Backups Don't Matter Test your readiness

Backup versus recovery, defined

RTO vs RPO vs clean recovery: which one decides survival?

You can hit RTO and RPO perfectly and still fail if the point you restore is compromised.

The two classic targets

  • RTO, recovery time objective. The maximum acceptable downtime: how quickly you must be back after a disruption.
  • RPO, recovery point objective. The maximum acceptable data loss, measured in time: how far back your last usable point can be.

They are useful and they are not going away. They set the targets that size your backup frequency, your infrastructure and your budget.

The hidden assumption in both

RTO and RPO quietly assume the recovery point is clean and restorable. That assumption comes from the disaster-recovery world, where the enemy is a flood or a failed disk, not an adversary who spent three weeks poisoning your backups. Against ransomware, the assumption breaks, and the two targets stop telling you whether you will actually survive.

Clean recovery is the third dimension

After an attack, integrity matters more than freshness. A clean point from four days ago can be worth far more than a compromised point from four hours ago. Sometimes clean recovery means deliberately accepting a worse recovery point objective to get a point that predates the attacker. The decision that decides survival is not "how recent?" but "how clean?"

Rethinking the targets for cyber

  • Add recovery-point integrity as a first-class requirement alongside time and data loss.
  • Measure time to clean recovery, which includes selecting and validating a clean point, not just time to restore bytes.
  • Establish your real recovery time by testing, because an untested recovery time is a guess.

What people get wrong

  • Buying replication to hit an aggressive recovery point objective that simply replicates the attack in real time.
  • Reporting a recovery time from a test that used a clean, happy-path point and never simulated compromise.
  • Treating recovery time and recovery point as service levels that backup software alone can meet, without clean-point selection or isolation.

How KELYN makes this operational

KELYN designs recovery on Commvault to hit recovery-time and recovery-point targets while adding the third dimension the targets miss: a known-clean point, validated in isolation, sequenced identity first. Then it tests, so the numbers you report are the numbers you can actually deliver on the worst day.

Sources

Your next backup will run

Will your business come back?

You can prove it in two minutes. Test your recovery readiness and see where the gaps are before an attacker does.