Every business depends on its IT systems. A hardware failure, a ransomware cyberattack, a human error that deletes a critical database, or a natural disaster that takes down an entire data centre: any of these scenarios can bring a company's operations to a halt in a matter of minutes. The question is not whether an incident will occur, but when. And the difference between a business that survives a disaster and one that does not comes down to having a well-defined Disaster Recovery (DR) plan.
At the heart of any DR plan lie two fundamental metrics that determine the architecture, cost and effectiveness of the recovery strategy: the RPO (Recovery Point Objective) and the RTO (Recovery Time Objective). Understanding these two concepts is the first step towards designing a business continuity strategy that is realistic, proportional to the risk and aligned with the budget.
In this article we explain what RPO and RTO are, how to calculate them according to business type, which technologies correspond to each level of requirement, how Veeam facilitates DR implementation and what services EasyDataHost offers to protect your infrastructure.
What Is Disaster Recovery
Disaster Recovery (DR) is an organisation's planned capability to recover its IT systems, applications and data after a disruptive event. It is not just about having backups: a complete DR plan includes documented procedures, prepared infrastructure, assigned roles and periodic testing to ensure that, when a disaster strikes, recovery is fast, predictable and controlled.
Disasters can take many forms: hardware failures (disk, controller, power supply), cyberattacks (ransomware, data destruction), human errors (accidental deletion, misconfiguration), natural disasters (fire, flood, earthquake) or provider failures (data centre outage, prolonged network disruption). An effective DR plan covers all these scenarios with strategies tailored to the criticality of each system.
The difference between Disaster Recovery and high availability (HA) is important: HA prevents downtime from individual component failures (a disk, a node), while DR prepares for recovery from events that affect the entire primary infrastructure. Both are complementary and necessary. A sound strategy combines local HA with DR to a remote location following cloud backup best practices.
RPO: Recovery Point Objective
The RPO (Recovery Point Objective) defines the maximum amount of data an organisation can afford to lose, measured in time. In other words, it answers the question: if a disaster happens right now, to what point in time can we restore the data?
An RPO of 24 hours means the organisation accepts losing up to a full day of data. An RPO of 1 hour means the maximum acceptable loss is one hour of changes. An RPO of zero (or near-zero) means no transaction loss is tolerated, which requires real-time synchronous replication.
RPO is directly linked to backup or replication frequency. The lower the desired RPO, the more frequent the copies must be or the more advanced the replication technology needs to be. A low RPO implies greater storage consumption, bandwidth and infrastructure cost. That is why each system should have an RPO proportional to its criticality: there is no point in applying a 5-minute RPO to an internal file server if a 24-hour RPO is sufficient.
Key concept:
RPO answers how much data can I lose. It is measured in time (minutes, hours, days). A lower RPO demands more frequent backups or continuous replication, which increases cost but reduces the risk of data loss. The GFS (Grandfather-Father-Son) strategy helps organise backup retention across different time levels.
RTO: Recovery Time Objective
The RTO (Recovery Time Objective) defines the maximum time that can elapse from the moment a disaster occurs until systems are operational again. It answers the question: how long can we be offline before the impact becomes unacceptable?
An RTO of 8 hours means the organisation can tolerate up to a full working day without access to its systems. An RTO of 30 minutes indicates the business needs to be back up in less than half an hour. An RTO close to zero requires hot standby infrastructure that takes over the load instantaneously when the primary system fails.
RTO is linked to the cost of recovery infrastructure. Reducing the RTO means having servers, storage and networks ready to go live at any moment. The lower the RTO, the more expensive the required infrastructure: a hot standby with automatic failover is far more costly than restoring from tapes stored at an offsite facility.
