How to Calculate RPO and RTO Without Guessing
A four-step method for deriving recovery targets from the average cost of downtime ($4,537 a minute), and the trap of setting every system to zero.

Short answer: Calculate RPO and RTO from business cost, not from what the technology can do. Work out the cost of one hour of downtime and one hour of data loss for each workload, and buy protection in proportion to those numbers. Setting every system to near zero produces an architecture nobody budgets for and therefore nobody builds.
For reference, PagerDuty's 2026 data puts the average cost of downtime at $4,537 per minute, roughly $272,000 an hour, and 68% of organizations report losing more than $300,000 an hour during IT incidents. That is not your number; the method for producing yours is below.
The two numbers
RPO is how much data loss you can accept, expressed in time. It determines replication frequency. RTO is how long you can be down before the impact becomes unacceptable. It determines recovery architecture.
They are independent. A reporting system may tolerate a 24-hour RPO while demanding a 2-hour RTO. A log platform may be the reverse.
The four-step method
Step 1: quantify the hourly cost of downtime. Add lost revenue, the cost of idle staff, contractual penalties and regulatory risk. On an e-commerce platform this is straightforward: average hourly revenue multiplied by the share lost. For internal systems, use fully loaded staff cost multiplied by the number of people blocked.
Two items are usually missed: the cost of working through the backlog that builds up during the outage, and the extra load that lands on customer support. Both appear after the outage ends, so neither makes it into the calculation.
Step 2: quantify the hourly cost of data loss. Ask what it costs to reconstruct an hour of lost transactions. Sometimes it is impossible, in which case the answer is effectively infinite and the workload is automatically Tier 1. Sometimes it means rerunning a batch job, which is cheap.
Step 3: assign tiers.
- Tier 1: both costs high. RPO in seconds, RTO under 15 minutes. Continuous replication.Tier 2: moderate. RPO 1 to 4 hours, RTO 4 to 8 hours. Snapshot replication.Tier 3: low. RPO 24 hours, RTO 24 to 48 hours. Nightly backup.
We covered which technology handles Tier 1 in our Zerto and Veeam comparison; in short, continuous replication and deep retention are jobs for different products.
Step 4: sanity-check the spend. Compare the annual cost of protection with expected annual loss, which is outage cost multiplied by a realistic incident frequency. If protection costs more than the risk it removes, the tier is wrong.
Why most organizations get this wrong
They ask application owners what they want. Every owner says "zero downtime, zero data loss," because no cost is attached to the answer. The fix is to attach cost to the answer: show the price difference between a 4-hour RTO and a 15-minute RTO, and have the owner choose within a budget while you are in the room.
Expect the result to surprise you. Once a price tag is attached, the Tier 1 list usually shrinks to a handful of systems, because for an application to genuinely be Tier 1 its downtime cost has to exceed the annual cost of continuous replication, and for most internal systems it does not.
Measured RTO versus declared RTO
The RTO you declare is a target. Your measured RTO is the time your last real drill produced. They are usually different, and only the measured one means anything.
For a sense of how large the gap can be: in Veeam's 2025 ransomware research, average recovery among attacked organizations took 24.6 days. It is safe to assume none of those organizations had 24.6 days written in their plan.
To measure it, restore a representative workload end to end, including the steps people forget: finding credentials, getting approval to declare a disaster, reconfiguring DNS, and verifying that the application not only starts but actually works. We set out the method step by step in the disaster recovery failover test guide.
Frequently asked questions
Can RPO be zero? Not in any real sense. Synchronous replication approaches zero but adds latency and cost, and is justifiable only for a narrow set of workloads.
Is a lower RPO always better? Only if you can justify the cost. Going from 24 hours to seconds can multiply the cost of protection several times over.
Who owns these numbers? The business unit owns them; IT translates them into architecture. Targets set by IT alone do not survive a real incident review. We covered how to write down decision authority in the incident escalation matrix.
How often should targets be reviewed? Annually, and whenever an application's criticality changes materially.
Sources
- PagerDuty 2026 MTTR data: cost per minute of downtime and average resolution timeVeeam 2025 Ransomware Trends: recovery times actually achievedHow we build this layer: disaster recovery engineering