Lesson18 min

MTPD and RTO: the ceiling and the target

Two different objects

The MTPD — maximum tolerable period of disruption — is the duration beyond which consequences become unacceptable: irreversible client loss, regulatory sanction, harm to people, cash collapse.

The RTO — recovery time objective — is the duration within which the organisation commits to having resumed the activity.

These are objects of different natures. The first describes a limit you suffer. The second describes a commitment you make. Conflating them is the discipline's most frequent and costliest error.

Why RTO must sit strictly below MTPD

Every real recovery overruns its estimate. The causes are systematic, not accidental:

  • Detection time is almost never counted in estimates;
  • Decision time — convene, assess, arbitrate, authorise — routinely runs one to three hours;
  • Forgotten dependencies surface mid-recovery: an expired certificate, a service account, an entitlement, an unreachable third party;
  • Verification before return to service takes longer than the failover itself.

If RTO = MTPD, those four factors mathematically guarantee breaching the ceiling. The margin is not prudence: it is a structural necessity.

Who sets what

QuantityWho determines itOn what basis
MTPDExecutive and business linesClient, regulatory, financial and human impact
RTOExecutive / technical trade-offWhat the selected strategy can sustain
RPOBusiness, validated by technicalAcceptable volume of re-keying
MBCOExecutiveMinimum service level to maintain

The governance rule is simple: those who suffer set the ceiling, those who repair propose the target, management arbitrates the gap. Any other split produces either unrealistic objectives or comfortable ones.

The activity with no MTPD

Some activities can stop for a long time with no material consequence: internal monthly reporting, training, part of recruitment. That is valuable information, not an analytical failure.

Identifying what can stop matters as much as identifying what cannot: those activities are what will free up people the day you must sustain a degraded mode for three weeks.

A reading exercise

A bank sets, for its instant payments service: MTPD = 4 h, RTO = 4 h, RPO = 0.

Two problems. First, RTO = MTPD, so a breach is guaranteed. Second, RPO = 0 requires synchronous replication, whose cost and latency constraints are almost never carried through — and synchronous replication faithfully copies a logical corruption. The number is right in intent, unrealistic in implementation.

Key takeaways

  • MTPD is a ceiling on harm, RTO is a recovery target
  • RTO = MTPD structurally guarantees a breach
  • MTPD is set by those who suffer the disruption, never by those who fix it