If the worst happens: does your backup hold up?
Continuity requirements come down to two questions: how much downtime can you tolerate (RTO), and how much data can you afford to lose (RPO). The answers set the protection level and the price. Require that restoring from backup is actually rehearsed, not just taken, and that responsibility between you, the agency, and the cloud provider is settled in advance.
Backup is one of those items that’s easy to tick off and assume you’re covered. But “we take backups” says almost nothing about how well protected the business actually is. Two questions make continuity concrete and measurable, and they should be answered by you as the buyer – not buried in a technical appendix. Here’s how to think about them.
RTO and RPO: the two numbers that drive everything
Behind all continuity work sit two metrics. They sound technical but describe pure business decisions.
RTO – how long can it take to come back up? Recovery Time Objective is the amount of downtime you can tolerate after an outage. An online store in the middle of the holiday rush might measure its RTO in minutes. An internal planning tool can live with half a day. RTO answers the question: how fast must we be back?
RPO – how much data can be lost? Recovery Point Objective is the amount of data you can afford to lose, measured in time. An RPO of one hour means the most recent backup must never be older than an hour – in other words, backups must be taken at least every hour. RPO answers the question: how much work can afford to disappear?
The two numbers are related but different. The first is about uptime, the second about data. And both are business decisions: it’s the business, not the technology, that decides what an outage or data loss actually costs.
A business example
Take a booking system for a medical clinic. If the system is down for a morning, appointments get cancelled and staff sit idle – so RTO needs to be short, say a couple of hours. If bookings made in the last hour disappear, you get double bookings and patients being called – so RPO needs to be tight, maybe fifteen minutes.
Compare that to an internal system that compiles statistics once a week. There, a day’s outage does little harm, and a day’s lost data can be recreated. Same organization, two completely different needs. The point is not to give everything the same protection. Matching the level to what each system actually means for the business is what keeps the cost reasonable.
| System | Reasonable ambition level |
|---|---|
| Business-critical (booking, payment) | Short RTO, tight RPO – more frequent backups, faster recovery |
| Business-supporting | Moderate RTO and RPO – daily backup is often enough |
| Internal and rarely used | Long RTO and RPO – simple protection, low cost |
The requirement everyone forgets: rehearse the restore
Here’s where the most common and most dangerous mistake lies. Almost everyone takes backups. Far fewer have ever tested restoring one.
A backup that’s never been restored isn’t a guarantee – it’s a hope. Files can be corrupted, missing parts, or take hours longer to restore than anyone expected. Sometimes it’s discovered in the middle of an active crisis that the backup of a central database has been broken for months, with no one alerted.
So require that restores are rehearsed regularly, not just that backups are taken. A real rehearsal restores the system in a safe environment, verifies the data is intact, and measures how long it took – which also reveals whether your RTO is realistic or wishful thinking. Only once the recovery is proven is the protection real.
Splitting responsibility: you, the agency, and the cloud
The last thing to settle is who’s responsible for what. This is where dangerous gaps appear, because all three parties often assume someone else has it covered.
- The cloud provider is responsible for its infrastructure and keeps its own systems up. But it doesn’t automatically protect your data against you accidentally deleting something, or against a faulty update – its default commitment is usually narrower than people assume.
- The agency or operations partner may have set up the backup routines, but that doesn’t automatically mean they’ve committed to restoring in a crisis, or to rehearsing the restore. That has to be spelled out.
- You carry the ultimate responsibility for the business being able to continue. That responsibility can be delegated in practice, but not assumed away.
Write down who does what – takes backups, stores them, tests restores, and acts in an active incident. A written division of responsibility is cheap insurance against the worst discovery of all: that nobody had responsibility when it mattered.
At Weapp, we’re happy to build continuity and backup into the system work from the start, so the protection matches the business and is actually rehearsed. Get in touch and we’ll go through what’s reasonable for you.
Frequently asked questions
What do RTO and RPO mean?
RTO (Recovery Time Objective) is how fast the service must be back up after an outage. RPO (Recovery Point Objective) is how much data you can afford to lose, measured in time. An RPO of one hour means backups must be taken at least every hour. Together they describe how much disruption and data loss the business can tolerate.
Isn't it enough that backups are taken automatically?
No. A backup that's never been tested is just a hope. Files can be corrupted, missing parts, or take far longer to restore than anyone expected. The only thing that proves the protection works is a rehearsed restore, where you actually recover and verify that the system comes up and the data is intact.
Who's responsible for backup – us, the agency, or the cloud provider?
It depends on the setup, and that's exactly why it needs to be settled in advance. The cloud provider is usually responsible for its infrastructure, but not automatically for your data the way you might assume. The agency may have set up backup routines without necessarily having committed to restoring them. Write down who does what, so no gap opens up when it matters.
How often should backups be taken?
As often as your RPO requires, no more and no less. A system where a day's lost orders is manageable can get by with daily backups. A system where every transaction counts needs much tighter intervals, sometimes continuous. The question is always how much data you can afford to lose – the answer sets the pace.
What do higher protection levels cost?
The price rises with the ambition. More frequent backups, faster recovery, and geographic redundancy cost more in both storage and complexity. The point is to match protection to the business's real needs: not everything needs the same level. A business-critical system deserves more than an internal reporting module, and telling them apart saves money.