Skip to content
SecuriFii

Evidence

The business impact analysis, and why IT should not set the RTO

The most common continuity finding is an assumed recovery time — a number technology chose without asking the people who bear the consequences.

Facts checked2026-09-11

Who should set the RTO and RPO?

A business impact analysis identifies which activities deliver your products and services, what they depend on, and what happens as each hour of disruption passes. From that come the recovery time objective — how quickly an activity must resume — and the recovery point objective, how much data loss is tolerable.

Both belong to the activity owner, not to IT. Finance can say what four hours of an unavailable billing system costs; the infrastructure team can only say what it would take to restore it in four hours. Confusing those two is how organisations end up with expensive resilience nobody asked for and gaps nobody noticed.

The bottom line

Get the RTO and RPO signed by the person who owns the activity. An IT-set recovery objective is an assumption, and auditors treat it as one.

Related insights