RTO and RPO don’t need to be confusing. Here’s how UK SMEs choose recovery targets, set priorities, and build a continuity plan that actually works.
Most SMEs only think about business continuity after a scare: a ransomware story in the news, a supplier outage, a server failure, or a “we can’t access files” morning that wipes out half a day. The issue isn’t that SMEs don’t care — it’s that continuity planning is often presented like an enterprise exercise full of jargon and giant documents. In reality, you can get 80% of the value from a simple approach: decide what matters most, decide how quickly you need it back, and make sure you can actually restore it.
Two terms drive most continuity decisions: RTO and RPO. They sound technical, but they’re just business questions. Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester — and we find continuity becomes straightforward once leaders agree on priorities and acceptable downtime.
In plain English: business continuity is your plan to keep operating (or recover quickly) when systems, data, or suppliers fail.
RTO and RPO in plain English
RTO (Recovery Time Objective)
How long you can afford to be without a system or data before it becomes a serious business problem.
Example: “If email is down for 4 hours, we can cope. If it’s down for 2 days, we’re in trouble.”
RPO (Recovery Point Objective)
How much data you can afford to lose, measured in time.
Example: “We can tolerate losing the last 2 hours of work, but not the last 2 days.”
How SMEs choose sensible RTO/RPO targets
Step 1: List your “must-run” business functions
Think in outcomes, not tech:
- delivering client work
- invoicing and getting paid
- customer communications
- access to core files and systems
Step 2: Map those functions to systems
For many SMEs, the big ones are:
- Microsoft 365 (email, SharePoint/Teams files)
- line-of-business apps
- finance platforms
- identity/sign-in (if you can’t log in, nothing works)
Step 3: Decide priorities (what comes back first)
Most SMEs benefit from a simple tiering:
- Tier 1: business stops without it
- Tier 2: painful but workable short-term
- Tier 3: can wait
Step 4: Validate with reality (restore confidence)
A plan is only real if:
- backups exist for what you think they do
- restores have been tested
- you know who does what in the first hour
Common continuity gaps in SMEs
- “We have backups” but no restore testing
- cloud data assumed to be recoverable without a defined approach
- no alternative comms plan if email is compromised
- supplier dependencies not considered (one outage can halt operations)
FAQ
Do we need a huge continuity document?
No. Most SMEs need a clear, short plan with priorities, contacts, and tested recovery steps.
Is this just about ransomware?
No. Outages, accidental deletion, supplier downtime, and human error are just as common.
How often should we review continuity?
At least annually, and after major changes (new systems, growth, office moves).
If you want RTO/RPO targets that match how your business actually operates — and a recovery plan you can trust —
we can help you define it and test it properly.