RPO and RTO by Business Type
RPO and RTO values vary enormously depending on the type of business and the criticality of the systems. The following table shows typical examples that serve as a starting point for defining recovery objectives for each organisation:
| Business type | RPO | RTO | Rationale |
|---|---|---|---|
| E-commerce | 1 hour | 1 hour | Every hour of downtime means lost sales; every unrecorded order is an unhappy customer |
| Hospital / Healthcare | 0 (near-zero) | 15 minutes | Medical records and critical systems cannot lose data or become inaccessible |
| Small office | 24 hours | 8 hours | A daily backup is sufficient; recovery can wait until the next working day |
| SaaS platform | 5 minutes | 30 minutes | Customer SLAs demand high availability; data loss affects many users simultaneously |
Technologies by RPO Level
Each RPO level requires a different technology. As RPO decreases, complexity and cost increase, but so does the protection against data loss:
- event Daily backup (RPO: 24h): one full or incremental copy per day, typically overnight. This is the minimum baseline. Suitable for non-critical systems, internal files and development environments. Immutable backups add protection against ransomware.
- schedule Hourly backup (RPO: 1h): incremental copies every 60 minutes. Requires more storage and bandwidth, but reduces the loss window to a maximum of one hour. Ideal for transactional business databases and ERP systems.
- sync Continuous replication (RPO: minutes): CDP (Continuous Data Protection) or asynchronous replication that captures changes at intervals of seconds or minutes. Veeam offers CDP for VMware with RPO measured in seconds. Suitable for SaaS platforms and critical applications.
- bolt Synchronous replication (RPO: near-zero): every write is confirmed simultaneously at the primary site and the DR site. Zero data loss, but requires low latency between sites and greater bandwidth. Necessary for finance, healthcare and systems where every transaction is irreplaceable.
Technologies by RTO Level
The RTO determines how fast systems must be back in production. Each RTO level implies a different type of recovery infrastructure:
- inventory_2 Tape restore (RTO: days): LTO tapes stored offsite offer the lowest cost per TB, but restoration involves requesting the tapes, transporting them, mounting the drive and restoring sequentially. It can take days.
- hard_drive Disk restore (RTO: hours): backups stored in disk repositories (local or offsite S3) allow faster restorations. Depending on data volume, a full server restore can take between 1 and 8 hours.
- play_arrow Instant VM Recovery (RTO: minutes): technologies such as Veeam Instant Recovery boot a VM directly from the compressed backup file, without waiting for a full restore. The VM is operational in 2-5 minutes while data migrates in the background.
- flash_on Hot standby (RTO: seconds): active replicas of VMs running at a DR site. When the primary site fails, failover is immediate or near-immediate. It is the most expensive option but essential for systems with availability SLAs above 99.99%.
DRaaS: Disaster Recovery as a Service
Not every company has the budget or technical capacity to build and maintain its own DR site. DRaaS (Disaster Recovery as a Service) solves this problem by delegating the recovery infrastructure to a cloud provider. The model is straightforward: the virtual machines in the production environment are continuously replicated to an external data centre, and in the event of a disaster, they are started at that remote location.
The advantages of DRaaS over on-premise DR are clear: no upfront hardware investment, no need to maintain a second data centre, predictable cost (pay-per-use) and the provider handles the infrastructure, maintenance and monitoring. Moreover, being in a different geographical location, it protects against disasters that affect the primary site.
EasyDataHost offers Veeam DRaaS with VM replication to our data centre in Spain, automated failover, DR testing without production impact and a guaranteed SLA. It is the fastest and most efficient way to have a complete DR site without the complexity of managing it internally.
Key concept:
DRaaS provides a complete recovery site at an external data centre without investing in your own hardware. VMs are continuously replicated and can be started within minutes when the primary site fails.
Veeam for Disaster Recovery
Veeam Backup & Replication is the market-leading platform for data protection in virtualised environments, and it offers a comprehensive set of tools for implementing DR strategies with different RPO and RTO levels:
- backup Backup & Replication: incremental VM backups with Changed Block Tracking (CBT), compression and deduplication. Supports local targets, offsite repositories and S3 storage.
- cloud_sync Veeam Cloud Connect: replication of backups and VMs to a certified Service Provider (such as EasyDataHost) through a secure TLS channel. No VPN or complex network configuration required.
