Objectives before products
RPO and RTO are business decisions per workload, not global settings. The finance close can tolerate 15 minutes of data loss and four hours down; the e-commerce front end wants the opposite. Write the two numbers next to every application name, get the business to sign them, and only then pick tooling — never the reverse.
Runbooks are the product
A restore procedure that exists as tribal knowledge is a single point of failure wearing a lanyard. The working pattern is a one-page runbook per critical system: restore order, prerequisites, who executes, who verifies, and the phone tree. Pages get rehearsed twice a year, which is also how you discover the undocumented dependency on a retired admin’s script.
Test restores on a schedule, and time them
The only meaningful backup metric is a timed restore. Monthly, pick one system, restore it to an isolated network, and record the wall-clock. The trend line of those timings is your real disaster recovery capability — and the first artefact a BB ICT or client auditor should be shown.




