RPO and RTO for Professional Firms in Orange County
By Tom Hermstad · HD Tech

What are RPO and RTO, and how do professional firms in Orange County set recovery targets that actually work?
RPO (Recovery Point Objective) is how much data your business can afford to lose, measured in time — for example, "we can reconstruct up to a certain amount of lost work." RTO (Recovery Time Objective) is how long your systems can be down before the damage becomes unacceptable — for example, "billing must be back online within a defined window." Every professional firm in Orange County needs both numbers, set by business process, before a disaster tests them.
Most MSPs throw around "RPO and RTO" like they mean something. They hand you a checklist, set a blanket target across your entire environment, and call it a disaster recovery plan.
That is not a plan. That is a guess dressed up in acronyms.
I've seen this exact gap sink firms that thought they were covered — firms with binders full of documentation and zero proof their backups actually worked. Over many years working with Orange County businesses, I've personally walked into law firms and CPA offices where the backup had been silently failing for months — and nobody knew until something broke.
Most firms find out their backups fail when they actually need them. That's too late.
The real question is not "what are your recovery targets?" The real question is: what does downtime actually cost your firm, by the hour, by the process, by the season?
Answer that first. Then work backward to the technology.
This is honestly one of the conversations I get most fired up about. The moment you put real dollar figures on downtime, every technology decision in the room sharpens immediately — and you stop making guesses dressed up as plans.
Why "one-size-fits-all" RPO/RTO targets fail professional firms
Industry guidance is clear: RPO and RTO must be set per business process or application, based on impact — not assigned as a blanket IT policy.
A single flat target across your entire environment almost always means two things:
- Your critical systems are under-protected.
- Your non-critical systems are over-engineered.
The international business continuity standard ISO 22301 — think of it as the global rulebook for keeping operations running after a disaster — defines RTO as the period after an incident within which a product or service must resume, and RPO as the point to which information is restored.
In plain English: both are promises about what your business can survive, not settings your IT vendor configures and forgets.
Notice both definitions start with the business outcome, not the backup schedule.
The Scripps Health ransomware attack in 2021 illustrates exactly what happens when these targets are not set — or not tested. EHR (electronic health record) access was disrupted for an extended period, and the impact on patient care and operations was severe.
For an Orange County medical group, a similar event forces a specific decision: can your practice tolerate losing a day of appointment data, or going several days without your scheduling system?
If you have not answered that before the event, someone will answer it for you — badly, under pressure, in the middle of the night.
How to set RPO and RTO for your firm: start with the math
Here is where it gets interesting — and where most firms get it completely wrong.
The defensible approach starts with the business process, quantifies impact over time, and only then maps to technology. Most firms skip straight to the technology. That is backwards, and it costs them every time.
Law firms: billable hours and court deadlines
Consider a hypothetical mid-sized Orange County litigation firm. If multiple attorneys are unable to bill and your practice management system is down for an extended period, the unrealized billings can reach significant sums before you count paralegal time, court deadline exposure, and trust accounting compliance risk.
A full-day outage pushes the direct cost even higher — and that number does not include the reputational damage of missing a filing window.
Your RTO for practice management and billing is not "as soon as possible." It is a specific number — chosen by your firm because that is where the dollar damage crosses an unacceptable threshold.
RPO follows a similar logic. If your client intake and time-entry data is backed up on a given schedule and you lose several hours of entries, how long does it take your attorneys to reconstruct those billable records?
The re-entry cost alone tells you whether your current backup interval is actually acceptable, or whether you need more frequent snapshots.
HD Tech's cybersecurity for law firms work starts exactly here: quantifying what a disruption actually costs before recommending any technology.
Greg Burnight, Principal at APC, Curtis & Burnight in Seal Beach, has worked with HD Tech for many years: "Careful attention to detail, solution-oriented services and implementation and fair pricing. We have been extremely satisfied with their professionalism and capabilities."
CPA firms: tax season changes everything
A CPA firm's tolerable downtime in November looks nothing like its tolerable downtime in the days leading up to a tax deadline.
During tax season, every hour your tax preparation software or client portal is unavailable has a compounding cost: filing deadline exposure, client trust erosion, and staff overtime to recover.
Even a handful of staff burning unplanned overtime to recover lost work adds up quickly — before you count a single client call or missed deadline.
Setting RPO/RTO by criticality and realistic capability means a CPA firm should use multiple tiers:
- Core tax preparation and document management warrant aggressive targets during filing season.
- Administrative and internal systems can tolerate a longer window.
- The right specific targets depend on your firm's size, client load, and true cost of downtime.
And here is the reality most firms miss: part-time or informal IT support — the "nephew solution" — rarely produces documented, tested RPO and RTO targets.
You get a backup that runs most nights and a shrug when you ask how long a full restore actually takes.
That is not a recovery plan. That is a hope.
Kathleen Urquidez, President & Managing Partner at Urquidez & Associates, CPAs, Inc. in Long Beach, said it directly: "For our firm, downtime means lost billing. With HD Tech on our side, we have close to no interruptions. Secondly, data security is always a large concern, but with HD Tech on our side, we know we are doing everything we can to avoid a data breach and we rest easier."
HD Tech's managed IT services for accounting and CPA firms are built around this seasonal reality — not a static annual target.
Healthcare and biomedical: compliance meets patient impact
For Orange County healthcare and biomedical firms, the stakes combine financial exposure with regulatory risk and direct patient harm.
The FBI's Internet Crime Complaint Center (IC3) reported that cyber-related crimes cost Americans nearly $21 billion in 2025, up from losses exceeding $16 billion in 2024 — pressure that hits regulated industries like healthcare especially hard.
