Question this briefing helps answer: What should public safety agencies ask about RTO, RPO, and disaster recovery?
Backups are not disaster recovery
Backups matter, but backups are not the same as disaster recovery. A backup is a copy of data. Disaster recovery is the ability to restore or resume service after disruption in a way the agency can operationally survive.
An agency may have backups and still face a long outage. Data may be protected while the application, interfaces, user access, and operational workflows remain unavailable.
RPO is about data loss
Recovery point objective, or RPO, describes how much data loss may be acceptable after a disruption. In public safety, this is not just a technical number. It may affect calls, notes, timestamps, unit activity, status changes, reporting, and later reconstruction.
A four-hour RPO may sound reasonable in a contract until those four hours include a major incident. Agencies should ask what data could be lost, how it would be reconstructed, and what manual procedures would be needed.
RTO is about time to restore
Recovery time objective, or RTO, describes how long recovery is expected to take. Agencies should know when the clock starts, what services are covered, what exclusions apply, and whether the commitment is a target or an enforceable contract term.
The agency also needs to know how it will operate while recovery is underway. The vendor may recover technology, but the agency must maintain continuity of operations.
Testing proves the plan
Disaster recovery should be tested. Documentation is important, but testing reveals missing access, unclear authority, weak communication, and unrealistic assumptions.
Agencies should ask whether the vendor tests recovery, whether results are shared, whether customers participate, and how lessons learned are applied. For public safety, recovery should be evidence-based, not hope-based.