Disaster Recovery Strategy for Enterprises: Zerto, Veeam and the RPO/RTO Decision
How to choose between Zerto and Veeam, set realistic RPO and RTO targets, and build a disaster recovery architecture that survives ransomware.

Short answer: Use Zerto when you need a Recovery Point Objective measured in seconds and failover in minutes for mission-critical workloads. Use Veeam when your priority is immutable backup, long-term retention, and cost-efficient protection across a large environment. Most enterprises should run both: Veeam as the backup baseline for everything, Zerto as the continuous replication layer for the small set of systems where minutes of data loss are unacceptable.
This guide explains how to make that decision with numbers rather than vendor claims, and how the choice changes when you operate under Turkish regulatory requirements such as KVKK.
Two reference numbers to start with: PagerDuty's 2026 data puts the average cost of downtime at $4,537 per minute, while Veeam's 2025 ransomware research puts the average time attacked organizations actually took to recover at 24.6 days. The gap between those two is what this article is about.
What RPO and RTO actually mean
Two figures drive every disaster recovery design.
- RPO (Recovery Point Objective) is how much data you can afford to lose, measured in time. An RPO of 15 minutes means that after an incident, you accept losing up to the last 15 minutes of transactions.RTO (Recovery Time Objective) is how long the business can tolerate the system being unavailable before the impact becomes unacceptable.
These are business decisions, not technical ones. The most common mistake is to set both to near zero for every system, which produces an architecture nobody can afford. The disciplined approach is to tier your workloads and assign different targets to each tier. We lay out a four-step method for deriving targets from business cost in how to calculate RPO and RTO.
A practical workload tiering model
Tier 1, mission critical. Payment processing, core banking, e-commerce checkout, production databases. Target RPO of seconds, RTO under 15 minutes. This tier justifies continuous replication.
Tier 2, business important. ERP, CRM, internal line-of-business applications. Target RPO of 1 to 4 hours, RTO of 4 to 8 hours. Snapshot-based replication is usually sufficient.
Tier 3, standard. File servers, development environments, internal tooling. Target RPO of 24 hours, RTO of 24 to 48 hours. Nightly backup is appropriate.
Tiering matters because the cost curve is steep. Moving a workload from a 24-hour RPO to a sub-minute RPO can multiply its protection cost several times over, driven by bandwidth, storage at the recovery site, and licensing.
Zerto compared with Veeam
A separate article compares the two in detail: Zerto and Veeam compared. The summary below covers only what the tiering decision needs.
Both are strong products solving overlapping but distinct problems.
Zerto was built specifically for disaster recovery. It uses continuous data protection, intercepting writes at the hypervisor level and replicating them as they happen. Zerto publishes RPOs of seconds and failover measured in minutes, because data already sits at the recovery site in native format with no rehydration step. Its journal-based architecture also allows rewinding to a point seconds before a ransomware detonation, which is the single most valuable property in a modern attack scenario.
The trade-offs are real. Zerto requires sustained bandwidth between sites because replication never stops. Its per-VM licensing carries a higher unit cost than backup-oriented tools, and the design work is more demanding.
Veeam is primarily a backup and recovery platform, and it is the stronger choice for long-term retention, immutability, and breadth of coverage. Recent Veeam releases have emphasized immutable-by-default backups and expanded continuous data protection capabilities, narrowing the gap for some use cases. Veeam holds roughly 13.6 percent of the global data protection market, which also means a deep talent pool and mature tooling.
How to choose. If the question is "how do I avoid losing data," start with Veeam. If the question is "how do I keep the business running through an outage," you need Zerto or an equivalent continuous replication layer for the affected workloads. In practice these are complementary rather than competing purchases.
FKM or DRaaS: the architecture question
In the Turkish market the choice is usually framed as FKM (Felaket Kurtarma Merkezi, a disaster recovery center) versus DRaaS (Disaster Recovery as a Service).
A traditional FKM means hardware and software you own, in a second facility you control. It gives maximum control and can be mandatory in some regulated contexts, but you pay for capacity that sits idle, and you carry the operational burden of keeping the secondary site current.
DRaaS means the recovery environment is hosted and operated by a provider, consumed as a service. Capital expenditure becomes operational expenditure, and the provider carries the responsibility for keeping the target environment ready.
A hybrid approach is increasingly common: Tier 1 workloads replicate to a provider-operated DRaaS platform, while regulated datasets that must remain under direct control stay in a private FKM.
For organizations subject to KVKK, the decisive question is data residency and processor responsibility. Confirm where replicated data physically resides, who has administrative access to it, and how that is evidenced during an audit. Get this answered before the technology selection, because it constrains the options.
Why untested plans fail
A disaster recovery plan that has never been executed is a hypothesis, not a capability. The most common causes of failure during a real incident are mundane:
- Recovery runbooks reference systems, IP ranges, or people that no longer exist.Application dependencies were mapped incompletely, so a database fails over while the service that depends on it does not.Nobody has authority to declare a disaster after hours, so the first hour is spent seeking approval.Backups were verified as "completed" but never actually restored.
The numbers show how common that is: in the same Veeam research, only 10% of those attacked recovered more than 90% of their data and 57% recovered less than half. Almost all of them had backups.
The corrective practice is scheduled failover testing with the business present, at least twice a year, with results documented; we set out the procedure step by step in the disaster recovery failover test guide. Ransomware makes this more urgent: recovery is only meaningful if you can restore to a point before the encryption began, which requires both a sufficiently granular journal and confidence in which point that was. Given that attackers dwell for a median of 14 days, finding that point is harder than it sounds; the detail is in the ransomware recovery playbook.
Common questions
Is Zerto better than Veeam? They solve different problems. Zerto is stronger for near-zero RPO failover of critical workloads. Veeam is stronger for immutable backup, long-term retention, and broad coverage at lower unit cost. Most mature environments deploy both.
What RPO is realistic without continuous replication? Snapshot-based replication typically delivers RPOs from 15 minutes to several hours depending on change rate and bandwidth. Sub-minute RPO effectively requires continuous data protection.
Does disaster recovery protect against ransomware? Only if the design accounts for it. Replication alone can propagate encrypted data to the recovery site. Protection requires immutable backup copies plus a journal granular enough to rewind to a pre-attack point.
How often should a DR plan be tested? At minimum twice a year for Tier 1 systems, with a full failover rather than a tabletop walkthrough, and with business stakeholders validating that the recovered service is genuinely usable.
What does DRaaS cost compared with building an FKM? DRaaS shifts capital expenditure to a recurring operational cost and typically reaches a defensible recovery capability faster. A self-built FKM can be more economical at large scale or where regulation requires direct control of the facility.
How Eclit approaches this
Eclit operates disaster recovery for regulated and high-transaction environments in Türkiye, including finance, healthcare, retail, and energy. Our practice is to begin with workload tiering and a dependency map, agree on RPO and RTO per tier with the business, then design to those targets rather than to a product. We operate both Veeam and Zerto, run the failover tests, and report the results.
If you want your current recovery position assessed against these criteria, our architects run a disaster recovery readiness review that produces a tiering model, a gap list, and a costed remediation plan.
Sources
- PagerDuty 2026 MTTR data: cost per minute of downtimeVeeam 2025 Ransomware Trends: recovery rates and times actually achievedHow we build this layer: disaster recovery engineering