Technology6 min read

Backup & Disaster Recovery: The 3-2-1 Rule, RPO & RTO

What separates a real backup strategy from a false sense of security — and the two numbers that define how much downtime and data loss your business can survive.

Published July 29, 2026Updated July 29, 2026
BackupDisaster RecoveryBusiness ContinuityRPORTO3-2-1 RuleRansomware

The 3-2-1 rule

Backups are insurance you hope never to use — but when ransomware hits or a server dies, they're the difference between a bad afternoon and a business-ending event.

  • 3 copies of your data (production + two backups).
  • 2 different media types (local appliance + cloud).
  • 1 copy offsite — ideally immutable, so ransomware can't encrypt it.

The two numbers that matter

MetricQuestion it answers
RPO (Recovery Point Objective)How much data can we afford to lose? Sets backup frequency.
RTO (Recovery Time Objective)How fast must we be back online? Sets recovery method.

A 15-minute RPO means backing up every 15 minutes. A 1-hour RTO means you need fast local recovery or virtualization, not just cloud restore.

The rule nobody follows: a backup you've never restored is a hope, not a plan. IDENETY runs periodic restore testing and verification as part of managed BCDR — so you know recovery works before you need it.

IDENETY managed backup options

Endpoint backup, server backup, and compliant (immutable) backup for regulated workloads — all monitored, alerted, and restore-tested. HIPAA and PCI clients are provisioned with immutable cloud vaults and documented recovery procedures from day one.

Backup and business continuity are included in the COMPLETE MSP plan. Contact us to discuss RPO/RTO targets for your environment.