- verified SureBackup: automated verification of backup restorability. Veeam boots VMs in an isolated sandbox, verifies that the OS starts, that applications respond and that data integrity is correct. This ensures that DR will work when needed.
- play_arrow Instant Recovery: boots VMs directly from the backup file in 2-5 minutes. The VM runs while data migrates in the background to production. Minutes-level RTO without the need for a permanent hot standby.
EasyDataHost offers Veeam licences with included support, plus the offsite backup and DRaaS services needed to implement a complete DR plan with Veeam.
Designing Your Disaster Recovery Plan
An effective DR plan is not improvised: it is built from a systematic analysis of the business. These are the fundamental steps for designing a solid DR plan:
- analytics BIA (Business Impact Analysis): identify all IT systems, classify each one by its impact on the business if it becomes unavailable, and quantify the cost of downtime per hour. The BIA is the foundation for assigning priorities and budget.
- category Classify systems by criticality: divide systems into tiers (Tier 1: mission-critical, Tier 2: important, Tier 3: non-critical). Each tier will have a different RPO and RTO, with proportional DR infrastructure.
- tune Define RPO and RTO per system: assign concrete RPO and RTO values to each system based on its classification. A production ERP may need an RPO of 1h and RTO of 30min, while a file server may tolerate an RPO of 24h and RTO of 8h.
- science Test regularly: a DR plan that is never tested is a plan that does not work. Run DR drills at least twice a year: execute failover to the recovery infrastructure, verify that systems start correctly and measure the actual RPO and RTO times.
Common Disaster Recovery Mistakes
Even organisations that invest in DR make mistakes that can invalidate the entire plan when it is needed most. These are the most frequent errors:
- warning Not testing the DR plan: the most critical mistake. A plan that is written but never tested guarantees nothing. Tests reveal configuration issues, forgotten dependencies and actual recovery times that differ from theoretical estimates.
- warning Same-site backups only: if backups are stored in the same data centre as the production systems, a disaster that affects the data centre (fire, flood) will destroy both. An offsite copy at a different geographical location is always required.
- warning No documentation: if the DR plan only exists in one person's head, when that person is unavailable during a disaster, nobody will know what to do. The plan must be documented, accessible offline and assign clear roles.
- warning Ignoring dependencies: restoring an application server without its database, without DNS, without Active Directory or without the necessary network connectivity is useless. The DR plan must account for all dependencies between systems and the recovery order.
EasyDataHost DR Services
EasyDataHost offers a complete portfolio of Disaster Recovery services designed to cover different RPO and RTO levels, tailored to each organisation's criticality and budget:
- check_circle Veeam DRaaS: VM replication to our data centre with automated failover, impact-free DR testing and a guaranteed SLA.
- check_circle Offsite Backup: backup copies in external repositories with Veeam Cloud Connect, immutability and end-to-end encryption.
- check_circle S3 Storage: S3-compatible object repository with Object Lock for immutable backups and long-term archiving.
- check_circle Managed services: DR plan design, implementation, 24/7 monitoring and periodic recovery testing.
Conclusion
RPO and RTO are the two metrics that define the effectiveness of any Disaster Recovery plan. Without them, there is no objective criterion for choosing technologies, sizing infrastructure or evaluating whether the investment in data protection is proportional to the risk. Defining these values for each system is the first step towards building a realistic and effective DR plan.
- arrow_right RPO defines how much data you can lose; RTO defines how long you can be offline.
- arrow_right A lower RPO requires more frequent or continuous replication; a lower RTO requires more advanced recovery infrastructure.
- arrow_right Each system should have its own RPO and RTO based on a Business Impact Analysis.
- arrow_right Veeam provides comprehensive tools for implementing DR with different RPO and RTO levels.
- arrow_right DRaaS provides a complete recovery site without investing in your own hardware.
If you need to design or improve your Disaster Recovery plan, contact our team to analyse your RPO/RTO requirements and find the solution that best fits your business.