That pressure drives the need for tighter RPO and RTO around EHR systems, imaging, and patient scheduling.
A medical group that loses even a few hours of appointment scheduling data does not just lose revenue — it creates patient safety risk and potential HIPAA documentation exposure.
Your RPO for your EHR should reflect that reality, not a generic backup policy your MSP set three years ago.
Healthcare IT security in Orange County increasingly demands that these targets are documented, tested, and verifiable — not assumed.
The gap most firms never close: stated targets versus tested capability
Here is the part that fires me up most — because it is the most common and most dangerous problem I see. Most firms have stated targets. Very few have tested them.
Research and industry guidance are consistent on this point: the gap between what a firm declares and what its current backup and disaster recovery processes can actually deliver is frequently significant.
Most firms find out their actual restore time is far longer than their stated RTO the same way they find out their backups were failing — when something breaks for real.
It's not if, it's when. The question is whether your firm finds that gap during a controlled test — or during an actual incident in the middle of the night when clients are counting on you.
The firms that have already tested their recovery plan aren't just sleeping better. They're winning bids and keeping clients when a competitor's plant goes dark. That is what a tested RTO looks like as a competitive advantage — not a line item on an IT checklist.
This is the conversation HD Tech has with every new client under the Lifeguard Loop™. During the Listen & Learn phase, we do not just ask what your targets are.
We ask: when did you last test a full restore? How long did it actually take? What data was missing?
If you cannot answer those questions, your RPO and RTO are fiction.
And that is fixable — but only if you know where you stand right now.
How do you translate RPO and RTO targets into a technology stack that actually delivers?
Here is the five-step process we walk every firm through. I want to be clear: this is not abstract methodology. Every step without it has a real-world consequence.
Define the outcome by business process. What does this system do, and what does an hour of downtime actually cost? Without this step, you set targets that look good until the auditor asks when you last tested them.
Quantify impact over time. Build the cost curve — when does downtime become catastrophic versus inconvenient? Without this step, you pick a number out of thin air and hope it's close enough.
Set explicit targets. RTO and RPO per critical process, tiered by severity. Without this step, your entire environment runs on a single blanket policy that protects nothing well.
Map to technology. Backup frequency, replication, failover — chosen to meet the targets, not the other way around. Without this step, you buy tools your vendor recommended instead of tools your business actually needs.
Test and document. Confirm the tech stack actually delivers what you declared. Without this step, your recovery plan is a binder — not a capability.
Orange County professional firms — law, CPA, healthcare, biomedical — operate in regulated, deadline-driven, reputation-sensitive environments.
Your recovery targets need to reflect that. Your IT partner needs to help you set them with math, not guesswork.
Keep paddling. The firms that come out ahead are the ones who do the work now — not the ones who find out the hard way.
Frequently Asked Questions
RPO is how much data you can afford to lose, measured in time. Your backups must run frequently enough that you never lose more than your defined acceptable window of work. Miss that, and you are manually reconstructing entries your attorneys already billed.
RTO is how long your systems can be offline before the damage becomes unacceptable. Set both per business process, based on real financial impact. A single blanket target across your whole environment is not a plan — it is a guess with a logo on it.
Start with your hourly billing rate multiplied by the number of attorneys who cannot work. Add court deadline exposure, paralegal time, and trust accounting compliance risk. When the total crosses the threshold your firm cannot survive, that is your RTO — not a number some IT checklist handed you.
No two firms land in the same place. That is exactly why it must be done firm by firm, not assumed from a template. I get fired up every time I walk a firm through this exercise — because the number almost always surprises them.
Regularly, and again after any major system or organizational change — that is what frameworks like NIST SP 800-34 and ISO 22301 call for. Schedule that test well outside peak filing season.
A real test means actually restoring from backup, timing it, and comparing the result to your declared RTO. It is common in exercises to find that actual recovery times exceed stated RTOs by a wide margin. That gap is the problem — and the only way to find it is to look. Most of your competitors have not looked. That is your edge.
HIPAA's Security Rule requires a documented, tested contingency plan — including data backup and disaster recovery procedures. HIPAA does not mandate specific numeric targets, but federal auditors and cyber insurers expect documented, tested recovery procedures.
With cyber-related crime losses reaching nearly $21 billion in 2025, up from losses exceeding $16 billion in 2024, regulators are scrutinizing these plans harder than ever. A plan that looks good in a binder but has never been tested is not protection. It is paperwork. Do not wait for an auditor to be the one who finds it.
An honest picture of where you stand is the first real step toward fixing it. Industry guidance recommends testing whether your disaster recovery processes can actually meet your declared targets and documenting any shortfalls.
From there, you close the gap: adjust backup frequency, add replication, implement faster failover, or revise targets to reflect what is actually achievable. A documented gap beats a hidden one every time. The firms that have already done this work are recovering from incidents in far less time while others are still reading from a binder.
You survived ransomware once. You know better than anyone what an untested recovery plan costs in the middle of the night — the phone calls, the production halt, the employees standing around waiting, the clients you had to face the next morning.
Your RPO and RTO are business decisions. They belong to you, not your vendor. If you have not made them deliberately, with real numbers and tested processes, you are operating on assumptions.
Your employees are counting on you. Your clients trust you with their most sensitive work. The business you have built — and everything you want it to become — deserves better than a guess dressed up in a binder.
If you still don't know your tested RTO — or you're not certain your backups would hold up under real pressure — don't be a casualty. Book your free Cyber Preparation Assessment with HD Tech today.

Tom Hermstad
President & CMO, HD Tech
Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.
