Home›Guides›DRP and BCP

DRP and BCP

How do you set your RPO?

You set an RPO by asking, for each activity: “if we lost everything entered in the last X hours, what would have to be redone, and how much would it cost?” The largest value of X that is still acceptable is the RPO. You then configure the backup so that the interval between two successful copies is shorter than that X.

Updated October 20263 min read4 sources cited

Key points

  • Ask the users of each tool, not just the IT person.
  • Three criteria: how fast the data changes, whether it can be rebuilt, the cost of losing it.
  • A 24-hour RPO assumes a morning alert: two failures in a row, and the actual RPO becomes 48 hours.
  • Below one hour, plan for replication or database logs, and a history that protects against ransomware.
  • The depth of history (30 days, one year) is a setting separate from the RPO.

The method in one meeting

NIST calls this exercise a business impact analysis (BIA): identify the processes, measure the consequences of an interruption, then set recovery priorities. For an SME, one meeting is enough. For each vital tool, ask three questions to the people who use it, not just the IT person.

  1. How fast does the data change? One entry per minute, per hour, per week?
  2. Can it be rebuilt? An email received from outside, no. An invoice whose copy is still on the customer’s desk, partly. A workshop production entry, no.
  3. After how much lost time does the cost become unacceptable? Cost of re-entry, orders to be placed again, files to be reopened from memory.

Write the answer down in hours. Common examples in SMEs:

ActivityOften reasonable RPOWhy
Rarely modified office files24 hLosing a day is noticeable and can be redone
ERP or quoting software used all day1 to 4 hA lost day of quotes cannot be reconstructed
Email1 to 8 hIncoming messages cannot be re-entered
Accounting24 h, plus separate long-term archivingThe day can be redone; the financial year is archived
Point-of-sale databaseMinutes to 1 hCash received must remain traceable

This table is not a standard. It is a starting point to challenge or confirm with operational staff.

Translating the RPO into a frequency

  • RPO 24 h: one successful backup per day, and an alert in the morning if it failed. If it fails two nights in a row, the actual RPO becomes 48 h. Monitoring is part of the RPO.
  • RPO 4 h: at least one copy every four hours during business hours.
  • RPO below one hour: replication or very frequent copies, and a separate discussion about ransomware, because the freshest copy may already be bad. ANSSI, France’s national cybersecurity agency, also recommends considering replication in addition to backup when the tolerable loss is below 24 hours.

For a database, frequency is not set by full backups alone. Microsoft states that in the full recovery model, frequent transaction log backups make it possible to restore to a precise point in time. This is often the most economical way to achieve an RPO of a few minutes on business software.

Also plan the depth: being able to go back 30 days does not change the RPO (which is about freshness), but it saves the day when the latest copies are corrupted. ANSSI gives as an example 15 days of daily backups, one year of monthly backups and five years of yearly backups. The two settings coexist.

Checking that the RPO is met

An RPO is checked in the console, not in the contract:

  • the time of the last successful copy of each server, every morning;
  • the duration of the jobs: a backup that takes five hours cannot run every four hours;
  • the volume of changes sent compared with the site’s upload bandwidth;
  • a restore test, at least on one file, to prove that the copy is readable. See How do you test that a backup works?.

Mistakes

  • Letting the software vendor announce the RPO (“real-time backup”) without looking at the actual interval between jobs.
  • A single RPO for the whole company, set to match the most talkative application, which means paying the maximum level for static files.
  • Forgetting that the RPO of cloud email is that of your copy, not that of the vendor’s recycle bin.

At WeDoBack

The frequency is set in the console: the RPO depends on this choice by the customer. The subscribed volume must absorb this frequency, because closer copies retain more changes. The published rule of thumb to get started is the current volume multiplied by three, to be adjusted after a week of use. WeDoBack does not impose an RPO. If the customer’s link cannot send the changes within the chosen interval, the actual RPO will be longer than the displayed RPO: this is a physical constraint, to be measured in the first month, not a detail. Backup monitoring runs 24/7; human support is available from 9 am to 1 pm and from 2 pm to 5:30 pm (Paris time, i.e. from 11 am to 3 pm and from 4 pm to 7:30 pm Mauritius time during European summer time, one hour later during European winter time). Prices for the SMART and INTEGRAL offers are detailed on the offers and prices page.

Frequently asked questions

Who should set the RPO, management or IT?

Management and business managers, because the RPO is an economic choice: how much lost work the company accepts. IT then translates that choice into a backup frequency, and flags what is technically impossible with the available bandwidth or budget.

Do all servers need the same RPO?

No. A single RPO, set to match the most active application, means paying the maximum level for files that rarely change. One line per activity, with its own frequency, is more accurate and often cheaper.

Is the RPO for Microsoft 365 or Google Workspace the vendor’s?

No. The vendor’s recycle bins and retention are not a copy you control. The RPO of your email is that of your own backup: its frequency and its last success.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.