. Setting targets puts the conversation in business terms partners understand.
ABA Model Rule 1.1 Comment 8 and Rule 1.6(c) touch on understanding technology risks and protecting client information, and availability of client files is part of serving clients. The ABA has not set specific recovery targets, so choose what fits your practice.
How to set targets: five steps
1. List your systems
Include email, document management, practice management, billing and trust accounting, phone system, file shares, e-filing access and any line-of-business applications.
2. Rank by impact
Ask partners and administrators: if this system were unavailable for a day, what would stop? Mark systems as critical, important or routine.
3. Ask the two questions
For each system:
- How long could we work without it, using a workaround?
- How much recent work could we afford to recreate?
4. Write the targets down
Record them in a simple list in your plan. For example, a hypothetical firm might decide that email needs a four-hour RTO and 15-minute RPO, document management needs a four-hour RTO and one-hour RPO, and archived closed-matter files can tolerate several days. These figures are illustrations, not recommendations.
5. Test them
Targets that are never tested are guesses. Run recovery exercises and measure the actual time. If testing shows eight hours for a system with a four-hour target, you have a gap to fix or a target to revise.
What drives the cost
Tighter targets generally cost more. Short RPOs need frequent backups or replication. Short RTOs may require standby systems, cloud-hosted recovery environments or simplified architecture. Moving to cloud services can change the picture, because the vendor handles some availability, but you still need an independent plan for data protection and for account compromise.
Common mistakes
- Setting a universal target for every system
- Choosing numbers that the current backup design cannot meet
- Forgetting dependencies, such as needing identity services, internet access and licenses before applications work
- Ignoring the people side, including who makes decisions and who contacts clients
- Assuming the vendor's availability promise equals your recovery
Workarounds count
Part of meeting an RTO may be a manual fallback. Printed contact lists, a mobile hotspot, a shared mailbox in a second service, or access to court calendars by phone can keep the firm functioning while systems recover. Document these in your plan.
Put the numbers to work
Once targets exist, use them to:
- Choose backup frequency and retention
- Select cloud recovery options
- Compare vendor service levels
- Brief your cyber insurance carrier
- Answer client questionnaires accurately
Next step
Gather partners for an hour, list your top ten systems and assign a draft RTO and RPO to each. Counsel Cyber can then compare those targets against your actual backup design and run a timed recovery test to show where reality falls short.