Glossary

Recovery Time Objective (RTO)

Maximum acceptable time within which systems or processes must be restored after a disruption.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

The Recovery Time Objective (RTO) specifies the maximum acceptable duration within which systems, applications or business processes must be restored after a disruption. It represents the threshold beyond which downtime causes unacceptable harm to the organisation (whether financial, reputational or regulatory). RTO is a fundamental metric in disaster recovery and business continuity planning.

Defining realistic RTOs requires input from both technical teams and business stakeholders, as the cost of achieving shorter recovery times increases significantly with tighter targets. Regular disaster recovery testing is essential to validate that actual recovery capabilities align with documented RTOs and to identify bottlenecks before a real incident occurs.

S

T

U

V

W

Z

Frequently asked questions

What is a Recovery Time Objective (RTO)?
The RTO is the maximum acceptable time a process or system may be unavailable before the impact on the business becomes unacceptable. It answers: how quickly must this be back?
What is the difference between RTO and RPO?
RTO is about time to restore; RPO — Recovery Point Objective — is about how much data you can afford to lose, measured back from the moment of failure. An RTO of four hours with an RPO of fifteen minutes means restore within four hours, losing at most fifteen minutes of data.
How do you set a realistic RTO?
Derive it from a business impact analysis rather than from what the infrastructure currently manages, then test whether you actually meet it. An RTO that has never been verified in a restore test is an aspiration, not a control.